Welcome, Guest. Please Login or Register.
Search
Members
Login
Register
   Mischel Internet Security Forum
   TrojanHunter
   Frequently Asked Questions
(Moderators: Helena, Gavin_Coe, Magnus)
   Free Anti-Rootkit Scanners
« Previous topic | Next topic »
Pages: 1    Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Free Anti-Rootkit Scanners  (Read 4499 times)
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Free Anti-Rootkit Scanners
« on: Dec 1st, 2006, 10:29am »

Provided below are download links for various commonly used dedicated free rootkit detection scanners.  Please read the information concerning the rootkit detection software provided on the web pages of these links.
 
Quoting from a past article of sysinternals:
 
"What is a Rootkit  
The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.  
 
Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.  
 
Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.  
 
User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt, to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.  
 
The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.  
 
Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer."  
 
Please note that TrojanHunter also contains rootkit detection technology and rulesets.
 
Sophos Anti-Rootkit
 
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
 
Grisoft/AVG Anti-Rootkit
 
http://avg-anti-rootkit.en.softonic.com/
 
Trend Micro Rootkit Buster
 
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=result_ page&clkval=drop_list&catid=6&prodid=155
 
Panda Anti-Rootkit
 
http://www.pandasoftware.com/download/documents/help/rkc/en/rkc_en.htm
 
Rootkit Unhooker
 
http://www.antirootkit.com/software/RootKit-Unhooker.htm
 
A review of six(6) rootkit detectors.
 
http://www.informationweek.com/software/showArticle.jhtml?articleID=1969 01062&pgno=1
 
Be sure to check the developers' web page for compatibility with your Windows version.
 
Applies to all versions of TrojanHunter.
« Last Edit: Dec 15th, 2011, 10:46am by siliconman01 » IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Pages: 1    Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »