| Rootkit detection is difficult because a rootkit may be able to
subvert the software that is intended to find it. Detection methods
include using an alternate, trusted operating system;
behavioral-based methods; signature scanning; difference scanning;
and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only alternative. |