The best rootkit cleaner?

Discussion in 'other anti-malware software' started by Biscuit, Oct 21, 2010.

Thread Status:
Not open for further replies.
  1. Biscuit

    Biscuit Registered Member

    Joined:
    May 26, 2006
    Posts:
    978
    Location:
    Isle of Man
    Hi

    Can anyone recommend the best rootkit cleaning tool? I have a pc that is infected with a rootkit, which cannot be cleaned by Malwarebytes, Prevx or Combofix.
     
  2. ReverseGear

    ReverseGear Guest

    Gmer , Sophos anti rootkit , rootkit unhooker ... there may be more
     
  3. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    @ Biscuit

    First off, how do you know you got one ?

    If you know what it is, how did you find out, and what is it ?
     
  4. Boyfriend

    Boyfriend Registered Member

    Joined:
    Jun 7, 2010
    Posts:
    1,070
    Location:
    Pakistan
    @Biscuit: Which rootkit? If specific name can be found, then use specialized rootkit tools like stuxnet, TDSS, Ransomlock etc.

    I will sugget you following tool:
    GMER
    Panda Anti-Rootkit
    Helios-Lite AntiRootKit
    DarkSpy AntiRootKit
    F-Secure BlackLight
    IceSword
    NIAPSoft AntiRootkit Tools
    RootkitBuster
    TDSSKiller
     
  5. Gobbler

    Gobbler Registered Member

    Joined:
    Jul 30, 2010
    Posts:
    270
    Dr.Web CureIT ran in safe mode and if it doesn't work, run it from UBCD4win.
     
  6. progress

    progress Guest

    No tool because it's nearly impossible to clean a rootkit infection :doubt:
     
  7. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,920
    +1

    Clean Image or backup.
    Improve security!
     
  8. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    hitman pro
     
  10. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    hitman pro for sure will help:thumb:
     
  11. Biscuit

    Biscuit Registered Member

    Joined:
    May 26, 2006
    Posts:
    978
    Location:
    Isle of Man
    Hi, thanks for your reply.

    I had cleaned the computer, but from my experience I guessed that it was still infected & probably by a rootkit. Boot & shutdown were taking a while & I was unable to correctly install Prevx which would freeze on it's first scan & had no processes running. Also about 50% of the time, the explorer process would not load properly.

    As I had bought Prevx for this computer, I contacted Prevx support who within the hour, remotely connected to the pc & cleaned the infection. It was the TDSS rootkit.

    Thanks for all your replies & thanks Dave from Prevx.
     
  12. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Backup, but for the sake of repeating oneself, the tool that can remove the rootkit.

    As you found anyone with Prevx will be helped to remove anything awkward by their support...maybe they keep their tdss removal tool private.
     
    Last edited: Oct 22, 2010
  13. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    @ Biscuit

    Ah well you didn't say it was a paid version in your original post ! If you had i was going to let you know that prevx will help you clean up ;)

    Nasty :eek:

    Surprised MBAM failed !

    How did you get infected with it ?

    I see you're on Windows 7 32bit Ultimate too :p
     
  14. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    simple, use Avast for cleaning a rootkit
     
  15. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    not that simple sometimes :)
     
  16. element119

    element119 Registered Member

    Joined:
    Jul 14, 2008
    Posts:
    72
    rootkits are getting to be very common. i've had to remove them on systems with avast, mse, avira, avg... dr web has been doing a good job for me, it found one in the MBR yesterday.
     
  17. Serapis

    Serapis Registered Member

    Joined:
    Nov 15, 2009
    Posts:
    241
    Use sandboxie and never have to worry about any rootkits whatsoever
     
  18. Biscuit

    Biscuit Registered Member

    Joined:
    May 26, 2006
    Posts:
    978
    Location:
    Isle of Man
    I made the post because in the past I have found that getting Prevx remote support can take days or even weeks. I assumed that I was going to have to fix it myself, hence the post.

    The infection came from a teenager. :rolleyes:

    The pc was not mine, it was XP & "protected" by McCrappy. The browser was IE.
     
  19. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Really o_O I havn't noticed that delay in the Prevx forum !

    Typical :D
     
  20. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  21. markusg

    markusg Registered Member

    Joined:
    Jun 10, 2009
    Posts:
    248
    for most rootkits you can use gmer to find out what kind of rootkit is it and after this use combofix, but perhaps you have to create scripts to remove your rootkit. for some rootkits you have special cleaner, without knowing what kind of rootkit you have, nobody can say you what cleaner you have to use.
     
  22. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    i think the best anti-rootkit app, GMER, scored only over 80% in detecting rootkits.

    what good is 80%?
    AFAIC it's just as bad as 0%.

    the only logical solution is to prevent them getting into a computer in the first place.

    the best anti-rootkit cleaner?
    a clean system image to restore from i think.
     
    Last edited: Oct 30, 2010
  23. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,351
    Although the problem is already solved, for me one of those who clean this virus the best Hitman Pro. :thumb:
     
  24. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    yes hitman pro;) :thumb:
     
  25. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    what about prevxo_O
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.