Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Any rootkit prevention, detection and/or repair suitable for use by the average user?

Reply
Thread Tools

Any rootkit prevention, detection and/or repair suitable for use by the average user?

 
 
Blue Event Horizon
Guest
Posts: n/a
 
      08-12-2006
Using Windows XP Media Center Edition 2005 on a computer I've only had
about a month after 6 1/2 years using another computer with Windows ME
so I'm still learning about my OS and rootkits have just really come
to my attention recently. Also now DSL instead of dialup, if that
matters. Kerio 2.1.5 firewall, AVG Free antivirus, currently using
Ad-Aware, Spybot, ewido antispyware products (ewido is new to me).

Are there are programs/tools/whatever suitable for average
(unsophisticated, ignorant or however you care to characterize us)
users to prevent, detect and/or repair rootkit threats and problems?
Preference for freeware and GUI.

BEH
 
Reply With Quote
 
 
 
 
nemo_outis
Guest
Posts: n/a
 
      08-12-2006
Blue Event Horizon <> wrote in
news::

> Using Windows XP Media Center Edition 2005 on a computer I've only had
> about a month after 6 1/2 years using another computer with Windows ME
> so I'm still learning about my OS and rootkits have just really come
> to my attention recently. Also now DSL instead of dialup, if that
> matters. Kerio 2.1.5 firewall, AVG Free antivirus, currently using
> Ad-Aware, Spybot, ewido antispyware products (ewido is new to me).
>
> Are there are programs/tools/whatever suitable for average
> (unsophisticated, ignorant or however you care to characterize us)
> users to prevent, detect and/or repair rootkit threats and problems?
> Preference for freeware and GUI.
>
> BEH
>


All the following require a modicum of intelligence:

RootkitRevealer
http://www.sysinternals.com/Utilitie...tRevealer.html

F-secure BlackLight
https://europe.f-secure.com/blacklight/

IceSword (arguably the best bnut also the geekiest)
http://tinyurl.com/ckqsn [English download mirror]

Regards,


 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      08-12-2006
From: "nemo_outis" <>


| All the following require a modicum of intelligence:
|
| RootkitRevealer
| http://www.sysinternals.com/Utilitie...tRevealer.html
|
| F-secure BlackLight
| https://europe.f-secure.com/blacklight/
|
| IceSword (arguably the best bnut also the geekiest)
| http://tinyurl.com/ckqsn [English download mirror]
|
| Regards,
|

Add...

gmer -- http://www.gmer.net/

Vinzenz Feenstra, ewido anti-spyware developer, Anti-RootKit Beta
http://blog.evilissimo.net/2006/08/0...-rootkit-beta/


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Sebastian Gottschalk
Guest
Posts: n/a
 
      08-13-2006
David H. Lipman wrote:
> From: "nemo_outis" <>
>
>
> | All the following require a modicum of intelligence:
> |
> | RootkitRevealer
> | http://www.sysinternals.com/Utilitie...tRevealer.html
> |
> | F-secure BlackLight
> | https://europe.f-secure.com/blacklight/
> |
> | IceSword (arguably the best bnut also the geekiest)
> | http://tinyurl.com/ckqsn [English download mirror]
> |
> | Regards,
> |
>
> Add...
>
> gmer -- http://www.gmer.net/


And remove BlackList, as it's nothing special over other common non-beta
free utilities. At its first release it offered a sinmple but special
method to detect unlinked process lists, but this is now a standard
feature of Gmer, DarkSpy, Knlps and VICE.

Rootkit Revealer might me removed as well, as it's totally buggy. On
well-hardened machines is doesn't even run (spawns the service process
and then crashes) and even on kinda normal machines it may run into bad
errors (f.e. if you linked C:\mnt\floppy to A:\ and no floppy is
inserted, the 'dir' command in the spawned cmd.exe process will hang
forever, so the entire file system scan fails completely).

> Vinzenz Feenstra, ewido anti-spyware developer, Anti-RootKit Beta
> http://blog.evilissimo.net/2006/08/0...-rootkit-beta/


Yeah, this one is another piece of junk. Without any question is tries
to remove a simple hidden process, fails, reboots, tries again, fails,
crashes, ...


Add...

DarkSpy
RkDetector2
VICE
System Virginity Verifier
 
Reply With Quote
 
nemo_outis
Guest
Posts: n/a
 
      08-13-2006
"nemo_outis" <> wrote in news:Xns981DA3A26BE65abcxyzcom@
204.153.244.170:

You ask - I deliver!

