Cleaning an Infected System

If your system has been infected with a rootkit, it is almost impossible to clean it up. Never trust a machine that has been infected with a rootkit, because hiding is a rootkit's main purpose.

A clean install of the system is recommended after backing up the full system. Follow these steps:

  1. Take the host offline.

  2. Back up your data (as much as possible, including binaries and logfiles).

  3. Verify the integrity of this data.

  4. Install your host with a fresh install.

  5. Investigate the old logfiles and the possible used tools. Also investigate the services that were vulnerable at the time of the hack.