This post originated from an RSS feed registered with .NET Buzz
by Robert Hurlbut.
Original Post: Simple and interesting solution for hidden root kits
Feed Title: Robert Hurlbut's .Net Blog
Feed URL: http://www.asp.net/err404.htm?aspxerrorpath=/rhurlbut/Rss.aspx
Feed Description: Development with .Net, Rotor, Distributed Architectures, Security, Extreme Programming, and Databases
Microsoft Research has a short paper on using hackers' tricks against them, including using differential file system scans (using WinDiff) from infected vs. clean OS boots to detect hidden files [via G. Andrew Duthie]
Follow the link to Andrew Duthie's post as well for more comments. This is a great tool in the fight against malware.