Sophos Anti-Rootkit: using the command line scanner
Where possible you should use the graphical user interface (GUI) version of the Sophos Anti-Rootkit tool on a single computer, not the command line version. See the user manual for instructions on how to do this.
This article gives background information on using the command line version in exceptional circumstances, or when using the command line tool over a network.
What to do
1. Running the command line version
Open a command prompt and change to the directory in which you placed the Sophos Anti-Rootkit tool (by default this will be C:\SOPHTEMP).
- Type
SARCLI
This will:- scan running processes for hidden items
- scan the Windows registry for hidden items
- scan the local hard drives for hidden items
- create the log file %TEMP%\sarscan.log, where %TEMP% is the Windows temporary directory of the scanned computer.
- Once you are satisfied that automatic removal will not remove any valuable files, run another scan to remove the rootkit. Type
SARCLI -clean -restart
This will:- scan running processes for hidden items
- scan the Windows registry for hidden items
- scan the local hard drives for hidden items
- append scan information to the existing sarscan log
- restart the computer to clean up all hidden items recommended for removal (the computer will only be restarted if a rootkit is found)
- on an infected computer, create the log file %TEMP%\sarclean.log, where %TEMP% is the Windows temporary directory of that computer. (If you run a second cleaning scan this log will be overwritten.)
- Run a final scan to ensure that all components have been removed. Type
SARCLI
After running Sophos Anti-Rootkit to remove the rootkit you should:
- Purge System Restore on all Windows XP computers.
- Check your software or hardware firewall to ensure that it is running correctly.
- Check your that your anti-virus software is running correctly.
Run a scan with your anti-virus software and remove any worms or Trojans that were using the rootkit. Then follow any extra instructions in the analyses for those malicious programs (e.g. install any patches or use Windows update).
2. Making a copy of the command line tool on a CD
When cleaning more than one computer, or if problems are encountered running the tool, you may need to use a copy from a write-protected CD, or similar medium.
To prepare a CD version, do as follows.
- Go to an uninfected computer.
- Download Sophos Anti-Rootkit.
- Double-click the downloaded file to extract the contents into a folder called SOPHTEMP.
- Copy the contents of the SOPHTEMP folder to a medium that can be write-protected (the example here uses a CD).
- Write-protect the disk (e.g. on a CD/R or CD/RW, close the session).
If you need more information or guidance, then please contact technical support.
- Article ID: 17091
- Created: 18 Aug 2006
- Last updated: 9 Oct 2008