Here's a compilation (41 meg) of the following anti-rootkits:

Windows Anti-Rootkit Apps:

Rootkit Revealer
F-Secure BlackLight
Process Master
HookExplorer
GMER
UnHackMe
IceSword
Darkspy
System Virginity Verifier
Rootkit Hook Analyzer
HiddenFinder
LavaSoft ARIES Rootkit Remover

Windows Rootkit Prevention Apps:

AntiHook Pro
Process Guard
GesWall Personal
Defense Wall HIPS
SocketShield
Neoava Guard
Defense Plus

Linux/BSD Apps:

CHKRootkit
RkHunter
Zeppoo

Download it from:

http://rapidshare.de/files/29162303/...otkits_AIO.rar

rar password: www.2baksa.net

Regards,

 
Reply With Quote
 
Admins
Guest
Posts: n/a
 
      08-15-2006
On 13 Aug 2006 15:52:53 GMT, nemo_outis wrote:

> Path: auth.newsreader.octanews.com!newsreader.visi.com!n ews-out.octanews.net!indigo.octanews.net!authen.yellow .readfreenews.net.POSTED!not-for-mail
> Newsgroups: alt.computer.security
> Subject: Re: Any rootkit prevention, detection and/or repair suitable for use by the average user?
> From: nemo_outis <>
> References: <> <Xns981DA3A26BE65abcxyzcom@204.153.244.170>
> Organization: erewhon
> Message-ID: <Xns981E6484E5D57abcxyzcom@204.153.244.170>
> User-Agent: Xnews/2006.06.28
> Date: 13 Aug 2006 15:52:53 GMT
> Lines: 46
> NNTP-Posting-Date: 13 Aug 2006 10:52:53 CDT
> X-Trace: DXC=_8e1T@:\DZHM@X[oR]n0HIbQ9W<K20`3BO6Gh9bA988N6>bBE>CcU@J>ElQReo>5lCEP 9Dm9AWa^KdCLiFbIA4GCZ[?S<P@4`dI
> Xref: auth.newsreader.octanews.com alt.computer.security:48475
>
> "nemo_outis" <> wrote in news:Xns981DA3A26BE65abcxyzcom@
> 204.153.244.170:
>
> You ask - I deliver!
>
> Here's a compilation (41 meg) of the following anti-rootkits:
>
> Windows Anti-Rootkit Apps:
>
> Rootkit Revealer
> F-Secure BlackLight
> Process Master
> HookExplorer
> GMER
> UnHackMe
> IceSword
> Darkspy
> System Virginity Verifier
> Rootkit Hook Analyzer
> HiddenFinder
> LavaSoft ARIES Rootkit Remover
>
> Windows Rootkit Prevention Apps:
>
> AntiHook Pro
> Process Guard
> GesWall Personal
> Defense Wall HIPS
> SocketShield
> Neoava Guard
> Defense Plus
>
> Linux/BSD Apps:
>
> CHKRootkit
> RkHunter
> Zeppoo
>
> Download it from:
>
> http://rapidshare.de/files/29162303/...otkits_AIO.rar
>
> rar password: www.2baksa.net
>
> Regards,


I like f-secure black light, if it finds anything it gives you the option
of doing a google search on the item so you can see what it is and exactly
what it does. It's alot better than deleting a file you really need, most
of these root kit detectors are still giving false positives and are still
in beta,
--
Admin


* www.privacyoffshore.net (No Logs Internet Surfing)
* Anonymous Secure Offshore SSH-2 Surfing Tunnels
 
Reply With Quote
 
raincoater
Guest
Posts: n/a
 
      09-09-2006
Hello, nemo_outis!
You wrote:


> You ask - I deliver!
>
> Here's a compilation (41 meg) of the following anti-rootkits:
>
> Windows Anti-Rootkit Apps:
>
> Rootkit Revealer
> F-Secure BlackLight
> Process Master
> HookExplorer
> GMER
> UnHackMe
> IceSword
> Darkspy
> System Virginity Verifier
> Rootkit Hook Analyzer
> HiddenFinder
> LavaSoft ARIES Rootkit Remover
>
> Windows Rootkit Prevention Apps:
>
> AntiHook Pro
> Process Guard
> GesWall Personal
> Defense Wall HIPS
> SocketShield
> Neoava Guard
> Defense Plus
>
> Linux/BSD Apps:
>
> CHKRootkit
> RkHunter
> Zeppoo
>
> Download it from:
>
> http://rapidshare.de/files/29162303/...otkits_AIO.rar
>
> rar password: www.2baksa.net
>
> Regards,



Thanks Nemo. Much appreciated.


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
501 PIX "deny any any" "allow any any" Any Anybody? Networking Student Cisco 4 11-16-2006 10:40 PM
Rootkit detection and removal geermeister@gmail.com Computer Support 5 03-12-2006 03:36 AM
Best way to create clean Windows XP boot cd for running rootkit detection pamelafiischer@yahoo.com Computer Support 18 11-23-2005 11:19 PM
Microsoft Strider GhostBuster Rootkit Detection Software Download Pamela Fischer Computer Support 4 11-21-2005 02:21 PM
Microsoft Research: Strider GhostBuster Rootkit Detection and "...stealth software that hides in BIOS, Video card EEPROM" David H. Lipman Computer Security 34 09-24-2005 11:15 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57