- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
We’re worried that one or more of our PCs are infected with malware, perhaps rootkits. We have scanned and cleaned with the latest antivirus definitions, and the machines are still running slow and behaving strangely. What kinds of rootkit scanners are available?
There are a variety of rootkit scanners available. GMER is free and scans aggressively. The output can be difficult to read, but the program does highlight problems it finds in red in the output listing to indicate which entries should be deleted. And it provides a right-click context menu allowing you to choose between stopping the process, removing the service and removing the files. GMER can find and remove both user-mode and kernel-mode rootkits. Another tool to look at is RootkitRevealer from Microsoft, which is part of the Sysinternals tools collection. RootkitRevealer now runs as a Windows service so you no longer have to be at the console using a command prompt to use it. F-Secure provides a rootkit search tool called BlackLight that is included in the company's security suite and is available as a standalone download. Another interesting program is RootKit Hook Analyzer. This program identifies all the kernel hooks present on the system. Kernel hooks intercept system services to perform additional processing on the way to the system service. Not all kernel hooks are malicious, but most kernel-mode rootkits use them. This is a lower-level look at what is going on in your machine than some of the more user-friendly programs. Most of the antispyware programs you can find also do some checking for rootkit-type infections so you may want to use multiple scanning programs to search for whatever is slowing your PCs down and making them behave strangely.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment