Rootkit detection review

Viruses, hackers and crackers
Post Reply
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Rootkit detection review

Post by rustypup »

Information Week wrote:In October 2005, Windows expert Mark Russinovich broke the news about a truly underhanded copy-protection technology that had gone horribly wrong. Certain Sony Music CDs came with a program that silently loaded itself onto your PC when you inserted the disc into a CD-ROM drive. Extended Copy Protection (or XCP, as it was called) stymied attempts to rip the disc by injecting a rootkit into Windows — but had a nasty tendency to destabilize the computer it shoehorned itself into. It also wasn't completely invisible: Russinovich's own RootkitRevealer turned it up in short order. Before long, Sony had a whole omelette's worth of egg on its face, and the word rootkit had entered the vocabulary of millions of PC users.
included in the comparative review:
BlackLight
IceSword
RKDetector
RootkitBuster
RootkitRevealer
Rootkit Unhooker

Take the warning about "careful" use to heart, as these apps cannot distinguish between genuine system files and not so kosher ones...

now, if only there were some way of obliterating starforce after uninstalling its targeted app :evil:
Last edited by rustypup on 30 May 2007, 13:36, edited 1 time in total.
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Post by Anakha56 »

JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Gatsby
Registered User
Posts: 1294
Joined: 14 Dec 2005, 02:00
Location: with stupid.

Post by Gatsby »

My Bitdefender 10 has a built in rootkit scanner and remover. I wonder how good it is.
Image

Lazarus - Shattered Halls

ek se hosh. dala kulids. ghle, ho! oom, atts! hoe lyk die kambotcha? gwallafest 2007
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Post by rustypup »

rootkit unhooker has got to be the most comprehensive i've seen to date...

ice-sword comes with a command line plug-in which allows you to modify the file hives directly... so scrubbing those hard to remove files is a synch, (this is *not* a toy to be played with... unless the idea of re-installing sounds kinky..)
Most people would sooner die than think; in fact, they do so - Bertrand Russel
DeathStrike
Registered User
Posts: 2663
Joined: 29 Jul 2004, 02:00
Location: hidden deep in the depths of the underworld is my home.
Contact:

Post by DeathStrike »

Sorry for my Noob question but what are rootkits? :oops:
Spoiler: (show)
Image
SIG by HMAN 8)
Member of The Pride Of Darkness
DeathStrike on Twitter
About me
Spoiler: (show)
Asus P5KPL-CM motherboard, 4 GIG RAM, Q6600 @ 2.88GHz (Thanks Anthro), GeForce 8600GT, Samsung 2333 23" + CRT 17" Monitors. 500GB + 1.5TB HDD, Compro TV tuner, 350 WATT PSU
User avatar
Ron2K
Forum Technical Administrator
Posts: 9050
Joined: 04 Jul 2006, 16:45
Location: Upper Hutt, New Zealand
Contact:

Post by Ron2K »

DeathStrike wrote:Sorry for my Noob question but what are rootkits? :oops:
Nasty little buggers.

http://en.wikipedia.org/wiki/Rootkit
Kia kaha, Kia māia, Kia manawanui.
DeathStrike
Registered User
Posts: 2663
Joined: 29 Jul 2004, 02:00
Location: hidden deep in the depths of the underworld is my home.
Contact:

Post by DeathStrike »

Nasty. Where do i get 1 of those remover things? and how wud u know if your pc is infected?
Spoiler: (show)
Image
SIG by HMAN 8)
Member of The Pride Of Darkness
DeathStrike on Twitter
About me
Spoiler: (show)
Asus P5KPL-CM motherboard, 4 GIG RAM, Q6600 @ 2.88GHz (Thanks Anthro), GeForce 8600GT, Samsung 2333 23" + CRT 17" Monitors. 500GB + 1.5TB HDD, Compro TV tuner, 350 WATT PSU
PHR33K
Registered User
Posts: 779
Joined: 05 Sep 2004, 02:00
Contact:

Post by PHR33K »

As a rootkit writer I personally would choose Rootkit Unhooker.
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Post by rustypup »

DeathStrike wrote:and how wud u know if your pc is infected?
i would like to reiterate the point about not mucking with the file hives... it really is the quickest route to trashing your installation... some legitimate files, by their very nature, will not appear as a fat entry...

best approach is to scan, make a short list of suspects and then spend some time verifying if they are legit or not... those that you fail to verify, or that pop up as known kits, can be trashed...
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Post Reply