CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

Vista compatible Rootkit Detectors / Scanners

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5253

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Sun Jan 27, 2008 12:41 am    Post subject: Vista compatible Rootkit Detectors / Scanners
Reply with quote

The following rootkit detectors/scanners are compatible with Windows Vista (32 bit):

AVZ:(a multifunction antimalware tool with rootkit detection capability):
http://z-oleg.com/avz4.zip

BlackLight Rootkit Eliminator (F-Secure):
http://www.f-secure.com/security_center/
Direct download from F-Secure:
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe

BlackLight also runs on 64-bit Windows XP and Windows 2003 Server (32 and 64-bit)

Gmer (by Gmer):
http://gmer.net

IceSword 1.20 Vista (by pfj):
http://202.38.64.10/%7Ejfpan/download/is120en_vista.zip

Malicious Software Removal Tool (MSRT by Microsoft):
http://www.microsoft.com/security/malwareremove/default.mspx
See list of malicious software including prevalent rootkits detected by the MSRT here:
http://www.microsoft.com/security/malwareremove/families.mspx

PrevxCSI (very quick scanner):
http://info.prevx.com/downloadcsi.asp

Rootkit Hook Analyzer by Resplendence (Checks SSDT hooks only):
http://resplendence.com/hookanalyzer

Rootkit Unhooker (recently acquired by Microsoft):
http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar

Rootkit Revealer (Microsoft):
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

Unhackme (Greatis):
http://www.greatis.com/unhackme/download.htm


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5253

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Tue Jun 03, 2008 3:02 am    Post subject:
Reply with quote

When it comes to rootkits and Vista, it is wise to leave UAC turned on.

As most of you know the default in Vista is to run as a standard user. Standard user = NO Admin Privileges.

Why is this important when considering rootkits?? Because kernel mode rootkits need Admin privileges to install. UAC enables a standard user to elevate to Admin mode when necessary to perform functions that they would otherwise not be able to perform. UAC is turned on by default in Vista!

The following article describes a study in which thirty rootkits were thrown at both XP and Vista platforms to assess the effectiveness of standalone anti-rootkit tools and antivirus suites at detecting and removing rootkits . One offshoot of this study is that it revealed just how effective Vista is at preventing rootkit installation when UAC is turned ON.
http://www.pcworld.com/businesscenter/article/146256/vistas_despised_uac_nails_rootkits_tests_find.html

Here are some more excerpts from this study:

Of 30 rootkits thrown at XP anti-malware scanners, none of the seven AV suites found all 30, a similar story to the six web-based scanners assessed. Only four of the 14 specialized anti-rootkit tools managed a perfect score:
AVG Anti-Rootkit Free, GMER, Rootkit Unhooker LE, and Trend Micro Rootkit Buster

The results for Vista products were harder to assess because only six rootkits could run on the OS, but the testers had to turn off UAC to get even this far. Vista's UAC itself spotted everything thrown in front of it.

Only three of the 17 AV tools for Vista managed to both detect and successfully remove them, F-Secure Anti-Virus 2008, Panda Security Antivirus 2008, and Norton Antivirus 2008.

The best of the all-purpose suites was Avira AntiVir Premium Security Suite, which found 29 active rootkits, with Norton finding as few as 18.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Jun 03, 2008 2:45 pm    Post subject:
Reply with quote

Note: AVG Anti-Rootkit Free is no longer available as a free standing program. It has, unfortunately, been integrated into AVG 8.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer