whats the best rootkit and trojan finder

Discussion in 'other anti-trojan software' started by winterlord, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. RJK3

    RJK3 Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    862
    Offline
    Mount it offline, and save time with a custom scan of just the system32 folder with the following:
    Dr Web CureIT
    SAS
    Microsoft Malicious Software Removal Tool
    (Hitmanpro if you have the paid version.)
    even McAfee Stinger

    This'll save time. If they don't detect the rootkit here, then a full scan would have been a waste of time anyway.

    While you're scanning, check for hidden partitions, and check the MBR and autoruns (offline registry, win.ini, etc). You can also manually check the usual spots for standard trojans e.g. ProgramData, Program files, Appdata, etc. As long as you've deactivated the method for any trojans to start, then it's not so important to scan and remove them all offline. Manually search and delete any autorun.inf files.

    Replace any detected system files with originals from the Windows install media.


    Online
    Malwarebytes QUICK scan
    > Hijackthis / Sysinternals autoruns
    HitmanPro quick scan
    TDSSKiller
    Combofix
    then repeat with FULL scans from various tools e.g. Kaspersky AVPTool and leave it to scan.


    It's not necessarily the most skilled way, but can be quick & effective to use some of these elements.
     
    Last edited: Jul 5, 2011
  2. Jose_Lisbon

    Jose_Lisbon Registered Member

    Joined:
    Feb 5, 2010
    Posts:
    245
    Location:
    Portugal
  3. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Yes, I've used this before, and still do from time to time.

    Edit: Actually I keep forgetting about this one (Theres so many) until someone here mentions it.
    Small download
    Fast updates
    Quick scans
     

    Attached Files:

    Last edited: Jul 8, 2011
  4. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    which one do u consider to be most reliable:)
     
  5. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Thats a tough one sense my security setup strategy has been focused on prevention instead of detection and cure. Anytime I scan using any scanner if I get a hit its a FP. I haven't been infected in over five years.
     
  6. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    Trojan Remover! :thumb:
     
  7. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    but Sophos Anti-Rootkit 1.5.4 is pretty old 2009-07-14
     
  8. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    for me it is hitman pro and combofix;)
     
  9. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    A shame that combofix is 32bit only.
     
  10. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Not a shame most rootkits are. I don't have (or need) a dedicated rootkit finder anymore.
     
  11. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Most but not all.

    I don't exactly feel threatened by rootkits on 64bit but if I'm going to do a scan I want to be sure.
     
  12. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    than hitman pro is the solution;)
     
  13. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    howz eset sys inspector against rootkitso_O?
     
  14. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    never try it:D
     
  15. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  17. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    like it:D
     
  18. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    anyone here using eset sys inspector??:rolleyes: and if yes ..is this effective?
     
  19. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    is it included in the antivirus program or in the security package?thanks
     
  20. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
  21. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thanks alot
     
  22. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Anytime!

    TH
     
  23. RJK3

    RJK3 Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    862
    At rootkits? Not particularly:
    Comparitive Analysis of Rootkit Detection Techniques, May 2011:
    http://sce.uhcl.edu/yang/research/A Comparitive Analysis of Rootkit Detection Techniques.pdf

    Useful that it can detect things like drivers that seem dodgy, e.g. if running out of a temp folder. Clunky interface.

    Most of the antirootkits are out of date, last worked on in 2008.

    Of the dedicated antirootkits, only RKU found all four rootkits without false positives according to table 7. GMER missed one.

    For cleaners (excluding antivirus suites), Malwarebytes and Combofix did the best. Hitmanpro wasn't included in the testing.
     
  24. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  25. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    + :thumb: :thumb: I downloaded that report for further reading later. ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.