How do I scan for rootkits outside of windows?

pood

Senior member
May 10, 2005
216
0
0
There might be a chance that i received a trojan of some sort because I installed something early today, left for a hour and when I came back I saw 2 cmd prompt windows opened executing or making save1.exe

Since NOD32 and Trojan Hunter didn't find anything, I'm going to check for a rootkit. Currently running rootkit revelear. Since rookit revealer is not fool proof, I would also like to do a scan outside of windows.

My friend was suggesting using a different, OS and running the a scanner on that, how do I do that? I was thinking of using a ubuntu live cd.
 
 

pood

Senior member
May 10, 2005
216
0
0
sweet! is it the rootkit tool or is it one of the other free tools?
 

TheKub

Golden Member
Oct 2, 2001
1,756
1
0
Did you try rootkit revealer? There isn't a need to run it out side of windows. It won't remove it (its not an antivirus) but it will show you what and where it is which may require an repair\removal outside of windows.
 

pood

Senior member
May 10, 2005
216
0
0
my friend says it may not catch all the root kits, that's why I'm going to check outside of the OS
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,055
198
116
Thank you, i didn't know that and I am testing it out now. seems to be working well!

Originally posted by: MustISO
Antivir has a bootable CD you can use to scan outside of windows.

 

pood

Senior member
May 10, 2005
216
0
0
well I ran Rootkit revealer, found nothing really suspicious, maybe I'm just paranoid.

nod32, trojan hunter, panda rootkit, rootkit revealer showed nothing.
 

TheKub

Golden Member
Oct 2, 2001
1,756
1
0
Originally posted by: pood
well I ran Rootkit revealer, found nothing really suspicious, maybe I'm just paranoid.

nod32, trojan hunter, panda rootkit, rootkit revealer showed nothing.

Thats a safe bet.
 

Atheus

Diamond Member
Jun 7, 2005
7,313
2
0
Originally posted by: pood
maybe I'm just paranoid

Nah, pretty sure you have a virus - search google for save1.exe and you'll see the few results all mention viruses.

Was the 'something' you installed the Acrobat 9 torrent?

Run some anti-spyware stuff like spybot, adaware, etc etc. Should pick it up.