Wilders Security Forums  

Go Back   Wilders Security Forums > Other Topics > polls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

View Poll Results: Which Rootkit Removal Tool do you use?
Panda Anti-Rootkit 7 7.61%
TrendMicro RootkitBuster 7 7.61%
GMER 34 36.96%
F-Secure Blacklight 8 8.70%
Sophos Anti-Rootkit 12 13.04%
McAfee Rootkit Detective 4 4.35%
SysProt AntiRootkit 1 1.09%
UnHackMe 3 3.26%
RootRepeal 12 13.04%
Other 43 46.74%
Multiple Choice Poll. Voters: 92. You may not vote on this poll

 
 
Thread Tools Search this Thread
  #26  
Old November 24th, 2009, 06:35 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,418
Default Re: Which Rootkit Removal Tool do you use?

the Tester & geohac, you're both welcome! Take care.

JR
  #27  
Old November 25th, 2009, 06:03 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

LiveCD

Enumerate Windows files then delete from outside Windows.


Also the MS Strider page describes :
Quote:
# Run "dir /s /b /ah" and "dir /s /b /a-h" inside the potentially infected OS and save the results.
# Boot into a clean CD, run "dir /s /b /ah" and "dir /s /b /a-h" on the same drive, and save the results.
# Run a clean version of WinDiff from the CD on the two sets of results to detect file-hiding ghostware (i.e., invisible inside, but visible from outside).

UBCD4Win>Rootkitty is a tool that apparently automates this process.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #28  
Old November 25th, 2009, 08:51 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

gmer has a userland detector, catchme which can collect, delete and kill malicious files.

BreakPE is a nice little tool.
Quote:
BreakPE takes different approach to stealth malware removal. This program makes malware unexecutable by overwriting disk sectors where it is stored. In more technical terms BreakPE damages PE header of specified file by overwriting it directly on the volume.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #29  
Old November 25th, 2009, 09:38 AM
Keyboard_Commando's Avatar
Keyboard_Commando Keyboard_Commando is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 682
Default Re: Which Rootkit Removal Tool do you use?

ESET SysInspector.

32 & 64 bit.

Having used many of those mentioned ... I'd say SysInspector is the most user friendly of the lot. Google is your best friend with these!

Has a feature that can "exclude private, personal information from being saved in logs", though I am not entirely sure what and how it hides the info ... I am guessing file user names, etc. Quite handy if you're sending a system log to be analyzed by a stranger.

http://www.eset.com/download/sysinspector.php
  #30  
Old November 25th, 2009, 10:39 AM
ASpace
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

GMer , RootRepeal and Microsoft's Rootkit Revealer.

On Windows 7 - GMers sometimes gives me BSOD , RootRepeal can't start at all and RootkitReleveal has problems displaying the messages.

On Vista and XP - no problems .

I am most pleased by GMer.
  #31  
Old November 25th, 2009, 11:57 AM
progress
 
Posts: n/a
Unhappy Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by ASpace
On Windows 7 - GMers sometimes gives me BSOD.

I noticed this behaviour too
  #32  
Old November 25th, 2009, 03:37 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

RootkitRevealer is not meant to be run on an OS above xp and 2003 (or on 64bit) it will not produce a coherent result - vista, 7 and 2008, and is also considered outdated.

7 has not been out long and some tools need to be worked on because of the differing structure of the OS. Also remember the ark will have to be run elevated - r/click run as administrator.

Some problems with RootRepeal maybe due to individual system incompatibility. If anyone has a problem try moving the slider in Options and uncheck 'Use lowest level for MBR check.'
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #33  
Old November 25th, 2009, 03:57 PM
ASpace
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by ance
I noticed this behaviour too

It was a "big fun" for me the first time it happened because generally if this happens , it might be a sign of a rootkit . I didn't have time to see the name of the guilty file (the first blue screen I got) . Later I noticed it , checked it and ensured myself the system was clean
  #34  
Old December 1st, 2009, 05:18 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by geohac
Thanks for the link, but that version is unstable. What is the most stable version?
RkU was updated again version 3.8 LE build 383/585 Service Release 1
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #35  
Old December 2nd, 2009, 11:20 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

New XueTr v3.0, works on 2000 to 2008 including 7 and comes with extra help in dealing with malware, check out settings...
Attached Thumbnails
Click image for larger version

Name:	xuetr32.JPG
Views:	8
Size:	64.6 KB
ID:	213993  

Click image for larger version

Name:	xuetr3.JPG
Views:	4
Size:	145.9 KB
ID:	213994  

__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #36  
Old December 2nd, 2009, 11:28 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

NT Internals is putting a list together with the tools that deal with TDSS/TDL.

TDL author/s have included some lines from Fight Club and Simpsons Movie into their rootkit see also here(tdl3_analysis_paper_ed.rar) They seem to be really busy with numerous builds...TDL4 soon?
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : December 2nd, 2009 at 02:23 PM.
  #37  
Old December 2nd, 2009, 02:15 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Hidden Process Detection Test - by NT Internals.

Sysinternals
Quote:
I've also created short video sample showing final results of process detection by the most advanced software.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #38  
Old December 4th, 2009, 05:59 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

RkU was updated again to 3.8 LE build 383/586 Service Release 1
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #39  
Old December 9th, 2009, 12:44 AM
icr icr is offline
Very Frequent Poster
 
Join Date: Sep 2008
Location: Mumbai
Posts: 1,588
Default Re: Which Rootkit Removal Tool do you use?

