Wilders Security Forums  

Go Back   Wilders Security Forums > Other Topics > polls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

View Poll Results: Which Rootkit Removal Tool do you use?
Panda Anti-Rootkit 7 7.61%
TrendMicro RootkitBuster 7 7.61%
GMER 34 36.96%
F-Secure Blacklight 8 8.70%
Sophos Anti-Rootkit 12 13.04%
McAfee Rootkit Detective 4 4.35%
SysProt AntiRootkit 1 1.09%
UnHackMe 3 3.26%
RootRepeal 12 13.04%
Other 43 46.74%
Multiple Choice Poll. Voters: 92. You may not vote on this poll

 
 
Thread Tools Search this Thread
  #1  
Old November 21st, 2009, 11:22 PM
Brian_12
 
Posts: n/a
Default Which Rootkit Removal Tool do you use?

Hi all, I'm new to the forums. I'm glad to be here and I look forward to learning a lot. I'll start my first post with a poll.

I use GMER and F-Secure Blacklight.

Which anti-rootkit(s) do you use?
  #2  
Old November 22nd, 2009, 04:17 AM
subhrobhandari subhrobhandari is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 238
Default Re: Which Rootkit Removal Tool do you use?

I will vote for other, since I dont use any specific. See my sig.
__________________
Realtime: Webroot SecureAnywhere Private Beta + Zemana Antilogger + HitmanPro Alert
On-Demand: Hitman Pro
Others: Router + EMET (Custom Conf.) + Fully Updated Windows 7 SP1 64Bit + Other Security Measures
  #3  
Old November 22nd, 2009, 04:59 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Windows up-to-date ark list with alive, dead and download.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #4  
Old November 22nd, 2009, 09:58 AM
progress
 
Posts: n/a
Lightbulb Re: Which Rootkit Removal Tool do you use?

TrendMicro RootkitBuster

Quote:
Originally Posted by Meriadoc
Windows up-to-date ark list with alive, dead and download.

Thank you for this interesting list, unfortunately many of them are incompatible with Win 7
  #5  
Old November 22nd, 2009, 10:52 AM
noone_particular noone_particular is online now
Very Frequent Poster
 
Join Date: Aug 2008
Posts: 1,876
Default Re: Which Rootkit Removal Tool do you use?

On units that I'm servicing, I use RKU, gmer, and others. On my own, none. Rootkit removers aren't necessary when a default-deny security policy won't allow them install in the first place.
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come.
  #6  
Old November 22nd, 2009, 12:37 PM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Which Rootkit Removal Tool do you use?

Radix.

http://www.usec.at/rootkit.html
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #7  
Old November 22nd, 2009, 12:45 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Radix is outdated.
  #8  
Old November 22nd, 2009, 07:58 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

WinDbg
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #9  
Old November 22nd, 2009, 09:36 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Meriadoc, why use a debugging tool when you can use an actual antirootkit that finds rootkits themselves?
  #10  
Old November 22nd, 2009, 09:51 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Of course it is one of the best tools for this.

By using, knowing how to use WinDbg you may not limit yourself to the power of an ark while applying the same sort of approaches as antirootkit tools use.

[expanded post]
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 22nd, 2009 at 10:20 PM.
  #11  
Old November 22nd, 2009, 09:53 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by noone_particular
On units that I'm servicing, I use RKU, gmer, and others. On my own, none. Rootkit removers aren't necessary when a default-deny security policy won't allow them install in the first place.

I forgot about RKU. Is it still being developed? Where can I download the latest version?
  #12  
Old November 22nd, 2009, 10:36 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

expanded last post

In fact it was updated yesterday. Here : RkU3.8.382.584

runs on 7 ance
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 22nd, 2009 at 11:08 PM.
  #13  
Old November 22nd, 2009, 10:49 PM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,086
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by noone_particular
On units that I'm servicing, I use RKU, gmer, and others. On my own, none. Rootkit removers aren't necessary when a default-deny security policy won't allow them install in the first place.

