Solved

Best rootkit cleaner if I have to slave drive in another system

Posted on 2010-08-23
8
2,856 Views
Last Modified: 2012-05-10
I have a posible rootkit infection and really don't want to wipe the drive clean. I am getting a blue screen on startup and cannot get into windows. I looked up the BSOD and seems like it could be a rootkit. I would like to slave the drive in another system and scan it for a rootkit. I already tried slaving it and running Vipre and it didn't detect anything. Maybe i should try supperantispyware.
any other suggestions?
0
Comment
Question by:calitech
8 Comments
 
LVL 9

Accepted Solution

by:
Darksquire earned 100 total points
ID: 33502978
0
 
LVL 8

Assisted Solution

by:tskelly082598
tskelly082598 earned 100 total points
ID: 33503620
0
 
LVL 22

Assisted Solution

by:optoma
optoma earned 100 total points
ID: 33503694
Try these when system is live. If a rootkit is detected(patched system file).
They should be able to replace the file.
Run TdssKiller and Hitmanpro.
http://support.kaspersky.com/viruses/solutions?qid=208280684
http://www.surfright.nl/en/hitmanpro

If still having issue run Combofix and post log here
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

IF slaving the drive or using a boot cd, keep the logfiles.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 25

Assisted Solution

by:madunix
madunix earned 100 total points
ID: 33508982
look @ Bootable antivirus Rescue CD
http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/
Bootable antivirus Rescue CD method consider as the most effective way to remove the virus, trojan and malware because it track down some viruses, trojans and other malware are embedded so tightly into your operating system that when you boot Windows the normal way.
0
 
LVL 2

Assisted Solution

by:dragon24
dragon24 earned 100 total points
ID: 33510119
Combofix does a great job as optoma suggested. You might also want to try Malwarebytes. www.malwarebytes.org
0
 
LVL 2

Expert Comment

by:dragon24
ID: 33637742
Calitech, have you tried any of the above suggestions? Any update status?
0
 

Author Closing Comment

by:calitech
ID: 33791594
thanks for the information
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
IPS Logs NMap Scans 1 92
ransomware and redirected folders 9 95
Sophos EC migration to Cloud. 1 86
auto script to stop bitdefender to scan my external drives 6 42
Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now