How to Detect Rootkits on a Computer or Laptop by Britec

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
22,676
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Aug 5, 2009

How to Detect Rootkits on a Computer or Laptop by Britec

Rootkits are used by hackers to hide intrusions into a computer. Rootkits are often used to obtain administrator privileges to the system and to other machines on the network so that they can spread malware, track keystrokes or open a backdoor into the system. Because of their stealthy nature, rootkit detection is difficult.
--------------------
Gmer download: http://www.gmer.net/

GMER is an application that detects and removes rootkits .
It scans for:
hidden processes, hidden threads, hidden modules, hidden services, hidden files, hidden Alternate Data Streams, hidden registry keys, drivers hooking SSDT, drivers hooking IDT
drivers hooking IRP calls, inline hooks
----------------------
RootRepeal download: http://ad13.geekstogo.com/RootRepeal.zip

The ability to scan and display all currently loaded drivers and tell you whether they are hidden and whether the drivers file is visible on disk.
Scans for hidden, locked or falsified files on the system
Scans and displays the currently running processes (similar to Process Explorer) but shows if the process is hidden or locked.
Scans the SSDT (system service descriptor table) to see if any services are hooked.
Scans for Stealth objects which looks for rootkit symptoms in general.
Scans for Hidden services and displays them.
Once you have found something malicious, you can right click on the driver/file/service and either copy, wipe or force delete it.
-----------------------

Rootkit unhooker download: http://www.softpedia.com/get/Security/Security-Related/Rootkit-Unhooker.shtml
------------------------------

http://www.briteccomputers.co.uk
http://www.britec.org.uk
http://www.pcrepairhertfordshire.co.uk

  • likes, 1 dislikes

Link to this comment:

Share to:

Uploader Comments (Britec09)

  • hello britec.is it true that 64bit computers are more immune to these rootkits?thanks.

  • @MrArnold1972 I have never seen a Rootkit on a 64bit O/S

    But I would not like to say 64bit is 100% rootkit free...I suppose only time will tell, but as of right now Rootkits wont run on 64bit O/S

  • Please help! T.T my computers been infected by 7 rootkits and malware defense. I disconnected my computer from the internet and then scanned tried scanning with malwarebytes, superantispyware, and an antivirus program. But none of them work!

    Superantispyware and malwarebytes wont open and everytime I try the antivirus program my computer freezes. My computer wont

    even let me do a system restore. Im typing this from my phone right now and desperately need help!

  • @GTOrulezzz try running malwarebytes in safemode, keep pushing F8 at startup and enter safemode

  • when i run the scan it scans for about five seconds and then the program freezes. why is that?

  • @hermanoguzman there is other programs you can try, Root Repeal, Panda Anti Rootkit, Sysinternals RootkitRevealer, IceSword, DarkSpy.

    I have had that same problem with Gmer, maybe its the root kit locking up the pc? not sure

see all

All Comments (83)

Sign In or Sign Up now to post a comment!
  • @KASHEDS well thats the difference. the fact that they are both a different size is mainly the difference

  • @destructias445 so its just a diffent size so what

  • @KASHEDS k. but one has a bigger screen then another.

  • @destructias445 lol there the same thing its called a desktop a desktop is older than a laptop computers and laptops are the same thing just differnt names

  • @KASHEDS A computer is older then a laptop daaa

  • a computer is a laptop daaa

  • @Britec09 my computer is a 64bit OS, and I do indeed have alureon.a...microsoft security essentials found it, and I have seen evidence of svchost's activity being odd, so I don't have a doubt it's making stuff up! haha

    for some reason I can't access my F8 function on startup, so I can't even enter safemode. My computer boots normally in any other case.

  • is it compatible with av

  • Gmer is great thanks

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more