My vote for sophos AR never used frequently though.
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01101001 01100011 01110010

--->My Blog<---
  #40  
Old January 7th, 2010, 02:50 PM
progress
 
Posts: n/a
Lightbulb Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by icr
My vote for sophos AR

It seems to be compatible with Win 7 but I got several 'FP' ...
  #41  
Old January 20th, 2010, 06:47 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Only just noticed the update.

Rootkit Unhooker LE 3.8.386.588 SR1

I like the ease of this tool, the management the way it operates and appearance. Strong and always been stable for me.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #42  
Old February 6th, 2010, 12:07 AM
Saint Satin Stain's Avatar
Saint Satin Stain Saint Satin Stain is offline
Regular Poster
 
Join Date: Feb 2004
Location: Huntsville, AL and Greenwich Village, NYC
Posts: 199
Default Re: Which Rootkit Removal Tool do you use?

GMER and Sophos but also IceSword, Rootkit Unhooker, RootkitRevealer, RootRepeal, and SpyDLLRemover. They never find anything. My realtime apps are
Online Armor
Prevx
Sandboxie.
__________________
saint satin stain
Sandboxie,SpywareBlaster,Webroot SecureAnywhere Complete,Windows XP firewall,,Gmer,Malwarebytes' Anti-Malware
  #43  
Old February 19th, 2010, 07:36 PM
ameyap ameyap is offline
Regular Poster
 
Join Date: Feb 2010
Posts: 87
Default Re: Which Rootkit Removal Tool do you use?

luckily for me since i started using vista i never had to use a rootkit for removing anything
  #44  
Old February 20th, 2010, 12:39 AM
3GUSER 3GUSER is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 813
Default Re: Which Rootkit Removal Tool do you use?

ComboFix and GMer
  #45  
Old February 22nd, 2010, 08:12 PM
Brian_12
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by ameyap
luckily for me since i started using vista i never had to use a rootkit for removing anything
64bit?
  #46  
Old February 24th, 2010, 06:21 AM
guest
 
Posts: n/a
Default Re: Which Rootkit Removal Tool do you use?

I don't use any of these tools. My current AV, Microsoft Security Essentials, already includes anti-rootkit features.
  #47  
Old February 26th, 2010, 07:34 AM
leofelix's Avatar
leofelix leofelix is offline
Regular Poster
 
Join Date: Sep 2009
Location: Italy
Posts: 171
Default Re: Which Rootkit Removal Tool do you use?

I generally do not use rootkit scanners for myself since I use on different computers ESET NOd32, GData antivirus or Avira as antivirus and a MalwareBytes' AntiMalware, Moosoft The Cleaner and A-Squared as antimalware which have rootkit removal ability.
Windows is always up to date and so Sun Java JRE, Adobe Reader and Flash Player and my main browser.
I practice a safe surfing and I always download and install software only from trusted sources.

However if I have to clean infected systems I generally trust Gmer, MBAM and Trend Micro RootkitBuster (Well, it depends on what kind of Rootkit I have to clean: the most difficult to remove are MBR rookit in my opinion)

Do anyone ever heard of Tizer™ Rootkit Razor?
It is free, only free registration is needed.

I'd like to know your opinion if possible,

Thank you
Attached Images
 
  #48  
Old February 26th, 2010, 08:22 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Razor is mentioned in this thread and although it cannot see some of the modern rootkits they are working on it.

Quote:
...the most difficult to remove are MBR rookit in my opinion
Hmmm MBR rootkit imo is one of the 'easiest' to remove.

Quote:
...trust Gmer, MBAM and Trend Micro RootkitBuster
MBAM has some v.good people that keep on top of the latest infections. RootkitBuster is worked on by old Darkspy antirootkit author.
Its been said before but there isn't a best ark only up to date ones, and I can mention a few :

Rootkit Unhooker
Kernel Detective
Root Repeal

List of arks.

I really must stay away from my machine on holiday
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #49  
Old February 26th, 2010, 08:33 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Which Rootkit Removal Tool do you use?

Quote:
Originally Posted by guest
I don't use any of these tools. My current AV, Microsoft Security Essentials, already includes anti-rootkit features.
Think about TDL rootkit as an example, of course talking about an active rootkit, avs are not removing it - although its gotta get on in the first place. These anti-rootkit features aren't antirootkit.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #50  
Old February 26th, 2010, 08:36 AM
leofelix's Avatar
leofelix leofelix is offline
Regular Poster
 
Join Date: Sep 2009
Location: Italy
Posts: 171
Default Re: Which Rootkit Removal Tool do you use?

Thank you Meriadoc...

MBR Rootkit the easiest to remove?:-)
I'm pretty sure your help would greatly appreciated in several italian security forums I know, since it seems that you cannot get rid of a MBR rootkit simply formatting your HD (both high level and low level format) and there are some (Italian) users who are driving crazy
Someone solved with zero-filling techique as far as I know.

Generally I first try with Stealth MBR rootkit/Mebroot/Sinowal detector by Gmer and other similar tools.
Well I'm not a security expert nor an hardware technician, I'm only interested in security stuffs, so I cannot tell more

thank you again I'm going to have a look at the thread you linked

Cheers

[EDIT to add]

I have just read your reply

Quote:
Originally Posted by Meriadoc

example of hot samples that razor didn't detect.

TDSS
TDL
Rustock
4DW4R3

OMG, once again thank you (for the link provided too)

Last edited by leofelix : February 26th, 2010 at 08:52 AM.
 

Wilders Security Forums > Other Topics > polls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:58 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums