Author Topic: active root kit remover?  (Read 9666 times)

0 Members and 1 Guest are viewing this topic.

footballer62

  • Guest
active root kit remover?
« on: March 16, 2007, 03:29:30 PM »
hi, I was wondering if there is an active rook kit remover out there. I found out that some nasty root kits are some how blocking my internet access until they are removed (the internet didn't work at all until I removed them with rootkit unhooker), but the bad thing is they come back after ever pc restart, and some times even during a windows session.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: active root kit remover?
« Reply #1 on: March 16, 2007, 03:33:54 PM »
Hi footballer62,

I'd recommend F-Secure BlackLight, the Panda scanner, the BitDefender scanner and the Sophos scanner listed here:

http://www.antirootkit.com/software/index.htm
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: active root kit remover?
« Reply #2 on: March 16, 2007, 05:00:48 PM »
How did you find out that there may be a rootkit at work ?

Whilst doing this investigation, consider isolating any rootkit elements so that the samples can be sent to avast to help improve detection.

Adding them to the User Files section of the avast Chest will stop them getting up to any further mischief, from here they can be sent to avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Spiritsongs

  • Guest
Re: active root kit remover?
« Reply #3 on: March 16, 2007, 05:26:34 PM »
 :)  Hi Footballer :

     I see you followed my recommendation on Feb 28 to use Rootkit Unhooker;
     in that Post I mentioned they have Support Forums . It would be wise to
     use them at http://rku.xell.ru/forum/  . Probably their "Technical support"
     forum would be the one to use !? The Russian Programmers and their
     "associates" are very wise ; did you ever read the thread about this
     program at the highly regarded Wilders Security Forums
    ( www.wilderssecurity.com/showthread.php?t=157547&highlight=rootkit+unhooker )  ?

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: active root kit remover?
« Reply #4 on: March 16, 2007, 06:51:01 PM »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

mouniernetwork

  • Guest
Re: active root kit remover?
« Reply #5 on: March 16, 2007, 08:05:14 PM »
Maybe Avast could build a tool like this  ;)

Al968

footballer62

  • Guest
Re: active root kit remover?
« Reply #6 on: March 17, 2007, 04:18:19 AM »
How did you find out that there may be a rootkit at work ?

Whilst doing this investigation, consider isolating any rootkit elements so that the samples can be sent to avast to help improve detection.

Adding them to the User Files section of the avast Chest will stop them getting up to any further mischief, from here they can be sent to avast.

I found out the root kit was at work when my internet stopped working. I would open up both firefox and internet explorer with every page giving me a server not found error (every page!). So I proceeded to try the un hooker, and sure enough my pages loaded directly after that. Now at the start of windows I have to unhook this files, but I think there may still be a thing or two hidden in there, because I still get the server down every so often (but hitting the refresh button usually gets it to load after about 5 tries).

I am going to try the file thing in avast tomorrow, to see if that works, wish me luck!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: active root kit remover?
« Reply #7 on: March 17, 2007, 01:45:40 PM »
That seems strange activity for a rootkit, whose whole idea is stealth to effectively stop you browsing, drawing attention to itself. Good luck and keep us up to date, thanks.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

WuLFe

  • Guest
Re: active root kit remover?
« Reply #8 on: March 17, 2007, 02:59:40 PM »
yep, strange for a rootkit... there are alot of free rootkit  detectors and removers out there...

try this site out http://www.antirootkit.com/software/index.htm

good luck  ;)

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11652
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: active root kit remover?
« Reply #9 on: March 17, 2007, 07:57:31 PM »
GMER is the best. ;)
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: active root kit remover?
« Reply #10 on: March 17, 2007, 08:09:02 PM »
GMER is the best. ;)
Why?
Why is their 'official' website off-line?
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: active root kit remover?
« Reply #11 on: March 17, 2007, 08:17:49 PM »
I have just visited the 'official' web site and it was on-line, the page at antirootkit.com might be out of date, plus the mirror at castlecops is fine also.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11652
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: active root kit remover?
« Reply #12 on: March 17, 2007, 08:41:28 PM »
The site was down for quite some time because the bad guys kept DDOSing it. ;D
That is, their goal was to make the site inaccessible...

You can read about it here:
http://www.castlecops.com/article-6718-nested-0-0.html
and
http://www.castlecops.com/a6725-gmer_in_sanctuary.html


Cheers
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: active root kit remover?
« Reply #13 on: March 17, 2007, 10:13:24 PM »
Ok, you gave me the reason for the site to be down. Thanks.
But, why do you like it that much?
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: active root kit remover?
« Reply #14 on: March 17, 2007, 10:28:32 PM »
I just ran it to see what the interface is like and I have to say it looked like a turbo charged rootkit revealer, absolutely tons of information. I'm not sure how much help that would be to your average user.

I believe I haven't got any rootkit infections ;D so I guess that is why there was no information as in 'this is a rootkit' alert ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security