Good anti-rootkits for Win 7

Discussion in 'other anti-malware software' started by aigle, Feb 12, 2010.

Thread Status:
Not open for further replies.
  1. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Meriadoc

    Thanks for the test. Hope you can be of help to Tizer.

    pradeepschandra

    Nice to see you responding.

    3GUSER

    That's good to know :)
     
  2. pradeepschandra

    pradeepschandra Registered Member

    Joined:
    Feb 20, 2010
    Posts:
    5
    Hi Meriadoc,

    I will be glad to see your pm for your interest in discussing rootkit detection algorithm.

    PS : Please find some spare time if possible.

    Regards
    Pradeep
     
  3. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Yes you were pmed :)
     
  4. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    XueTr works on 7.
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    What is the download link for it? Is it good?
     
  6. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
  7. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    XueTr showing some of TDL3 - DriverObject
     

    Attached Files:

    Last edited: Feb 26, 2010
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks. So how will you compare it with RKU, gmer and RootRepeal?

    Thanks
     
  9. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    ...pmed
     
  10. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks
     
  11. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    XueTr reports a suspicious driver object after installing avast 5. o_O
     
  12. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Is it aswSP.SYS? If so, this is normal. It's avast!'s self-protection module.
     
  13. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    Unfortunately it doesn't say. XueTr says the object is not signed either. So maybe your right or maybe it's just a quirk with XueTr.
     
  14. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    If you post a screenshot of XueTr it would help me verify that we're looking at the same thing. I checked again and the drivers I see on my system don't sound like what you're describing.

    EDIT: I just realized that this is a Win7 thread and I'm on XP. :oops: I may not be much help. Maybe someone else with the same OS as you will reply.
     
  15. pradeepschandra

    pradeepschandra Registered Member

    Joined:
    Feb 20, 2010
    Posts:
    5
    Thanks to Meriadoc for reporting the TDL3 4DW4R3 detection issue with Tizer Rootkit Razor. We have downloaded the rootkits and run several tests after which we have successfully completed necessary upgrades for Rootkit Razor so that it is now able to detect TDL3 4DW4R3 and Rustock and safely remove them. During our testing, we noticed that TDL3 4DW4R3 appeared to have been updated over the internet by the malware writers last weekend, after which the latest version is not fully removable (though it is detected by some) by any of the other currently available rootkit removal tools. We have updated Rootkit Razor to detect and safely remove both Rustock and the latest version of TDL3 4DW4R3. Please see screen shots of detection

    Screen Shot 1

    Screen Shot 2

    We invite your comments and useful suggestions for any further improvements that we can make to better meet user requirements. We would also be glad to receive any reports of new rootkits that you may find or any new malware samples for our analysis and testing. We look forward to receiving support from the user community that will help us launch better tools for your internet security.

    You can download Tizer™ Rootkit Razor here.

    PS: If you are testing, please restart your system after installing rootkits.

    Best regards,
    Tizer Secure™ Support
     

    Attached Files:

    Last edited: Mar 5, 2010
  16. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    So far only tested against TDL 3.273

    FAIL

    confirmed
     

    Attached Files:

    • fail.JPG
      fail.JPG
      File size:
      12 KB
      Views:
      1,046
  17. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
  18. pradeepschandra

    pradeepschandra Registered Member

    Joined:
    Feb 20, 2010
    Posts:
    5
    Tizer™ Rootkit Razor was updated recently to be able to detect and safely remove the dangerous rootkits Rustock and 4DW4R3. It is not yet able to detect TDL3, but we have launched a separate utility called Tizer™ TDL3 Razor which has been tested and is able to safely remove the TDL3 rootkit from Windows XP 32-bit machines that have either atapi.sys or iaStor.sys hard disk drivers. Screen shots of successful detection and cleaning are given on http://www.tizersecure.com/about_TDL3_rootkit_detect_remove.php.

    Please note that the rootkit is safely removed only on reboot of the machine, as per the instructions on the dos screen.

    This fourth product we have released is specifically for the TDL3 rootkit, which is a botnet. About 50-60 million computers worldwide are infected by botnets.

    Download the free Tizer™ TDL3 Razor utility here.

    Regards
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.