Galdorf
Well-Known Member
- Reaction score
- 502
- Location
- Ontario, Canada
I was looking at a quick way to identify patched system files using md5 hash checks is there any web page with info on hashs of windows system files or a program that has them built in the compares the values automatically?.
atapi.sys and nvata.sys patch rootkits are very common but with all updates that nvidia does on their controller files its hard to get md5 of all versions.
I was thinking of making a utility to put on my bootcd that compares md5 hash values and replaces the infected file with clean one.
On another note i did find software that monitor files for changes using hashs and security signatures and such called tripwire the open source one only supports linux and commercial version supports windows.
atapi.sys and nvata.sys patch rootkits are very common but with all updates that nvidia does on their controller files its hard to get md5 of all versions.
I was thinking of making a utility to put on my bootcd that compares md5 hash values and replaces the infected file with clean one.
On another note i did find software that monitor files for changes using hashs and security signatures and such called tripwire the open source one only supports linux and commercial version supports windows.
Last edited: