PDA

View Full Version : Should I add an anti-rootkit?


MikeBCda
October 25th, 2007, 02:25 PM
As usual, feel free to move this if there's a more appropriate home for it.

I consider my system (see sig) to be a reasonable compromise between security and convenience of use, plus I try to follow safe-surfing guidelines. Haven't seen any intrusions in ages except for adware, and those are (usually) eliminated easily enough.

I guess my concern these days is with rootkits, which (as I understand) are more or less undetectable by security apps not specifically looking for them. Are they a serious (and widespread) enough threat to look at adding an anti-rootkit to my "arsenal"? And if so, recommendations as to which one (preferably free, if there is such a thing, or at least reasonably priced)?

I know about that monster from Sony, as I'm sure everyone does (missed me, fortunately), but are they otherwise fairly rampant, or not worth worrying about yet?

the Tester
October 25th, 2007, 02:37 PM
I would add an anti-rootkit.
Ice Sword is my preference.
While I wouldn't be surprised to learn that some av's do well in rootkit detection and removal,there hasn't been a lot of testing in that area.At least not that I have found so far.

prozabor
October 26th, 2007, 06:58 AM
Yes, you can install for example Sophos Antirootkit and sometimes scan system.

aigle
October 26th, 2007, 07:12 AM
I will prefer a real time non-signature based application in this regard. If u like popups, then a HIPS, if u want install and forget- ThreatFire! It,s free.

U can run other Anti-RootKit tools as needed.

MikeBCda
October 26th, 2007, 02:00 PM
Thanks to all. :)

As a note to the mods, I see that this was already covered in the "How important is ...?" thread, which I'd missed, in much greater detail. So by all means feel free to either delete this one or merge it with the other.