Likewise for me(although I'm not good enough to service computers!). I used F-Secure Blacklight in the past and Avira lately but I doubt I will ever find anything as nothing will execute without my approval and in a virtual environment.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
  #14  
Old November 22nd, 2009, 10:58 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Here's a nice tool, Kernel Detective by GamingMaster, supports 7.
Attached Thumbnails
Click image for larger version

Name:	ghostintheshell.JPG
Views:	6
Size:	158.0 KB
ID:	213834  

__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #15  
Old November 22nd, 2009, 11:51 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by Meriadoc
Of course it is one of the best tools for this.

By using, knowing how to use WinDbg you may not limit yourself to the power of an ark while applying the same sort of approaches as antirootkit tools use.

[expanded post]

True, but that is only of any use to people with a higher than intermediate knowledge of Kernel debugging. This will rule out about 95% of the people here.

Also, reformats are caused by these things than anything else!


Quote:
Originally Posted by Meriadoc
expanded last post

In fact it was updated yesterday. Here : RkU3.8.382.584

Thanks for the link, but that version is unstable.
Quote:
This release could be buggy and can fly to Blue screens country
What is the most stable version?
  #16  
Old November 23rd, 2009, 12:04 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,609
Default Re: Which Rootkit Removal Tool do you use?

I use Prevx 3 and does a good dam job!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #17  
Old November 23rd, 2009, 12:21 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

But arks need knowledge, the useful tools that generate the same information as WinDbg, are also advanced tools.

Actually some of the learning curve of WinDbg isn't so steep.

For example, using a good antirootkit tool such as Rku, RootRepeal or Kernel Detective we can look up hooked entries in the SSDT, System Service Table and IDT, interrupt dispatch table - some tools highlight these in red.

In WinDbg we can also do this by dumping said table using the command "!idt -a".

You could look for patched functions with - "!chkimg -d nt".

What you need to do is interpret the output, for example...

List processes in WinDbg "!process 0 0" - then compare with the list in a process explorer say Sysinternal's tool, Task Manager or Process Hacker. A discrepancy would point to a rootkit.

Ark's simplify some of this by showing you what is hidden, some of the information needs the user to investigate further.



I've never had to reformat due to using WinDbg.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 23rd, 2009 at 12:59 AM.
  #18  
Old November 23rd, 2009, 12:38 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by geohac



Thanks for the link, but that version is unstable. What is the most stable version?
Stable here so far.

Previous RkU release blog entry RkU3.8.380.580 Or Windows 2000 fix RkU3.8.380.581
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 23rd, 2009 at 12:44 AM.
  #19  
Old November 23rd, 2009, 10:29 AM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by geohac
Radix is outdated.

How is that?
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #20  
Old November 23rd, 2009, 11:41 AM
blacknight's Avatar
blacknight blacknight is offline
Very Frequent Poster
 
Join Date: Sep 2007
Location: Europe
Posts: 1,596
Default Re: Which Rootkit Removal Tool do you use?

GMER and Rootkit Repeal.
  #21  
Old November 23rd, 2009, 08:09 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

tester, I say that simply becuase it isn't the latest antirootkit out there. It hasn't been updated since Jan 2008. Also, it's only compatible with Windows 2000 and Windows XP.
  #22  
Old November 23rd, 2009, 10:09 PM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by geohac
tester, I say that simply becuase it isn't the latest antirootkit out there. It hasn't been updated since Jan 2008. Also, it's only compatible with Windows 2000 and Windows XP.


I see.
I thought it was updated about 3 months ago.
Can't find confirmation, so I may be wrong about that.
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #23  
Old November 23rd, 2009, 10:34 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,424
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by the Tester
I thought it was updated about 3 months ago.
Can't find confirmation, so I may be wrong about that.
the Tester, is this usec.at Radix 1.0.0.9 released forum post of August 20th, 2009, what you were thinking about?

Re: Radix Anti-Rootkit
  #24  
Old November 24th, 2009, 04:29 PM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by JRViejo
the Tester, is this usec.at Radix 1.0.0.9 released forum post of August 20th, 2009, what you were thinking about?

Re: Radix Anti-Rootkit


Yes it is JRViejo.
So Radix was updated this past August.
Thanks for finding and linking that.
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #25  
Old November 24th, 2009, 06:09 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

My mistake. Thanks for the information jrviejo.
 

Wilders Security Forums > Other Topics > polls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:51 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums