Announcement

Collapse
No announcement yet.

Rootkit detector review

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Rootkit detector review

    Yesterday's hardocp.com site had a link to an article reviewing Rootkit Detectors.

    Reading the article easily doubled my knowledge of rootkits and I learned about detectors I didn't know existed. I also learned the dectector I'd been using was not the most effective choice.

    http://www.eetimes.com/news/latest/s...6901422&pgno=1

    #2
    Re: Rootkit detector review

    The top two are apparently Rootkit Unhooker and Trend Rootkit Buster.
    I grabbed both and am running Unhooker right now.

    Too bad I saw this post one day late... I was running RK Revealer on a client machine last night. It took forever to run, and the results were ambiguous. The reviewer found similar results with Revealer, and recommended the others instead.

    Comment


      #3
      Re: Rootkit detector review

      good article
      problem is with a rootkit on a webserver it is advisable to reinstall......
      capacitor lab yachtmati techmati

      Comment


        #4
        Re: Rootkit detector review

        Fdisk/Format is the only way to completely douche out a Microsoft installation.

        The equivalent is keeping GHOST images of the newly installed system that are known to be free of contamination. I have a commercial client who operates an adult business. She is online constantly as a buyer for the business, and gets infected all the time. I restore her from a GHOST image, and she is done. Much less expensive and time consuming than doing a total rebuild.

        BTW, if anybody is interested, check out: www.sandboxie.com for a great browser condom. I'm running this now, and in several client sites.

        Comment


          #5
          Re: Rootkit detector review

          bgavin; you're telling me there is crap that can get through Opera or Firefox?

          Because she isn't using Internet Explorer for adult content _right_?
          "The one who says it cannot be done should never interrupt the one who is doing it."

          Comment

          Working...
          X