1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Top 3 Tools To Remove Rootkits

Discussion in 'General Software' started by Gman496, Aug 8, 2010.

  1. Gman496

    Gman496 Super Moderator Staff Member

    6,686
    472
    133
    Top 3 Tools To Remove Rootkits and Prevent Them from Infecting Your PC


    I may have a rootkit, how do I get rid of it?

    If you suspect you have been infected, there are a few steps you can do. First, run a regular virus scan. The simplest ones can be removed with the most up-to-date antivirus programs. The scans can be run in safe or regular mode, however true rootkits may not show up easily. A better option is to use specialized rootkit detectors like the ones below.


    1. TREND MICRO ROOTKIT BUSTER

    Trend Micro makes a small but powerful Rootkit Buster that scans your computer’s system folders and Master Boot Records (MBR) for rootkits. It allows you to perform a selective target scan for different locations such as Registry Keys and File Streams.

    [​IMG]



    2. SOPHOS ANTI-ROOTKIT

    Sophos makes the free Anti-rootkit application that is a simple yet powerful tool for both new users and experienced ones. It provides a graphical and a command line user interface that allows selective operation. The scanner checks the entries it finds with those in its database and provides with detailed information on them. It is also available for a large variety of platforms.

    [​IMG]



    3. MICROSOFT ROOTKIT REVEALER

    Microsoft also makes its Rootkit Revealer that uses advanced tactics such as name hopping to stop smart rootkits from recognizing the scan and hiding. It however does not include a command-line interface like Sophos anti-rootkit.

    [​IMG]


    It is best if these are run when the computer is disconnected from all networks. A more complex option is to run a boot disk/drive that will start your computer independently and allow you to scan hard drives and boot records.

    If you have no other alternative, then a format and re-install of your operating system may be in order. This will not affect computers with an infected BIOS; however such infections are rare and cannot be contracted through ordinary means. They can only be removed by experts.


    So how do I protect my PC?

    It is said that an ounce of prevention is better than a pound of cure. Needless to say that all conventional methods for protecting a computer against viruses must be practiced anyway, but additionally, the user can take the following steps:

    * Install software only from trusted sources. Non-essential programs should be locally installed
    for the user so that they do not have access to system spaces.

    * A strong firewall will make it harder for an external attacker to make use of an infected
    computer.

    * Regular scans of the computer will ensure any problems are nipped in the bud.

    Rootkits will continue to be a threat with the spread of the internet to all corners of the world. A little safe computing and knowledge will keep your forearmed.


    Also read, What is a rootkit?


    -
     
    Last edited: Aug 9, 2010
  2. ferguj1

    ferguj1 Super Duper Modulator Staff Member

    Nice post buddy. Stickied.
     
  3. billybongo11

    billybongo11 Registered

    3
    0
    0
    Just a quick note that we use TDSSKILLER from Kaspersky and NORMAN TDSS cleaner and work very well.
     
  4. axxxo

    axxxo VIP Member

    Ive only recently used TDSSKILLER myself and it found one problem but i think before removing what any of these find it should be looked into detail first as it could delete something related to running the computer. I deleted a false positive and had to do a system repair with the recovery disc.
     
  5. marrylama

    marrylama Registered

    4
    0
    0
    Nice Post.
     
  6. mpg1965

    mpg1965 Registered

    19
    0
    1
    a must have these days.nice 1
     
  7. cactikid

    cactikid VIP Member

    15,900
    982
    133
    as thats an old post any newer or better ones?