CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Routine Maintenance Scans

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
!RuyLopez

Colonel
Colonel
Premium Member

Joined: Jan 27, 2006
Posts: 1764

Premium

PostPosted: Fri Sep 22, 2006 4:19 am    Post subject: Routine Maintenance Scans
Reply with quote

Greetings,

I am wondering if you experts suggest that users scan for rootkits as one would for any malware as part of a routine maintenance protocol? If so, what applications would you recommend be used?

Best regards,
RL

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Fri Sep 22, 2006 2:43 pm    Post subject:
Reply with quote

Yes, and in fact everytime you get Microsoft Updates your box is scanned for well known rootkits.

I can hardly wait for the AVG Anti-Rootkit app to come out of beta since it's the most user friendly one I've seen to date.

Pretty sure the others have their own favorites.

The problem for now, with routine scans using rootkit detectors, is false positives and newbies who do not understand the results. For an advanced user this might be pretty simple, but for those who don't know it could be very difficult. You know that saying about something not being rocket science? Rootkits are rocket science, even for the experts.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Tibilicus

Corporal
Corporal


Joined: Sep 10, 2006
Posts: 60
Location: USA

PostPosted: Fri Sep 22, 2006 3:01 pm    Post subject:
Reply with quote

Hi prince_Serendip Just out of genrel itnerest I havn't heard much about the AVG anti rootkit. How efective is it and will they bundle it with there AVG free AV program?

Thanks

Tib

Back to top
View users profile Send private message
!RuyLopez

Colonel
Colonel
Premium Member

Joined: Jan 27, 2006
Posts: 1764

Premium

PostPosted: Fri Sep 22, 2006 3:17 pm    Post subject:
Reply with quote

Greetings,

Prince_Serendip wrote:
The problem for now, with routine scans using rootkit detectors, is false positives and newbies who do not understand the results.

I will assume that users are sufficiently sophisticated to come here with questions regarding the results of any scans. I will be most interested to see the different recommended tools and suggestions as to appropriate protocols to implement.

Best regards,
RL

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Sep 23, 2006 5:53 am    Post subject:
Reply with quote

Hi Tib,

Check this thread on AVG Ant-Rootkit here: CastleCops Link/t165363-AVG_Anti_Rootkit_1_0_0_13_Beta.html for more info and the download link. Remember that it's a beta which means it's not ready yet for primetime, and there could be program bugs and problems.

Hi Ruylopez: We get people here who are simply curious and/or want to learn more. This is good but it's a far cry from full knowledge and understanding. We're working on it every day. Thumbs Up


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
!RuyLopez

Colonel
Colonel
Premium Member

Joined: Jan 27, 2006
Posts: 1764

Premium

PostPosted: Sat Sep 23, 2006 3:03 pm    Post subject:
Reply with quote

Greetings Prince Serendip,

Quote:
Hi Ruylopez: We get people here who are simply curious and/or want to learn more. This is good but it's a far cry from full knowledge and understanding. We're working on it every day.

One must start somewhere. And learning is what it is all about.

Best regards,
RL

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer