| Windows 7: Best Anti-Rootkit for x64 windows 7? |
17 Jun 2011
|
#1 | | |
Best Anti-Rootkit for x64 windows 7? Hi everyone.
It's been a while since the 64-bit version of Win 7 became mainstream. Back when it was new, there were very few anti-rootkit solutions available for any x64 system, and very few people who were concerned about rootkits on 64-bit operating systems.
Times, though, have changed. Rookits are more capable than ever, infecting and hiding in the MBR of your hard disk. This not only makes it possible for them to survive a reinstallation of the operating system (if a format is not performed first), but also renders them essentially invisible to everything you can try from within the operating system! This is something that even impacts x64 systems, regardless of PatchGuard or driver signing.
So now that the rootkits have caught up, I'm curious as to what tools are available to scan, detect, and remove them? My old standby, Rootkit Revealer, seems to be still unavailable for x64 systems. The much lauded TDSSKiller is also only functional on 32 bit windows systems. I've heard that Sophos Antirootkit is x64 compatible, but I've also read that it's plagued with false positives and causes system instability.
Does anyone have any recommendations for a good x64 compatible rootkit scanner? | My System Specs |
| System Manufacturer/Model Number Custom OS Windows 7 RTM CPU i7 920 Motherboard eVGA x58 SLi Memory 6 GB Patriot Graphics Card eVGA GeForce 275 GTX Sound Card Soundblaster X-Fi Gamer Monitor(s) Displays Acer 225Tw PSU Corsair 750 W Case Antec Twelve Hundred Cooling Stock Hard Drives WD 1 TB |
17 Jun 2011
|
#2 | | Win 7 Pro 64-bit South Central Texas |
Here's one of my concerns about listing the best of anything. If your machine doesn't have any rootkits, then logically, a rootkit scan shouldn't show anything. But if it doesn't show anything, then how do you know if the machine is infected but the scan didn't pick it up? For that reason I use the same logic that people use for any similar product like antivirus or antispyware apps. No anti-whatever is 100% effective 100% of the time. Pick one for real time (or on demand) scanning and use others for extra on demand scans just to make sure the primary didn't miss something. Best Free Rootkit Scanner/Remover
I'd also add one more: Hitman Pro 3 - SurfRight | My System Specs | | Computer type Laptop System Manufacturer/Model Number Sony Vaio VPCEB47GM Laptop OS Win 7 Pro 64-bit CPU Intel i5 2.4 Ghz Memory 8GB DDR3 Graphics Card Intel HD 3000 Sound Card IDT High Definition Monitor(s) Displays 15.6 WGXA Anti-Glare LED Screen Resolution 1280x800 Hard Drives 640Gb 7200rpm Antivirus MSE Browser Opera (primary) with IE9 backup |
18 Jun 2011
|
#3 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
I have Sophos Anti-Rootkit, and Panda Anti-Rootkit, both are said to be x64, Sophos says so on their site. Neither have ever found anything, or caused any problems. Neither have updated in a while either.
There are more advanced tools, but they require advanced knowledge as well. Such as Ice Sword, and GMER.
A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
18 Jun 2011
|
#4 | | |
I use Sandboxie when surfing, delete upon finish, no more rootkit  If im not mistaken. | My System Specs | | OS Win 7 64 premium Other Info 7 fw, LUA, UAC on high, IE-9 w/ smartscreen on, SANDBOXIE |
04 Aug 2012
|
#5 | | Server 2008 R2, x64... Heavily modded, plus all the 7 wizbang... |
+1 on the Sandboxie. I like the concept, surprised OS developers never conceptualized it.
I'm actually boning up on rootkits and tooling, after a sweet attack by a "Toolbar". What a bear that thing was... or should I say, IS... Its an unsolicited installer too, weeee.... Good times indeed.
As it turns out the newest variant of the "Babylon Toolbar" entrenches itself in your NTUSER.DAT. Little ******* wouldn't stay dead, came back at each reboot, and just as strong as ever. Don't bother trying to restore registry backups while your OS is online, it'll eventually eat up all your good backups...
I had to drop my NTUSER.DAT cold, and bring in a fresh copy. Meaning all done via live disk, and with the OS "Completely offline". At the same time, I did a thorough cleaning of my system files. And walla, here I am... I haven't even brought my raid storage back online yet... lol...
While I'm thinking of it, ERUNT. Get it, and let it run every boot! You should even forget about it like I did. In all seriousness, this application was compiled back in 05, in our world of IT that's practically an antique. But what a life saver. And yes its happy as a clam on x64 systems. My current being a heavily modded Server 08 R2 package, x64 of coursee, and ERUNT just save my ass! Oh, and did I mention how I had just wiped my restore points prior to my infection. I was so glad I did that, wow... Good job fella!  Like I said "weeeeee...."
Last edited by TheGuru; 04 Aug 2012 at 01:56 AM..
| My System Specs | | System Manufacturer/Model Number GuruBuilt... OS Server 2008 R2, x64... Heavily modded, plus all the 7 wizbang... CPU AMD Phenom II X6 1055T, Clocked to 3.6GHz Cool & Quiet, 2yrs Motherboard MSI 870A-G54, also 2yrs old... Rock Solid!!! Memory 16GB, DDR3 PC3-8500, Patriot Graphics Card GeForce 9800GTX+, Direct 10? Nope... Code Dork 24/7 Sound Card Whats a sound card? Boards got a channels, that not enough? Monitor(s) Displays Dual 23" AOC, Fake Digital Signatures For Proper x64... Screen Resolution 1080p Keyboard No-name junk, buttons stick, glued baseboard to back 4 angle Mouse Laser Logitech, usb.... PSU 1k Case Cooler Master Cooling Couple 120's on either end... Very near silent... Hard Drives Lots... Some Raided, Some not Internet Speed Balls to the wall... Comcast Business... I've Spiked 30mb's Other Info Current plan for the next build is dual 16 core AMD's. 32nm tech, 32MB L3, twice the bang for my buck over intel. Wait a bit longer and I won't even need to buy HD's. Soon these things are gonna be a solid mass of RAM and CPU's, and cheap as dirt. |
04 Aug 2012
|
#6 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
I posted a method to run ERUNT as a task on Windows 7 a couple of years ago, and it works, but in several threads people have reported that restoring the backup is problematic. I have system images, so finally just deleted the ERUNT task and program (kept NTREGOPT). Have a look at this program, Registry Backup. Nice review here from Hal at Raymond Forum Backup and Restore the Whole Windows Registry or Selected Hives
Haven't used it myself, but it uses the Volume Shadow Copy Service, unlike ERUNT and others that use the RegSaveKey function. Have a read. A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
04 Aug 2012
|
#7 | | MS Windows 7 Home Premium 64-bit SP1 |
| My System Specs | | OS MS Windows 7 Home Premium 64-bit SP1 CPU Intel Core 2 Quad Q6600 @ 2.40GHz Motherboard ASUSTeK Computer INC. P5B-VM SE (LGA775) Memory Corsair PC2-6400 (400 MHz) 4.00 GB DDR2 Graphics Card GeForce 9600 GT 1024 MB Sound Card SB Audigy Monitor(s) Displays LG W2252 Screen Resolution 1680x1050 @ 60Hz Keyboard Microsoft Sidewinder X6 Mouse Microsoft Sidewinder Mouse PSU Corsair HX750W Case Antec 900 Cooling Thermaltake fans Hard Drives 977GB Seagate ST31000528AS ATA Device (SATA)
488GB Seagate ST3500630AS ATA Device (SATA) Internet Speed 2 Mbps Other Info D-Link DIR-655 router
WD My Book 1.0 TB
Buffalo NAS LS-CHL v2 2 TB Best Anti-Rootkit for x64 windows 7? problems? All times are GMT -5. The time now is 03:43 AM. | |