Jump to content


Anti-Rootkit programs


38 replies to this topic

#1 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 11 July 2007 - 09:56 PM

How important are these programs? I currently don't have any installed but looking at two right now. AVG Anti-Rootkit and Panda Anti-Rootkit. Anybody use these two and are these types of programs something we should all have like an AV or AS program? I don't see any mention of them on here.

#2 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 11 July 2007 - 11:01 PM

I just few days ago installed that AVG Anti-Rootkit program. There's also i.e. F-Secure Blacklight and RootkitRevealer.

I think it's good to scan for rootkits once a while, just to be sure.

#3 OFFLINE   Tarq57

    Advanced Member

  • Members
  • PipPipPip
  • 297 posts

Posted 11 July 2007 - 11:09 PM

I have the AVG one, seems alright. Also have Blacklight available, and Rootkit revealer.
Some of the results do need a bit of knowledge to action correctly, not everything flagged is necessarily a rootkit. Help files definitely worth reading.

#4 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 11 July 2007 - 11:31 PM

View PostCeeCee, on Jul 11 2007, 07:01 PM, said:

I just few days ago installed that AVG Anti-Rootkit program. There's also i.e. F-Secure Blacklight and RootkitRevealer.

I think it's good to scan for rootkits once a while, just to be sure.
I installed and tried the AVG Anti-Rootkit. Didn't find anything which is a good thing. Not much to it. I will keep this one just to be sure.

Also tried the Panda Anti-Rootkit. This was recommended on the 46 Best Ever Free Ware List as the guys first choice for Anti-Rootkit programs. This one requires no install. Unzip and run. Also found nothing.

#5 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 11 July 2007 - 11:40 PM

AVG Anti-Rootkit installs two driver (.sys) files to system32/drivers folder and they are loaded to memory every time when Windows is booted. I don't like it very much. I scanned once with AVG AR and then stopped them from loading with AutoRuns.

#6 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,324 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 11 July 2007 - 11:50 PM

AntiVir PE Classic also has a root-kit scanner. For people using it they have anti-virus and anti-rootkit all in one app, I'd use it too if it weren't for the update problems I keep having with AntiVir.
Complexity of incoherent design.

#7 OFFLINE   Tom AZ

    Power Member

  • Members
  • PipPipPipPip
  • 941 posts
  • Location:Scottsdale, AZ USA

Posted 12 July 2007 - 12:12 AM

View PostCeeCee, on Jul 11 2007, 11:40 PM, said:

I scanned once with AVG AR and then stopped them from loading with AutoRuns.

Could you elaborate on this procedure of stopping them from loading? Thanks.

#8 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 12 July 2007 - 12:18 AM

View PostTom AZ, on Jul 12 2007, 12:12 AM, said:

Could you elaborate on this procedure of stopping them from loading? Thanks.

Just download AutoRuns. Launch Autoruns.exe and go to "Drivers" tab. Uncheck "AVG Anti-Rootkit driver" and "AVG7 Clean Driver". Then just close AutoRuns program. Of course you can't use AVG Anti-Rootkit after that. When you want use it again, just check those drivers and reboot Windows.

#9 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 12:45 AM

The Panda Anti-Rootkit seems decent. It's really simple to use has a clean GUI and no install. Even has a option to run the scan on start up. You check the option and reboot. The scan starts at start up. It's a more thorough scan the regular one. Here is the help file with some screen shots in it. Only takes 5 min to go through.

http://www.pandasoftware.com/download/docu...c_en.htm#20.htm

#10 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 12 July 2007 - 01:07 AM

Panda Antirootkit crashes on me, when it's scanning registry. I get error "memory could not be written". ?? I got XP SP2.

EDIT: Others got also problems with 1.08. http://research.pandasoftware.com/blogs/re...rsion-1.07.aspx

Andrew, cham44, Jack, Sam and the rest of you running into problems with 1.08 during the registry scan, I have uploaded version 1.07 to http://research.pandasoftware.com/blogs/im...ootkit-1.07.zip. Please try running 1.07 but still send me the details of your machine and installed applications to pbustamante'at'pandasoftware.com.

That 1.07 works fine.

#11 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 03:14 AM

View PostCeeCee, on Jul 11 2007, 09:07 PM, said:

Panda Antirootkit crashes on me, when it's scanning registry. I get error "memory could not be written". ?? I got XP SP2.

EDIT: Others got also problems with 1.08. http://research.pandasoftware.com/blogs/re...rsion-1.07.aspx

Andrew, cham44, Jack, Sam and the rest of you running into problems with 1.08 during the registry scan, I have uploaded version 1.07 to http://research.pandasoftware.com/blogs/im...ootkit-1.07.zip. Please try running 1.07 but still send me the details of your machine and installed applications to pbustamante'at'pandasoftware.com.

