![]() |
|
#1
|
||||
|
||||
|
BitDefender Antirootkit - BETA 1 released
BitDefender Antirootkit comes as a separate tool and can be run on Windows XP, Windows 2000 and Windows 2003 (including systems with BitDefender Internet Security v10 installed). |
|
#2
|
|||
|
|||
|
any links?
|
|
#3
|
||||
|
||||
|
Has anybody tried this yet?
controler |
|
#4
|
||||
|
||||
|
__________________
Using: F-Secure BETA Tester, Opera, Mozilla Thunderbird, FoxIT Reader (The best PDF Reader), GMAIL, utorrent, AIMP I usually test a lot of AV softwares and my TOP3 are Avira, F-Secure and Kaspersky (not necessarially in that order). "Everything you say can and WILL BE used against you." |
|
#6
|
||||
|
||||
|
I agree, the scan took a whopping 5 seconds on my system. I guess someone will have to run it on some rootkits to actualy see how it goes.
the two common are HackerDefender and Futo |
|
#8
|
||||
|
||||
|
Quote:
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code |
|
#9
|
||||
|
||||
|
It will be nice to see what other testers have found.
Spanner are you there? I would like to see some tests on known rootkits. Then is it a program that will work against unknown rootkits? controler |
|
#10
|
||||
|
||||
|
To make things clear, this anti-rootkit exists because BitDefender can only currently detect the rootkit infected files before they have run on the system. BD cannot remove rootkits yet if they are already running.
This Anti-Rootkit module was designed for that job. Detection of unknown rootkits will probably be integrated into the B-HAVE heuristics rather than the anti-rootkit technology.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code |
|
#11
|
|||
|
|||
|
bitdefender are a bit later on using a rootkit scanner because f-secure has included one since f-seure has had black light since the start of f-secure 2006
|
|
#12
|
||||
|
||||
|
Quote:
|
|
#13
|
||||
|
||||
|
Just tried it. It sure is fast!
|
|
#14
|
||||
|
||||
|
Intersting just ran this - didn't scan inside of my First Defence folder $ISR - I guess it does not look for hidden directories?
No log file created |
|
#15
|
||||
|
||||
|
I did try it quickly with HackerDefender (default settings), and DBAR beta allows to see the files, the process but I think the GUI could provide more informations :
Here you see the files http://img319.imageshack.us/img319/1...antirk17vf.jpg But all you get about hidden processes is their number :http://img386.imageshack.us/img386/6...antirk31xf.jpg Then BDAR wants to rename the files : http://img386.imageshack.us/img386/3...antirk40hh.jpg And does ask to reboot : http://img464.imageshack.us/img464/6...antirk59ug.jpg As expected, the files are renamed/not hidden anymore, and the driver is not loaded either : http://img464.imageshack.us/img464/403/bdantirk63dp.jpg I think the "clean" button could show more obviously in the GUI, during the first test I didn't see it , the most obvious button is "next". In fact, this is very close to BlackLight and RootkitRevealer. Personally, I prefer IceSword, more informative, but this one is more like a l"cleaner".But well, it's seems to be doing the job - although it was not able to see another rootkit, harder to detect.. ![]() nicM
__________________
Online Armor
|
|
#16
|
||||
|
||||
|
During another test, it was not able to see process(es) hidden by FU
. Oh, it's still beta - and IceSword doen't see it either.nicM
__________________
Online Armor
|
|
#17
|
||||
|
||||
|
Beta 2 of BD RU is now available.
nicM
__________________
Online Armor
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|