Bypassing disk.sys to retrieve a sector from disk.

@James,

>I’m curious as to what environment you are running under where it is okay to consider that there is a n% possibility that you don’t have a rootkit installed, where n < 100?

I guess I didn’t make myself clear enough. All this % talk was related to types of rootkit available, rootkits which can be identified easily , rootkits which have used anti detection methods but still are detectable , Rootkit which can not be detected with current methods.

So I meant that my code should atleast detect first two types of rootkits.

>So don’t give up :slight_smile:

definitely not. :-), Thanks

@Anton

>In other words, stop relying upon any doc on the topic that you find of the web if it was written more than 2 years ago …

point noted, thanks for the suggestion.

Aditya