That 1.07 works fine.

Wher did you get 1.08? The download from the Panda site is 1.07. This is the download I used.
http://www.pandasoft...ts/antirootkit/

#12 OFFLINE   mfenech

    Advanced Member

  • Members
  • PipPipPip
  • 299 posts
  • Gender:Male
  • Location:Texas

Posted 12 July 2007 - 03:46 AM

View PostAndavari, on Jul 11 2007, 06:50 PM, said:

AntiVir PE Classic also has a root-kit scanner. For people using it they have anti-virus and anti-rootkit all in one app, I'd use it too if it weren't for the update problems I keep having with AntiVir.
You're still having them? I haven't had any update trouble nor have I heard complaints in a while now.

#13 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 04:03 AM

Just tried the "in depth scan" that requires a restart and it scanned with no problems.

#14 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,324 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 12 July 2007 - 06:18 AM

View Postmfenech, on Jul 11 2007, 10:46 PM, said:

You're still having them? I haven't had any update trouble nor have I heard complaints in a while now.
Yes I'm still having update issues. I recently got sick of Avast again and decided to switch back to either AntiVir or AVG. I would've preferred AntiVir but it just sits there and doesn't want to update, therefore I had to go with AVG.

Edit:
Supposedly my network settings are "borked" according to several software titles, however upon checking them and even reinstalling my ISP software that enables my DSL modem I find nothing out of the ordinary.
Complexity of incoherent design.

#15 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 12 July 2007 - 10:24 AM

View PostAnthony A, on Jul 12 2007, 03:14 AM, said:

Wher did you get 1.08?

From this link: http://research.pandasoftware.com/blogs/im...AntiRootkit.zip

Site: http://research.pandasoftware.com/blogs/re...t-Released.aspx



View PostAndavari, on Jul 12 2007, 06:18 AM, said:

I recently got sick of Avast again

Why? What it was about Avast, that you got sick of?

#16 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 01:51 PM

Well spent several hours researching and trying out several of these Anti-Rootkit programs. I like the Panda one the best so far and I have tried Blacklight, Sophos, AVG, and Panda. Panda is getting good reviews. It's tiny and no install required. I had no issues with it like CeeCee did but I ran 1.07 not 1.08. It has a scan on start up option to check for things that might not get detected in a normal scan. Very simple clean GUI and easy to use. From the reviews I have read Panda is much more thorough compared to some of the others. It scans the registry AVG and Blacklight do not. AVG didn't get good reviews. Blacklight is only free until October.
Here is a review of Panda http://www.pcmag.com...,2119254,00.asp

#17 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 12 July 2007 - 02:57 PM

View PostAnthony A, on Jul 12 2007, 01:51 PM, said:

Well spent several hours researching and trying out several of these Anti-Rootkit programs.

You are hellofatester. ;)

#18 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 03:05 PM

View PostCeeCee, on Jul 12 2007, 10:57 AM, said:

You are hellofatester. ;)

All I could really test is how smooth they ran and how easy to use and install they were. I had to rely on reviews about how well they cleaned since I don't have anything to clean :lol:

#19 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 12 July 2007 - 04:25 PM

View PostCeeCee, on Jul 11 2007, 08:18 PM, said:

Just download AutoRuns. Launch Autoruns.exe and go to "Drivers" tab. Uncheck "AVG Anti-Rootkit driver" and "AVG7 Clean Driver". Then just close AutoRuns program. Of course you can't use AVG Anti-Rootkit after that. When you want use it again, just check those drivers and reboot Windows.

Hey Cee Cee are you sure the AVG7 Clean Driver is for the Anti-Rootkit and not the Anti Virus or Anti Spyware? I have that driver in two machines that never had AVG Anti rootkit installed.

#20 OFFLINE   CeeCee

    Wait a minute, who am I here?

  • Members
  • PipPipPipPip
  • 1,210 posts
  • Gender:Male
  • Location:Finland
  • Interests:Movies, my computer

Posted 12 July 2007 - 04:44 PM

View PostAnthony A, on Jul 12 2007, 04:25 PM, said:

Hey Cee Cee are you sure the AVG7 Clean Driver is for the Anti-Rootkit and not the Anti Virus or Anti Spyware?

I don't got AVG Antivirus -or Spyware. Those two files came for me with that AVG Anti-rootkit. Of course i cannot say, if those other AVG programs uses that same file also...