![]() |
|
#1
|
|||
|
|||
|
hi i am looking for a good rootkit finder preferably one that is easy to use but if not thats ok to.
thanks winter |
|
#2
|
||||
|
||||
|
Gmer
|
|
#3
|
||||
|
||||
|
prevx, hitman pro, dr. web cureit
![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
#4
|
|||
|
|||
|
Rootkits
-GMER, UnHackMe, Teazer Rootkit Razor, and for TDSS (Kaspersky). -Prevx, HMP, EAM, and Dr.Web CureIt! Trojans MBAM, SAS, EAM, Dr.Web CureIt!, HMP etc. Last edited by PJC : January 27th, 2011 at 08:52 AM. |
|
#5
|
|||
|
|||
|
ok i used gmer and noticed that most of the upper check boxes on right hand side are greyed out. is there a payed version of this or?
|
|
#6
|
||||
|
||||
|
Depends on skills, some peeps at this forum don't need to use an ARK to find RK's, they use debuggers to analyze code and are familiar with all of the tricks used by malwares.
Others are Tool Operators, like myself, less skilled relying on the data we are given by the tool to determine our direction. GMER is so often used that malware authors have designed around it. When something is active on the system there will sometimes be a lack of information, crashing, or non working features of the tool. It's a clue that something is not right and requires further attention. At GMER's default settings, after it completes it's preliminary scan, all check boxes on the right should be accessible. If not, then something is wrong. There are many ARK's available, check out kernelmode.info forum for a very thorough list.
__________________
Americans are the enemy? Mil. can arrest you? What the heck is going on? |
|
#7
|
||||
|
||||
|
For rootkits: GMER, Sophos Antirootkit, MBAM, Prevx, & HMP. I believe GMER is the best though. I've also heard that Combo fix is great, but i've never used it myself and it can be dangerous to use if you don't know what your doing.
Trojans: Avira, Gdata, Kasparsky, HMP, & Hijack This.
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | WSA | Appguard | VoodooShield | Shadow Defender 1.1.0.325
|
|
#8
|
||||
|
||||
|
Quote:
|
|
#9
|
||||
|
||||
|
Quote:
Are GMER "safe" to use, I mean will it not make any problems in your pc after it disabled and deleted what it finds?
__________________
Eset NOD32 Sandboxie Firefox "The Internet? We are not interested in it" - Bill Gates, 1993 http://www.gatesfoundation.org/Pages/home.aspx “We are coming to think of God as dwelling in man rather than as operating on men from without.” - Lyman Abbott |
|
#10
|
||||
|
||||
|
EAM is a great tool.
As others mentioned: HMP, GMER, Combofix (Although i've never used it, lots of people recommend it)
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
#11
|
|||
|
|||
|
Trojans: MBAM
|
|
#12
|
|||
|
|||
|
Trend Micro Rootkit Buster is easier to use. But like any other anti rootkit it is important to analyse the results.
|
|
#13
|
||||
|
||||
|
tizer rootkit razor looks good and doing a great job.
__________________
switching from one AV to another very often Rollback RX On demand: HitMan Pro |
|
#14
|
||||
|
||||
|
Quote:
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | WSA | Appguard | VoodooShield | Shadow Defender 1.1.0.325
|
|
#15
|
|||
|
|||
|
Quote:
|
|
#16
|
||||
|
||||
|
Quote:
Gmer is built into avast!, Gmer is now owned by avast!. The developer of Gmer now works for avast!. IMHO, Gmer is the best rootkit finder. I like MalwareBytes Antimalware Free for scanning for trojans.
__________________
Bitdefender Free Edition | Norton ConnectSafe | Mbam Pro | WinPatrol Plus | ZA | 7 64bit | "If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh |
|
#18
|
|||
|
|||
|
|
|
#19
|
||||
|
||||
|
I'm a total noob @ rootkit detecting/removing. So what is the easiest rootkit finder to use? thanks
__________________
Desktop (WinXP x32): COMODO Internet Security Premium + Sanboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Laptop (Win7 x64): Avast! Free Antivirus + Sandboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Phone (BlackBerry 8520): NetQin
|
|
#20
|
||||
|
||||
|
Hitman Pro or an AV Rescue CD like Dr.Web.
__________________
|
|
#21
|
||||
|
||||
|
Quote:
__________________
Desktop (WinXP x32): COMODO Internet Security Premium + Sanboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Laptop (Win7 x64): Avast! Free Antivirus + Sandboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Phone (BlackBerry 8520): NetQin
|
|
#22
|
||||
|
||||
|
Quote:
First try the scanners provided by various antivirus vendors. If that doesn't work then go for complex tools like Gmer. Here are some good scanners: 1. Dr. web cure it 2. Kaspersky AVP tool. 3.Microsoft Safety Scanner 4.Fsecure Easy clean. good luck.
__________________
|
|
#23
|
||||
|
||||
|
Better than Gmer (include in avast and Mbam) you can use Icesword, but it's not designed for vista and 7.
__________________
Wait and See |
|
#24
|
||||
|
||||
|
Run these in order
Rkill http://download.bleepingcomputer.com...r/iExplore.exe SAS http://www.superantispyware.com/sasportable.php Malwarebytes http://www.filehippo.com/download_ma..._anti_malware/ Tdskiller http://support.kaspersky.com/downloa...tdsskiller.zip Combofix<-Rename it to Jenip.com http://www.Combofix.org
__________________
I've discovered that people on IRC don't get offended or riled up by racism, nor politically incorrect jokes, nor feminism, nazism, nor goatse, or even tubgirl, not even jokes about 9/11 get a rise out of anybody but as soon as I tell somebody that macs are better than PCs, things get ugly. |
|
#25
|
||||
|
||||
|
Good threads with good suggestions. Thanks all!
__________________
Desktop (WinXP x32): COMODO Internet Security Premium + Sanboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Laptop (Win7 x64): Avast! Free Antivirus + Sandboxie + Emsisoft Emergency Kit + VirusTotal Uploader + SpywareBlaster Phone (BlackBerry 8520): NetQin
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|