Need to update my software toolkit, any suggestions?

bytebuster

New Member
Reaction score
1
Location
Sacramento, CA
I'm getting back into the business, and want to know what pieces of software I need to battle these nasty Russian rootkits you guys are seeing. I have Malwarebytes, fixexefile, and TDSSkiller, will get them updated. I also plan on getting Combofix. I have CCleaner to clean the registry afterward. I have read of a file called unhide.exe that's needed for the "Your HDD has been erased" ransomware. Also I have heard of something called D7 that I remember seeing discussed a while back, but I didn't read the threads, but now techs seem to be using it with success. I've got a boot disk, too. I also have File Assassin for manual removals. Amy other suggestions?
 
I'm getting back into the business, and want to know what pieces of software I need to battle these nasty Russian rootkits you guys are seeing. I have Malwarebytes, fixexefile, and TDSSkiller, will get them updated. I also plan on getting Combofix. I have CCleaner to clean the registry afterward. I have read of a file called unhide.exe that's needed for the "Your HDD has been erased" ransomware. Also I have heard of something called D7 that I remember seeing discussed a while back, but I didn't read the threads, but now techs seem to be using it with success. I've got a boot disk, too. I also have File Assassin for manual removals. Amy other suggestions?

For inside-OS removal-

- Highly recommend D7 - its a great piece of kit.

- I also like UNHIDE - that has saved me hell-loads of time since I got onto it.

- Also, Im a big fan of LIBERKEY

For out-of-OS malware removal -

- SARDU if you're not already using it

- XBOOT is also very handy for a bootable ISO drive

- HIREN's is up to v 15 now. Another awesome resource (not just for malware removal of course)!
 
Last edited:
Loving that people are recommending D7 :) Thanks guys!

I wanted to extend the offer of assistance should you need any help in setup or usage. Feel free to email/PM/post on the D7 thread here/or visit my forums. I also take suggestions for D7 and try to implement them where possible, so if you use it and can think of anything you would like to see in the app, let me know!

I created D7 for mainly for malware/maintenance/data backup, but there are SO MANY other functions packed inside, thanks largely in part to suggestions from the TN community!

D7 can be used on a live system, or even on an offline OS (via a customer's HDD slaved to your tech bench PC, or from a WinPE based boot CD.) Note that when using from a booted WinPE based CD, D7 does need to be run from the ramdrive or a flash drive, as it needs write access to it's own directory...

---

Most other apps I would recommend you update your toolkit with are used as 3rd Party Tools with the D7 package.

So if you would like to try out D7, download it and setup the 3rd Party Tools first before you start going out all over the internet looking for various apps, as they may contain much of what you are looking for. Checkout the 3PT setup page here, and/or the youtube vid here. (There are also a number of other vids on my youtube page dealing with D7 usage and malware removal - granted they are a bit dated, I need to make updated vids and some others highlighting little known D7 functionality and newer malware removal techniques... anyway...

The setup process utilizes an app called Ketarin, which automatically downloads/updates your tools for you with one click! It's an awesome program which I highly recommend for your toolkit, whether you end up using D7 or not. Also done easily through D7, you can create your own custom Ketarin profiles for additional apps which aren't part of my default profile for Ketarin.

Good luck being back in the business!
 
thank you both the authors

for me D7 + UVK best toolkit + custom linux and win pe + hirens boot cd all in a usb drive
 
Yeah ukv is very good also and explains what things do a bit better than D7 to be honest.

Foolishtech would be nice if you could hover over some of the options and it would explain what exactly it does. Great utility still though
 
Foolishtech would be nice if you could hover over some of the options and it would explain what exactly it does. Great utility still though

Thanks! Well there seems to be so much explanation to do, and so little room for it within the GUI! Another issue is that I'm pretty bad at explaining things :( in universal terms...

I do have mouse hover / tool tips over most everything, I thought... If I'm missing something, let me know! With something specific you need to know about, just ask or let me know, if I don't provide an explanation for it within D7 (or it isn't detailed enough) I'll try to correct that in a future version.

I'm seriously considering figuring out a way to integrate a help file, or at least allow for one-click links to the online manual...
 
You been back in business since August after two months away. You've been posting every couple of weeks since then.

You've not been updating your toolkit in the last 4 months?

(The main thread on D7 has been going steady in the TechEyesOnly forum since May)

I haven't had any customers since I went back into the business. I advertised on Craigslist, but didn't get any replies, of course. I just now put my business on Facebook, and my Yellow Pages ad comes out at the beginning of March. I just now have been getting into seriously advertising. I've had other things going on in my life and the business got put on the back burner. Now it's a priority. So that's the short answer to your question.
 
Loving that people are recommending D7 :) Thanks guys!

I should let you know that the D7 download on Major Geeks is corrupted. I downloaded it and when I tried to extract it, my PC said it was an empty folder. I tried OPENING it instead, and was told it was unreadable. I had to download it from CNet.
 
I should let you know that the D7 download on Major Geeks is corrupted. I downloaded it and when I tried to extract it, my PC said it was an empty folder. I tried OPENING it instead, and was told it was unreadable. I had to download it from CNet.

Hmm... I'll contact Tim over there and see if he can repost it (for everyone else in the future...)

Your best just going to FoolishTechs site and downloading direct, cant imagine why your going through 3rd party sites?

I'm that guy myself, I always download direct if possible... but I do like it when ppl use Majorgeeks though, they are cool people (and I have no other way to track my downloads lol)
 
Your best just going to FoolishTechs site and downloading direct, cant imagine why your going through 3rd party sites?

I DID go to his site, and there were two download links. One was to download via Majorgeeks, and the other via CNet. Maybe I missed something? I doublechecked to make sure that I was at foolishIT.com, and I was. Again, if I've missed something let me know.
 
Back
Top