Would scanning a PC using Hijack-this (ads scan – on the tools menu).. assuming it found some alternative data streams (not including MS FAX!)…. be the quickest way of having an ‘indication’ of a rootkit?
Cheers
TAJ
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » HIJACK ADS scan – quickest indication of a rootkit
I would use Mark Russinovich’s (oops, Microsoft’s!) tool “Rootkit Revealer“. Or there is a rootkit finder/remover by Sophos, the antivirus firm. And no doubt many others by the other AV manufacturers.
I’m rather puzzled why you think that Merijn’s HijackThis, which checks browser hijacking, registry entries, startup links, etc, would have anything to say about rootkits, which came after HijackThis was written…
John
John,
Thanks for that. The reason I ask is that I was fixing a friends PC that had a rootkit on it. After the rootkit was stopped / disabled from starting.
A scan with hijack-this’ ADS scan (config > misc tools > Open ADS spy) revealed the same file where the rootkit was hidden. I forget the exact details.
but it found something along the lines of this.
windowssystem32nameoffile : (colon) name of hidden file within
What I’d wish I’d have done was the hijack this ADS scan before the rootkit was disabled from starting.
Cheers
TAJ
I’m not sure that HijackThis would have even seen that file if the rootkit was still running. If my understanding of rootkits is correct, they hide themselves from detection by that sort of program almost completely.
I have never delt with a rootkit personally (and hope I never have to). I’m basing my comment on what I’ve read about them.
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.
Notifications