PDA

View Full Version : blacklight root kit detector


toploader
August 23rd, 2005, 03:46 PM
has anyone tried the free beta of this product?

http://www.f-secure.com/blacklight

Bubba
August 23rd, 2005, 07:22 PM
-{ Quote: "has anyone tried the free beta of this product?" }-I personally have not....but a Forum Search for blacklight turned up a number of recent threads concerning that program.

Just one for starters---> F-Secure BlackLight (http://www.wilderssecurity.com/showthread.php?t=86941)

toploader
August 23rd, 2005, 07:31 PM
thanks Bubba - not much enthusiasm by the looks of things - the mention of processguard smart is something i might look into - though what it's got against services.exe i'm not quite sure ;D

triedit
August 23rd, 2005, 09:47 PM
The problem with Blacklight is it's not that good at finding rootkits. You would do much better to use both RootkitRevealer from Sysinternals and UnHackme. Both of these are good rootkit detectors.

toploader
August 23rd, 2005, 10:15 PM
thanks triedit - are rootkits a big problem or a side issue do you think?

controler
August 24th, 2005, 07:38 AM
They are becomming more mainstream these days.

Had to box up a laptop and send it back to the "IT" people because of a drive by rootkit install.

They were using Mcaffee and it did detect something but could not remove it.

controler

Infinity
August 24th, 2005, 08:14 AM
-{ Quote: "They are becomming more mainstream these days.

Had to box up a laptop and send it back to the "IT" people because of a drive by rootkit install.

They were using Mcaffee and it did detect something but could not remove it.

controler" }-


hmm, maybe hips would help you in the future ;)

controler
August 24th, 2005, 10:12 PM
Infinity

It is not I that needs HIPS but rather the company I work for.
LOts a young punk IT people LOL

Currenty I use WIndows Shared Computer Toolkit, PG * Boclean, RAMDisk on
test machine.

Tyreman
August 29th, 2005, 07:56 AM
I know that "blacklight" removed some malware(or said it did!) from one machine but have never seen it detect or do anything else thereafter even after re dl'd any newer versions... if they were..