Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Very sluggish computer. Any suggestions?
Message
De
29/08/2006 19:15:44
 
 
À
20/08/2006 22:39:40
Hilmar Zonneveld
Independent Consultant
Cochabamba, Bolivie
Information générale
Forum:
Windows
Catégorie:
Sécurité
Divers
Thread ID:
01147143
Message ID:
01149593
Vues:
21
As part of my investigation to speed up my machine, I looked into rootkits and I'd like to share a result of the investigation. In http://research.microsoft.com/rootkit/ MS suggests a way to investigate if you have a rootkit living in your machine. They say:

Simple steps you can take to detect some of today's ghostware:
Run "dir /s /b /ah" and "dir /s /b /a-h" inside the potentially infected OS and save the results.
Boot into a clean CD, run "dir /s /b /ah" and "dir /s /b /a-h" on the same drive, and save the results.
Run a clean version of WinDiff from the CD on the two sets of results to detect file-hiding ghostware (i.e., invisible inside, but visible from outside). See Hacker Defender ghostware files revealed (highlighted) for an example.
Note: there will be some false positives. Also, this does not detect stealth software that hides in BIOS, Video card EEPROM, disk bad sectors, Alternate Data Streams, etc.

One way to get a clean boot is through something called WinPE, a boot CD for Windows. Unfortunately MS only sells that to selected clients. On the other hand, I found an application called PeBuilder at http://www.nu2.nu/pebuilder/ that uses your Windows CD to create a boot CD which it calls BartPE. The author is by Bart Lagerweij and the application is very easy to use.

Coupling both findings I tested for rootkits in my home machine and found none. Tomorrow I'll check at the office...

For what it's worth, I got a large speed boost after I uninstalled version 10.0 of Symantec AntiVirus from my PC and installed a client copy of version 10.1. The client copy receives virus updates through the server instead of directly.

Thank you for the help.

Alex
Précédent
Répondre
Fil
Voir

Click here to load this message in the networking platform