Windows NT - 2000 - 2003 White Papers

Safe Termination of Orphan Processes on Windows NT Platforms

Overview Rootkits are one of the greatest challenges to computer security. Due to the stealthy nature of rootkits, it is almost impossible for a user to see these hidden processes or files. In some situations, even security applications may not be able to detect the presence of rootkits. Rootkits use different methods to infect systems and hide their objects. Rootkit scanners use different methods to detect rootkits. One method is differentiation. This method takes a snapshot of the system's objects at a low-level layer (or even before the system boots, called preboot scanning); then it takes another snapshot at a very high-level layer and compares the differences.

Further White Paper Details
PublisherMcAfee File FormatPDF
Date PublishedDecember 2007
FormatWhite Papers   
Topics

Quick Sitemap Links: