Gizmos Freeware Reviews  

Go Back   Gizmo's Freeware Forum > Debating Chamber > Security

Reply
 
Thread Tools Display Modes
Old 08. Jul 2011, 01:53 PM   #1 (permalink)
Senior Member
 
Join Date: Nov 2009
Posts: 440
Default Question about Rootkit Scanners/Removers

Hi guys,

I posted this question in the "Best Free Rootkit Scanner/Remover" some time ago - I noticed it doesn't have a dedicated editor only aftewards.

So, here it is:
Quote:
I'm familiar with the first four ones and have noticed that, except for Gmer, the others don't update often - Sophos is about a year old and Root Repeal & F-Secure Blacklight Rootkit Eliminator are about two years old.
This may be a silly question, but I'm wondering, are they considered to still be very effective because rootkits' updates are slow as well?
Thanks in advance.
__________________
26Dolphins
26Dolphins is offline   Reply With Quote
Old 09. Jul 2011, 02:02 AM   #2 (permalink)
J_L
Co-Author, Best Free Security List
 
J_L's Avatar
 
Join Date: Dec 2008
Posts: 1,475
Default

I find Hitman Pro one of the most effective, but it's removal is a 30-day trial.
J_L is offline   Reply With Quote
Old 10. Jul 2011, 03:51 PM   #3 (permalink)
Senior Member
 
Join Date: Nov 2009
Posts: 440
Default

Thanks for the reply J.L. (I'm familiar with Hitman Pro), but it didn't enlighten me on my original question

Thanks anyway.
__________________
26Dolphins
26Dolphins is offline   Reply With Quote
Old 10. Jul 2011, 06:26 PM   #4 (permalink)
Senior Member
 
bo.elam's Avatar
 
Join Date: Nov 2009
Posts: 1,224
Default

Hi 26Dolphins, my reply might not answer your question, but at one point
in the past I asked myself the same. The only thing that I could figure is
that dedicated anti rootkits don't use or need to update often because
they don't use definitions like a regular antivirus.
The applications you mentioned are scaners which as you know, detect
infections after you been infected so I decided to go a different way and
use something that prevents rootkit infections, that's how I got to SBIE.
I don't know if you are using SBIE but using the sandbox is a sure way to
stop rootkits when you are browsing/running programs under the
supervision of Sandboxie.
Sandboxie does not allow drivers to be installed.

Bo
bo.elam is offline   Reply With Quote
Old 10. Jul 2011, 10:17 PM   #5 (permalink)
J_L
Co-Author, Best Free Security List
 
J_L's Avatar
 
Join Date: Dec 2008
Posts: 1,475
Default

If they use specific signatures, then they won't be effective anymore without updating (unless uploading to cloud like HMP). If they use heuristics and behaviour analysis, then they can still be effective.
J_L is offline   Reply With Quote
Old 11. Jul 2011, 06:05 PM   #6 (permalink)
Senior Member
 
Join Date: Nov 2009
Posts: 440
Default

Thanks to both for replying.

I don't have an infection, thankfully.
The question came up after noticing that the version updates of SuperAntiSpyware include improvements to its rootkit detection engine, while the dedicated rootkit scanners/ removers don't update often, yet are considered effective.

I'm quite new to SBIE, but can already appreciate its advantages.

Thanks again.
__________________
26Dolphins
26Dolphins is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 10:34 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2