Anti-rootkits

Discussion in 'other anti-malware software' started by ako, Jan 21, 2010.

Thread Status:
Not open for further replies.
  1. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    Testing rootkits is too time-consuming and I'm also not competent for that. My question is: How big percentage of rootkits are still using basic methods easily detected by most tools?
    Ie. are eg. Sophos anti-rootkit anf F-secure blacklight usually OK, or does one usually need more advanced tools?

    PS. What do you think of Unhackme?
     
  2. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
  3. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    Thanks! :):thumb:
     
  4. dcrowe0050

    dcrowe0050 Registered Member

    Joined:
    Sep 1, 2009
    Posts:
    378
    Location:
    NC
    Sophos is still good as it is fairly regularly updated but I don't use it too much, my favorites to use are RootRepeal and RkU and they work great. The only problem with Sophos is the fact that unless you have Sophos AV then the anti rootkit only does a basic scan, and if you do have the AV it unlocks the extensive scan feature. I think that since most of the anti rootkit tools are not updated regular anymore its best if you have the know how, to use something like RootRepeal, RkU, GMER
     
  5. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    i use prevx always for rootkits detentions,i clean a very infected pc the other day with tons of malware including 2 rootkits and prevx did the job very well;)
     
  6. progress

    progress Guest

    Are there any anti-rootkits for Win 7 except TrendMicro RootkitBuster? :)
     
  7. dcrowe0050

    dcrowe0050 Registered Member

    Joined:
    Sep 1, 2009
    Posts:
    378
    Location:
    NC
    Sophos and RkU both run on Win 7 and Prevx of course. RkU and Sophos were both updated recently. As far as the rest, most of them have ended support, Blacklight will not run I think that Mcaffee Rootkit Detective is in beta but I am not sure, and I dont know about Panda. Rootkit Unhooker is definitely the best of those in my opinion.
     
  8. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    Does MAM check for rootkits?
     
  9. dcrowe0050

    dcrowe0050 Registered Member

    Joined:
    Sep 1, 2009
    Posts:
    378
    Location:
    NC
    It will detect some but not the more advanced rootkits.
     
  10. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    Am I right? There are two kinds of rootkits (forget Blue pill and other aliens):

    1) MBR-rootkits (these need special treatment, as data is stored on empty disk areas)

    2) Others (hidden files can be found eg. with UBCD4win (boot-cd) and Rootkitty (reads files outside and inside of the system) http://www.ubcd4win.com/forum/index.php?showtopic=2424 )

    Am I missing something?

    How big percentage of rootkits are using basic methods (some basic SSDT-hooking eg.) easily detected by most vendor tools (Avira, Sophos, etc.)? Or is it so, that if rootkits are used, they are usually technically high-level products?
     
  11. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Well there is (POCs, Hypervisor) bootkits, kernel, userland, library. So yes basically two with three types that modify kernel or processes, files, connections etc, persistent or memory based.

    Sorry I don't have any figures to hand.
     
    Last edited: Jan 22, 2010
  12. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    And on what do you base this claim?
     
  13. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,347
    Location:
    Europe, UE citizen
    Much better to use deeper software as GMER, RootRepeal....OSAM too..
     
  14. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    what is osam?
     
  15. nikanthpromod

    nikanthpromod Registered Member

    Joined:
    Oct 9, 2009
    Posts:
    1,369
    Location:
    India
    Online Solutions Autorun Manager
     
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thanks:D
     
  17. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    No problem. This was clear explanation. :thumb:
     
  18. dcrowe0050

    dcrowe0050 Registered Member

    Joined:
    Sep 1, 2009
    Posts:
    378
    Location:
    NC

    Right and all these can be sorted into different levels.
    Application level
    Kernel level
    Library level
    Virtualized
    Firmware
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.