CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Vaccination

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Arenlor

Lieutenant
Lieutenant


Joined: Feb 25, 2006
Posts: 274
Location: USA

PostPosted: Sat Feb 24, 2007 1:22 am    Post subject: Vaccination
Reply with quote

Hey I'm trying to vaccinate my brand new Vista laptop, so I want to make sure I have nothing on here yet, any suggestions as to what rootkit scanner to use?

Oh and don't forget to announce when the book comes out I want to purchase it for sure.


_________________
Who is this General Fault and why is he trying to read my HDD?
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Feb 24, 2007 6:45 am    Post subject:
Reply with quote

Rootkits For Dummies was published in USA and Canada on January 30, 2007. Best price I've found so far is at Amazon: http://www.amazon.com/Rootkits-Dummies-Computer-Tech/dp/0471917109

Rootkits are not like other malware. You cannot vaccinate against them, but you can protect your computer.

Have you had the Vista laptop online yet? Best thing to do with a new, out-of-the-box computer before you take it online is make sure you have a firewall (a dedicated bi-directional, and definitely NOT the Windows Firewall), AV, AT and AS. Then make a full backup of everything on it to a seperate drive (even to CDs), just in case. So many people never make such backups regularly. Then when they get in trouble, they're hosed.

Rootkits need something else in order to load, such as a backdoor or other kind of trojan. If you guard against that stuff you will not likely have to deal with them.

We give suggestions in the book for applications you could use. We can provide some here too if you'd like.

You could download RKR (Rootkit Revealer) and post the log here. Don't try to interpret it yourself as all scanners will show false positives.

http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx

Free download is at the bottom of the page. RKR will only detect. It does not remove.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Arenlor

Lieutenant
Lieutenant


Joined: Feb 25, 2006
Posts: 274
Location: USA

PostPosted: Sat Feb 24, 2007 6:56 am    Post subject:
Reply with quote

Does pulling it out of the box, setting up Vista, disabling the AV and AS that come with it then connecting to some random insecure Linksys network with it sound like a good idea Wink that's what I did, but I did it to download and install AVG HJT Spybot and AdAware. I wasn't thinking and was just excited to have my computer after saving up my money for a year to by one. I bet my one local store has a copy of RK4D for like 10, it's a cheapie store.


_________________
Who is this General Fault and why is he trying to read my HDD?
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Feb 24, 2007 8:43 am    Post subject:
Reply with quote

Firewall first. I suppose you used the onboard one. I would suggest ZoneAlarm or Agnitum Outpost. Here's some words about why you might still wish to use ZA on Vista: http://labnol.blogspot.com/2006/04/zonelabs-zonealarm-vs-windows-vista.html

SuperAntiSpyware is the best right now: http://www.superantispyware.com/
And they have a freeware version. Thumbs Up

For an Anti-Trojan I'd suggest A2: http://www.emsisoft.com/en/

Your HJT post for reference: CastleCops Link/t180683-Vaccination.html

AVG-free is okay. I use it. Spybot S&D and Adaware are good too.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Arenlor

Lieutenant
Lieutenant


Joined: Feb 25, 2006
Posts: 274
Location: USA

PostPosted: Sat Feb 24, 2007 9:58 pm    Post subject:
Reply with quote

I can only afford free stuff, I really don't have money, but that rootkit revealer won't save a log for me, after it finishes it basically crashes. I doubt I have any though, but it would always be nice to be paranoid about it.


_________________
Who is this General Fault and why is he trying to read my HDD?
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sun Feb 25, 2007 10:07 am    Post subject:
Reply with quote

I prefer freeware too. I could buy a new computer every year for what I pay for Internet. Shocked

A friend of mine wrote this up:
http://wiki.castlecops.com/Roll_your_own_Free_Security_Suite

For backup I would suggest The Replicator (also free for personal use and it's in our book): http://www.karenware.com/powertools/ptreplicator.asp

Much, much easier to use, and quick. It will copy anything.

You might get IceSword. It can detect and remove: CastleCops Link/t165203-IceSword_Instructions_in_English_Illustrated.html


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Arenlor

Lieutenant
Lieutenant


Joined: Feb 25, 2006
Posts: 274
Location: USA

PostPosted: Sun Feb 25, 2007 8:46 pm    Post subject:
Reply with quote

Well IceSword doesn't work, I'm really beginning to hate Vista, AVG anti-spy doesn't work either. Their rootkit remover beta works as does their anti-vir, superanti-spy does too, plus HJT AdAware and Spybot, so I think I'll be ok, but I can't get any firewall to work, which is disturbingly funny.


_________________
Who is this General Fault and why is he trying to read my HDD?
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Feb 26, 2007 7:09 am    Post subject:
Reply with quote

There's a real problem with Vista's firewall capabilities. Read here: Vista Firewall Fails...

At least they are not putting anyone out of business in that respect. Rolling Eyes

How to Turn Off the Vista Firewall

You will need to turn it off before loading a new firewall such as ZoneAlarm.

HTH Thumbs Up


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer