View Full Version : Know any good programs that detect rootkits?
latenight
October 17th, 2004, 10:46 AM
I have heard TDS-3 detects "some" rootkits, know any other programs that do also? For example will Pest Patrol detect them? How about Ewido? SpySweeper?
The more programs that you could list that do detect rootkits the better. Thanks for any help with what I feel is an important problem not often discussed here.
gerardwil
October 17th, 2004, 10:52 AM
Hi,
Have a look here:
http://home.arcor.de/scheinsicherheit/rootkits.htm
Gerard
Wayne - DiamondCS
October 17th, 2004, 10:54 AM
-{ Quote: "I have heard TDS-3 detects "some" rootkits" }-
It detects more rootkits than any other program I know of, just look at http://tds.diamondcs.com.au/primary.txt and search for rootkit, then look at the lists of other scanners. :)
But in regards to detection, prevention is even better - you don't need to get infected then!Process Guard (http://www.diamondcs.com.au/processguard/) blocks all known rootkit driver loading points in the system, as well as providing execution protection so even the trojan that drops the driver won't be able to execute, let alone attempt to install the driver. Two layers of security in one :)
iceni60
October 17th, 2004, 11:01 AM
http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt
EDIT sorry not a program just some reading
latenight
October 17th, 2004, 11:34 AM
Thanks very much Gerardwil, Wayne - DiamondCS, and Iceni60. All your info was very helpful.
Gerardwil, Looks like some good programs, even Process Guard made the list.
Wayne, looking at that list you provided makes me sick. It amazes me there is so much garbage out there. The people who make this crap really need to get a life!
Icene60, thanks for the reading, any info about detecting/removing rootkit is more than welcome.
Thanks.
GlobalForce
October 17th, 2004, 11:52 AM
We must first, "Know Our Enemy (http://216.239.39.104/search?q=cache:5xjMAfPMjyQJ:www.giac.org/practical/GSEC/Adam_Gaydosh_GSEC.pdf+manual+rootkit+detection&hl=en&start=4)".
GF
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums