Best Anti-Rootkit for x64 windows 7?

Carbonyl

New member
Power User
Local time
1:33 AM
Messages
76
Hi everyone.

It's been a while since the 64-bit version of Win 7 became mainstream. Back when it was new, there were very few anti-rootkit solutions available for any x64 system, and very few people who were concerned about rootkits on 64-bit operating systems.

Times, though, have changed. Rookits are more capable than ever, infecting and hiding in the MBR of your hard disk. This not only makes it possible for them to survive a reinstallation of the operating system (if a format is not performed first), but also renders them essentially invisible to everything you can try from within the operating system! This is something that even impacts x64 systems, regardless of PatchGuard or driver signing.

So now that the rootkits have caught up, I'm curious as to what tools are available to scan, detect, and remove them? My old standby, Rootkit Revealer, seems to be still unavailable for x64 systems. The much lauded TDSSKiller is also only functional on 32 bit windows systems. I've heard that Sophos Antirootkit is x64 compatible, but I've also read that it's plagued with false positives and causes system instability.

Does anyone have any recommendations for a good x64 compatible rootkit scanner?
 

My Computer My Computer

At a glance

Windows 7 RTMi7 9206 GB PatrioteVGA GeForce 275 GTX
Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
Here's one of my concerns about listing the best of anything. If your machine doesn't have any rootkits, then logically, a rootkit scan shouldn't show anything. But if it doesn't show anything, then how do you know if the machine is infected but the scan didn't pick it up? For that reason I use the same logic that people use for any similar product like antivirus or antispyware apps. No anti-whatever is 100% effective 100% of the time. Pick one for real time (or on demand) scanning and use others for extra on demand scans just to make sure the primary didn't miss something.

Best Free Rootkit Scanner/Remover

I'd also add one more: Hitman Pro 3 - SurfRight
 

My Computer My Computer

At a glance

Win 7 Pro 64-bitIntel i5 2.4 Ghz8GB DDR3Intel HD 3000
Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
I have Sophos Anti-Rootkit, and Panda Anti-Rootkit, both are said to be x64, Sophos says so on their site. Neither have ever found anything, or caused any problems. Neither have updated in a while either.

There are more advanced tools, but they require advanced knowledge as well. Such as Ice Sword, and GMER.

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I use Sandboxie when surfing, delete upon finish, no more rootkit:D If im not mistaken.
 

My Computer My Computer

At a glance

Win 7 64 premium
OS
Win 7 64 premium
Other Info
7 fw, LUA, UAC on high, IE-9 w/ smartscreen on, SANDBOXIE
+1 on the Sandboxie. I like the concept, surprised OS developers never conceptualized it.

I'm actually boning up on rootkits and tooling, after a sweet attack by a "Toolbar". What a bear that thing was... or should I say, IS... Its an unsolicited installer too, weeee.... Good times indeed.

As it turns out the newest variant of the "Babylon Toolbar" entrenches itself in your NTUSER.DAT. Little ******* wouldn't stay dead, came back at each reboot, and just as strong as ever. Don't bother trying to restore registry backups while your OS is online, it'll eventually eat up all your good backups...

I had to drop my NTUSER.DAT cold, and bring in a fresh copy. Meaning all done via live disk, and with the OS "Completely offline". At the same time, I did a thorough cleaning of my system files. And walla, here I am... I haven't even brought my raid storage back online yet... lol...

While I'm thinking of it, ERUNT. Get it, and let it run every boot! You should even forget about it like I did. In all seriousness, this application was compiled back in 05, in our world of IT that's practically an antique. But what a life saver. And yes its happy as a clam on x64 systems. My current being a heavily modded Server 08 R2 package, x64 of coursee, and ERUNT just save my ass! Oh, and did I mention how I had just wiped my restore points prior to my infection. I was so glad I did that, wow... Good job fella! :thumbsup: Like I said "weeeeee...."
 
Last edited:

My Computer My Computer

At a glance

Server 2008 R2, x64... Heavily modded, plus a...AMD Phenom II X6 1055T, Clocked to 3.6GHz Coo...16GB, DDR3 PC3-8500, PatriotGeForce 9800GTX+, Direct 10? Nope... Code Dor...
Computer Manufacturer/Model Number
GuruBuilt...
OS
Server 2008 R2, x64... Heavily modded, plus all the 7 wizbang...
CPU
AMD Phenom II X6 1055T, Clocked to 3.6GHz Cool & Quiet, 2yrs
Motherboard
MSI 870A-G54, also 2yrs old... Rock Solid!!!
Memory
16GB, DDR3 PC3-8500, Patriot
Graphics Card(s)
GeForce 9800GTX+, Direct 10? Nope... Code Dork 24/7
Sound Card
Whats a sound card? Boards got a channels, that not enough?
Monitor(s) Displays
Dual 23" AOC, Fake Digital Signatures For Proper x64...
Screen Resolution
1080p
Hard Drives
Lots... Some Raided, Some not
PSU
1k
Case
Cooler Master
Cooling
Couple 120's on either end... Very near silent...
Keyboard
No-name junk, buttons stick, glued baseboard to back 4 angle
Mouse
Laser Logitech, usb....
Internet Speed
Balls to the wall... Comcast Business... I've Spiked 30mb's
Other Info
Current plan for the next build is dual 16 core AMD's. 32nm tech, 32MB L3, twice the bang for my buck over intel. Wait a bit longer and I won't even need to buy HD's. Soon these things are gonna be a solid mass of RAM and CPU's, and cheap as dirt.
I posted a method to run ERUNT as a task on Windows 7 a couple of years ago, and it works, but in several threads people have reported that restoring the backup is problematic. I have system images, so finally just deleted the ERUNT task and program (kept NTREGOPT). Have a look at this program, Registry Backup. Nice review here from Hal at Raymond Forum

Backup and Restore the Whole Windows Registry or Selected Hives

Haven't used it myself, but it uses the Volume Shadow Copy Service, unlike ERUNT and others that use the RegSaveKey function. Have a read. A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi

My Computer My Computer

At a glance

MS Windows 7 Home Premium 64-bit SP1Intel Core 2 Quad Q6600 @ 2.40GHzCorsair PC2-6400 (400 MHz) 4.00 GB DDR2GeForce 9600 GT 1024 MB
OS
MS Windows 7 Home Premium 64-bit SP1
CPU
Intel Core 2 Quad Q6600 @ 2.40GHz
Motherboard
ASUSTeK Computer INC. P5B-VM SE (LGA775)
Memory
Corsair PC2-6400 (400 MHz) 4.00 GB DDR2
Graphics Card(s)
GeForce 9600 GT 1024 MB
Sound Card
SB Audigy
Monitor(s) Displays
LG W2252
Screen Resolution
1680x1050 @ 60Hz
Hard Drives
977GB Seagate ST31000528AS ATA Device (SATA)
488GB Seagate ST3500630AS ATA Device (SATA)
PSU
Corsair HX750W
Case
Antec 900
Cooling
Thermaltake fans
Keyboard
Microsoft Sidewinder X6
Mouse
Microsoft Sidewinder Mouse
Internet Speed
2 Mbps
Other Info
D-Link DIR-655 router
WD My Book 1.0 TB
Buffalo NAS LS-CHL v2 2 TB
Back
Top