Rootkit Revealer
Results 1 to 5 of 5

Thread: Rootkit Revealer

  1. #1
    Join Date
    Jun 2002
    Location
    Port St Lucie, FL
    Posts
    360

    Rootkit Revealer

    I downloaded Rootkit Revealer software from www.sysinternals.com. Scanned my system and found 60 "Rootkits". Could someone tell me how to remove them, or should they be removed?
    Thanks for any help!

  2. #2
    Join Date
    Jan 2000
    Location
    Brooklyn, New York, USA
    Posts
    1,264
    Rootkit just seems to be another way of saying spyware, Adware or malware. Running a program like Spybot Search & Destroy, AdAware or any other good anti mmalware program should do a lot to clean out your registry.

    For some of these you may need to turn off System Restore before you clean and you may also need to look for specific instruction for removal for some of what is in your system.

    Run the programs I mentioned above and see how that goes first.

    Doc
    "To err is human, but to really foul things up you need a computer."

    Home Build Intel Core Duo 2.0 GHz, 2 Gig RAM, Dual Boot XP Pro and Ubuntu 8.04LS

  3. #3
    Join Date
    Jun 2002
    Location
    Port St Lucie, FL
    Posts
    360
    Doc, tried both, they found nothing. Rootkit data could be false negatives. Thanks for you reply.

  4. #4
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    From Sysinternals "You should examine discrepancies and determine the likelihood that they indicate the presence of a rootkit. Hidden from Windows API discrepancies are the ones exhibited by most rootkits, however you should expect to see a number of such entries on any NTFS volume since NTFS hides its metadata files, such as $MFT and $Secure, from the Windows API. In addition, there are a number of Registry keys that are inaccessible from the Windows API and will report as access-denied discrepancies. Files or Registry data created after a scan starts will also show up as discrepancies indicating the data is visible to the Windows API, but not to the low-level scan, so run RootkitRevealer on an idle system."

    Would the hits you show qualify as these types? If so, you are probably ok...

  5. #5
    Join Date
    Jun 2002
    Location
    Port St Lucie, FL
    Posts
    360
    Thanks HAN, I guess I am O.K.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •