Jump to content


Anti-Rootkit programs


14 replies to this topic

#1 OFFLINE   Icedrake

    Shazam!

  • Members
  • PipPipPipPip
  • 1,646 posts
  • Gender:Male
  • Location:United States
  • Interests:Reading, using my computer, astronomy, physics, mathematics, etc.

Posted 25 April 2008 - 04:17 PM

Anyone know of a good freeware anti-rootkit program?
Website: www.icedrake.co.cc
YouTube: www.youtube.com/icedrake99
DeviantART: www.icedrake99.deviantart.com
Twitter: www.twitter.com/icedrake99

#2 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 25 April 2008 - 04:39 PM

These are currently freeware from reputable companies:
* Panda Anti-Rootkit
* Avira Anti-Rootkit

Do note that if you switch to either Avast Antivirus Home Edition, or AntiVir PersonalEdition Classic that they include rootkit detection build-in.
Complexity of incoherent design.

#3 OFFLINE   Coronagold

    Advanced Member

  • Members
  • PipPipPip
  • 115 posts

Posted 27 April 2008 - 01:48 AM

The Avira AntiRootKit Tool (beta) finds more rootkit entries than AntiVir free does.

#4 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 27 April 2008 - 02:08 AM

Here are two more. Both are no install apps.

F-Secure Black Light. Link is at the bottom of the page http://www.f-secure....ecurity_center/

Trend Micro Rootkit Buster http://www.trendmicr...oad/rbuster.asp

#5 OFFLINE   Tom AZ

    Power Member

  • Members
  • PipPipPipPip
  • 941 posts
  • Location:Scottsdale, AZ USA

Posted 27 April 2008 - 02:46 AM

Just downloaded and tried to install Avira Anti-Rootkit Tool. However, couldn't get the Setup.exe file to open. Anyone else have that problem? Or, is there possibly another way to install it?

#6 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 27 April 2008 - 03:57 AM

View PostTom AZ, on Apr 26 2008, 10:46 PM, said:

Just downloaded and tried to install Avira Anti-Rootkit Tool. However, couldn't get the Setup.exe file to open. Anyone else have that problem? Or, is there possibly another way to install it?

Go with the two I linked or the Panda one. All 3 do not require an install.

#7 OFFLINE   davey

    Keep it simple !

  • Members
  • PipPipPipPipPip
  • 2,235 posts
  • Gender:Male
  • Location:Maryland U.S.A.

Posted 27 April 2008 - 04:20 AM

View PostTom AZ, on Apr 26 2008, 10:46 PM, said:

Just downloaded and tried to install Avira Anti-Rootkit Tool. However, couldn't get the Setup.exe file to open. Anyone else have that problem? Or, is there possibly another way to install it?
Is it an executable also?As a matter of fact, aren't they all?
:) davey

#8 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 27 April 2008 - 09:31 AM

View PostTom AZ, on Apr 26 2008, 08:46 PM, said:

Just downloaded and tried to install Avira Anti-Rootkit Tool. However, couldn't get the Setup.exe file to open. Anyone else have that problem? Or, is there possibly another way to install it?
Maybe it was corrupted during the download. I've used it and removed it.

The one I really like is Panda Anti-Rootkit, it will even check for an update before scanning.

Many of the free anti-rootkit scanners haven't been updated for months!
Complexity of incoherent design.

#9 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 28 April 2008 - 01:37 AM

IceSword is pretty good, but detects many processes that are harmless. Info and a download link:
http://www.castlecops.com/t165203-IceSword...llustrated.html

SpyBot S&D is getting into rootkit finding; they describe their present app as "a work in progress". Info and a download link:
http://forums.spybot...ead.php?t=24185

Sophos has a good one. You have to register to download it:
http://www.sophos.com/products/free-tools/...ti-rootkit.html

Sysinternals has a good one: RootKit Revealer. Info and a download link:
http://technet.microsoft.com/en-us/sysinte...s/bb897445.aspx

None of the above require installation, all are free. :) I just use them to find out whats going on in my computer...never have found anything ugly, thank goodness. Would have to get expert help if an actual rootkit showed up. You have to be careful, a lot of processes that look scary are really legitimate.

Also I think you do have to install the Avira RKD, but no reboot is required.
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#10 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 28 April 2008 - 01:54 AM

View Postlogin123, on Apr 27 2008, 07:37 PM, said:

Also I think you do have to install the Avira RKD, but no reboot is required.
It does have to be installed. ;)

Some of those others that claim they can just be ran without installing are actually adding stuff onto the system like adding a line into a Windows .ini file like win.ini, etc.,, or writing stuff into the registry.
Complexity of incoherent design.

#11 OFFLINE   Anthony A

    POSIMO

  • Members
  • PipPipPipPipPip
  • 2,101 posts

Posted 28 April 2008 - 02:05 AM

View Postlogin123, on Apr 27 2008, 09:37 PM, said:

IceSword is pretty good, but detects many processes that are harmless. Info and a download link:
http://www.castlecops.com/t165203-IceSword...llustrated.html

SpyBot S&D is getting into rootkit finding; they describe their present app as "a work in progress". Info and a download link:
http://forums.spybot...ead.php?t=24185

Sophos has a good one. You have to register to download it:
http://www.sophos.com/products/free-tools/...ti-rootkit.html

Sysinternals has a good one: RootKit Revealer. Info and a download link:
http://technet.microsoft.com/en-us/sysinte...s/bb897445.aspx

None of the above require installation, all are free. :) I just use them to find out whats going on in my computer...never have found anything ugly, thank goodness. Would have to get expert help if an actual rootkit showed up. You have to be careful, a lot of processes that look scary are really legitimate.

Also I think you do have to install the Avira RKD, but no reboot is required.


Some of those ones you mentioned are for advanced users. You need to know what you are doing with them. Panda and Blacklight are very easy to use.

#12 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 28 April 2008 - 03:03 AM

View PostAndavari, on Apr 27 2008, 08:54 PM, said:

It does have to be installed. ;)

Some of those others that claim they can just be ran without installing are actually adding stuff onto the system like adding a line into a Windows .ini file like win.ini, etc.,, or writing stuff into the registry.

You are quite right, Andavari. But none of those I listed change the registry very much as far as I can tell, nor compromise performance after they are run. Sophos does add a stubborn key: HKLM\...\LEGACY_MEMSWEEP2, but no harm done as I can tell.

Anthony_A is right too. You gotta know what you're doing. Expert help is called for if you think you have found a rootkit. If it was easy everybody would be doin' it. :)
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#13 OFFLINE   Coronagold

    Advanced Member

  • Members
  • PipPipPip
  • 115 posts

Posted 28 April 2008 - 12:40 PM

Like me! :D

#14 OFFLINE   LUSHER

    Advanced Member

  • Members
  • PipPipPip
  • 95 posts

Posted 01 May 2008 - 03:44 PM

A couple more tools here http://wiki.castlecops.com/Lists_of_freewa...al_AV_companies

Bitdefender, Mcafee, Sophos , AVAST, Spybot all also provide standalone antirootkits ...

#15 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,460 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 01 May 2008 - 03:54 PM

Looks like DiamondsCS may be back up and running.

A new beta from them is Deep System Explorer for finding new and future rootkits
Info here
http://www.diamondcs.../detections.php

Some of you may recognise some of their windows freeware
http://www.diamondcs...eeutilities.php
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs