Home > Step 1: Is there a problem
Step-by-Step Guide:
EMAIL THIS LICENSING & REPRINTS

Step 1: Is there a problem

18 Oct 2006 | Kevin Beaver, Contributor

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Is your computer running slow or doing odd things? Have you found certain programs or data have been tampered with? Do odd windows or messages pop up during system startup or shutdown? Odd computer behavior is indeed a side effect of a rootkit infection, but strange behavior alone may not be a true indicator.

In fact, it's easy for the assumed presence of a rootkit to have a placebo effect, leading you (or a user) to believe the computer is infected. The truth is, strange behavior could just as easily be legitimate programs doing their things.

To determine if there is truly a rootkit operating behind the scenes, use a system process analyzer such as Sysinternals' ProcessExplorer or, better yet, a network analyzer. By using these tools, you'll likely be surprised to find what programs are doing and what's going in and out of your network adapter. You may also discover that you simply have an over-taxed system running with too little memory or a severely fragmented hard drive. With that in mind, I recommend checking your system configuration and defragmenting your drive(s). Remember, though, that it's better to be safe than sorry, so run a rootkit scan as well.


Finding and removing a rootkit

 Home: Introduction
 Step 1: Is there a problem
 Step 2: Choose the right scanning tool
 Step 3: Clean up the mess
 Step 4: Bulletproof your efforts
About the author:
About the author: Kevin Beaver is an independent information security consultant and expert witness with Atlanta-based Principle Logic, LLC. He has more than 18 years of experience in IT and specializes in performing information security assessments revolving around compliance and IT governance. Kevin has written six books, including Hacking For Dummies (Wiley), Hacking Wireless Networks For Dummies, and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach). He can be reached at kbeaver@principlelogic.com. Copyright 2006 TechTarget


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Spyware protection and clean up
Cool things about security, nothing about Britney Spears
Removing malware from your Windows system
What is malware?
A look back at the malware tips and news of 2006
Remove bots from your system -- a four-step process
Use a GPO to defend against Trojan downloads
Step-by-Step Guide: Finding and removing a rootkit
Step 2: Choose the right scanning tool
Step 4: Bulletproof your efforts
Step 3: Clean up the mess
Spyware protection and clean up Research

Malware and other Windows security threats
Prevent malware infection with malware detection tools
Does Vista mean the end of malware?
Zero-day attack prevention
Use patching to protect your network from threats
Remove bots from your system -- a four-step process
Define server roles, counterattack zero-day threats
Harden your network services and contain zero-day threats
Step-by-Step Guide: Finding and removing a rootkit
Step 2: Choose the right scanning tool
Step 4: Bulletproof your efforts
Malware and other Windows security threats Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchWindowsSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts