CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[Guide] Make your own System Security Suite for Free!
Goto page Previous  1, 2
 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Security [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 9038
Location: Nebraska, USA
MVP Premium

PostPosted: Mon Oct 17, 2005 7:39 pm    Post subject:
Reply with quote

Good catch - JB2. Did you check the CastleCops Wiki? (look on the left panel) I think what started out here, has been continued there - under beta content - for now.

RootkitRevealer by SystemInternals, downloaded from here is used to detect the presence of rootkits. Not sure there is anything out there yet claiming to automatically remove/repair too. Not sure I would want anything to "automatically" do it anyway - not unless there is a fail safe recovery process should it clean too aggressively. And I don't see that coming any time soon.


_________________
image Bill, AFE7Ret
Freedom is NOT Free!

image


Last edited by Bill_Bright on Tue Oct 18, 2005 12:29 pm, edited 1 time in total
Back to top
View users profile Send private message
satyr

Captain
Captain
Premium Member

Joined: Feb 25, 2004
Posts: 565

Premium Team F@H

PostPosted: Mon Oct 17, 2005 11:15 pm    Post subject:
Reply with quote

Bill_Bright wrote:
Not sure there is anything out there yet claiming to automatically remove/repair too. Not sure I would want anything to "automatically" do it anyway - not unless there is a fail save recovery process should it clean too aggressively. And I don't see that coming any time soon.


Just as an info; IIRC one of the anti-virus programs, namely F-Prot or F-Secure (not sure which one) implements "rootkit" detection in its real-time scanning engine.


satyr


_________________
If you want to, please check out my computing-related website titled Tadej's computing homepage, and enjoy reading my various strictly computing-related discoveries, hints, principles, and rules...
Back to top
View users profile Send private message Visit posters website
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Tue Oct 18, 2005 5:45 am    Post subject:
Reply with quote

Interesting suggestions being made here. In case anyone isn't aware of it, Swatkat`s original post is at the wiki. Thus anyone can implement their suggestions at the wiki article and/or discuss suggestions, changes made, etc at the corresponding talk page. Please don't rely on Swatkat to carry the load; if you think changes are warranted, make them yourself. Have no fear; if the changes are not quite on the mark they will be modified by others.

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Oct 18, 2005 4:01 pm    Post subject:
Reply with quote

Nice point Ikeb. Very Happy

From now on please go to the link in Ikeb's post to make suggestions or alterations to this work. Become a CastleCops Wiki Member/Contributor. It's exciting stuff. Thumbs Up

This thread is now locked. PM a Moderator if you need it re-opened.

Thanks


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Security All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer