Author Topic: active root kit remover?  (Read 9455 times)

0 Members and 1 Guest are viewing this topic.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: active root kit remover?
« Reply #15 on: March 17, 2007, 11:17:51 PM »
Basically, it produces lots of data but only RED entries are of interest (unless you really know what to look for).
But the efficiency of the program consists in showing the RED entries whenever necessary.
Additionally, if you right-click any of the red entries, the program lets you "fix" it.

Cheers
Vlk
« Last Edit: March 18, 2007, 12:05:42 AM by Vlk »
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: active root kit remover?
« Reply #16 on: March 17, 2007, 11:54:09 PM »
Thanks. I'll give it a try.
The best things in life are free.

Spiritsongs

  • Guest
"GMER"
« Reply #17 on: March 18, 2007, 12:55:59 AM »
 :)  Hi Vlk & Others :

     Have never disagreed with you before Vlk but everthing I read on the
     various threads on the "other anti-malware software" forum at Wilders
     ( www.wilderssecurity.com/forumdisplay.php?f=35 ) indicates that
       GMER is NOT the best ; see threads such as :
      www.wilderssecurity.com/showthread.php?t=168814  and
      www.wilderssecurity.com/showthread.php?t=157547  and our thread at
      http://forum.avast.com/index.php?topic=26128.0  .

WuLFe

  • Guest
Re: active root kit remover?
« Reply #18 on: March 18, 2007, 02:15:05 AM »
yep, i agree with Vlk, currently using Gmer and Darkspy...

is Icesword still being updated..?

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: active root kit remover?
« Reply #19 on: March 18, 2007, 09:48:38 AM »
Spiritsongs,

1. During the last year, GMER has vastly improved.

2. Saying that a certain program is BEST is of of course always a bit exaggeration (there's nothing like BEST antivirus, BEST firewall, BEST antirootkit etc.) but what I said is my personal oppinion based on certain facts and some personal sympathies.

3. I don't think the threads over at Wilders' (that you linked) indicate that GMER is "not the best". The first one doesn't mention GMER at all and the second one is of these super-lengthy threads that never lead to anything...

4. The test carried out by informationweek (mentioned in the thread on the avast forum) is definitely NOT something I'd base my judgements on... Compare this to magazine tests of antivirus software.


Cheers
Vlk
If at first you don't succeed, then skydiving's not for you.

footballer62

  • Guest
Re: active root kit remover?
« Reply #20 on: March 18, 2007, 10:03:36 PM »
ok, here are some images of what turns up in rootkit unhooker RIGHT when my pc has just booted up.

I also made a new discovery into this matter, it seems that what ever new program that gets loaded gets hooked within few minutes as well. I found this out as I booted up AIM, and about 5 minutes later it was hooked (and thus I had to unhook it). It was not hooked before I loaded it, as nothing was hooked at that point (unhooked everything on my pc after boot up).

This just keeps getting weirder and weirder!

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: active root kit remover?
« Reply #21 on: March 18, 2007, 10:22:39 PM »
A347bus.sys belongs to Alcohol120. The second driver belongs to AVG Antispyware.
I don't see anything suspicious on the screenshot you posted...
If at first you don't succeed, then skydiving's not for you.

footballer62

  • Guest
Re: active root kit remover?
« Reply #22 on: March 18, 2007, 10:24:53 PM »
and the second part...

footballer62

  • Guest
Re: active root kit remover?
« Reply #23 on: March 18, 2007, 10:30:24 PM »
A347bus.sys belongs to Alcohol120. The second driver belongs to AVG Antispyware.
I don't see anything suspicious on the screenshot you posted...

thats the thing, there is something on my system that is getting into these programs, and "hooking" them, the second pic has quite a few from window blinds (wblinds), myspace im, ect, but what in the world is messing with my pc like this?

btw, the first pic is of the SSDT hooks detector/restorer, the second is of the code hooks section in rootkit unhooker.

WuLFe

  • Guest
Re: active root kit remover?
« Reply #24 on: March 19, 2007, 06:07:11 AM »
hmmm... i dont think anything's wrong with those hooks in the second screenshot you posted either... and its natural for some programs to hook into other progs, so it would work, especially AVs, otherwise it would be useless