![]() |
|
#1
|
||||
|
||||
|
Does onecare detect rootkits? Playing with it on Vista and hate to say, but I kinda like it.... Has anyone ran ThreatFire alongside it as well?
Thanks!!
__________________
http://www.vipreantivirus.com/ |
|
#2
|
||||
|
||||
|
im not sure,
but their client security does, so does this mean onecare should? http://www.microsoft.com/forefront/c...y/default.mspx |
|
#3
|
|||
|
|||
|
Though it does not specifically say on OneCare's website, I am led to believe that it does.
Quote:
MS AntiMalware Team Blog
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#4
|
||||
|
||||
|
Quote:
![]()
__________________
http://www.vipreantivirus.com/ Last edited by Bubba : January 2nd, 2008 at 07:19 PM. Reason: added appropriate closing quote tags |
|
#5
|
|||
|
|||
|
Oh, I forgot to mention that I did run Threatfire once with OC. It seemed to interfere with OC's automatic scanning.
Since we are in doubt about OC's rootkit detection maybe better just download a free rootkit cleaner like F-Secure's Blacklight or such to be safe.
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#6
|
||||
|
||||
|
Well I guess it should be but I really can't find proof
__________________
ESS 5 beta, Hitman Pro + ..... |
|
#7
|
||||
|
||||
|
Quote:
or prevx does a free scan, but aint sure if it has removal, but it can still tell you if you have any as quickly as a minute or so. http://www.antirootkit.com/blog/2007...its-has-begun/ |
|
#8
|
|||
|
|||
|
I do use Blacklight myself but I added "and such" so I wouldn't appear too biased
AVG has one as well but the Vista version isn't out yet. I will probably use it when it does to keep it "all in the family", lol.
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#9
|
||||
|
||||
|
How about norton anti-bot? Since TF has issues with OC. Black light may also come in handy.
Thanks!!
__________________
http://www.vipreantivirus.com/ |
|
#10
|
|||
|
|||
|
AntiBot ran well with OC on my 'puter.
![]() I installed Threatfire one evening and later in the early morning I had a OC scan set up. When I got up later that morning and checked the computer the scan had froze. I took TF off and it never happened again. It may just be hardware related but not sure ![]()
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#11
|
||||
|
||||
|
Quote:
That is good to know. I'll try anti-bot and blacklight for giggles. Thanks!!
__________________
http://www.vipreantivirus.com/ |
|
#12
|
|||
|
|||
|
You're welcome
![]() Since you got my curiosity up, I have inquired about whether OC scans for rootkits in the *vista.security newsgroup. I will see what the MVPs has to say and report back.
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#13
|
||||
|
||||
|
Quote:
Then let me thank you in advance!! ![]()
__________________
http://www.vipreantivirus.com/ |
|
#14
|
||||
|
||||
|
Here's a post. Re: WLOC and RootKits detection
|
|
#15
|
||||
|
||||
|
Quote:
Again some clever wording... potentially detect rootkits; However, it does make me feel better... Thanks!!
__________________
http://www.vipreantivirus.com/ |
|
#16
|
|||
|
|||
|
Thanks Ron, I was just on Microsoft's support site looking around and the OC board was next on my list
![]() It is strange though I have yet to see anything official about rootkit detection in OC yet when you go to the Forefront Client Security page it is all in your face, lol.
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#17
|
|||
|
|||
|
I got an answer from a MVP (actually the same person who replied in that forum post) in the Vista security newsgroup:
Quote:
This time he was a little more clear ![]()
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 |
|
#18
|
|||
|
|||
|
OneCare DOES detect rootkits - when they're not loaded into memory. Microsoft detection pops up moderately often for me when comparing rootkit driver files on VirusTotal. In fact, it'd be a very high claim to say that any major vendor today does not detect rootkits when they're in their inactive form.
The more valid question would be whether OneCare includes any mechanism for detecting the rootkits after they've loaded themselves into memory and stealthed themselves from the OS. |
|
#19
|
||||
|
||||
|
While it was with the 1x version of the product, Consumer Reports listed OneCare as *not* detecting rootkits. That's a scary thought.
__________________
Vista 64 Running Windows Firewall, Windows Defender, and Eset NOD32 v3; Firewall Router w/ NAT and SPI |
|
#20
|
||||
|
||||
|
Ugh, not too sure I'm real happy with the response, considering I have a machine running OneCare...
Quote:
__________________
Vista 64 Running Windows Firewall, Windows Defender, and Eset NOD32 v3; Firewall Router w/ NAT and SPI |
|
#21
|
||||
|
||||
|
sounds interesting I was looking at blacklight ( F-Secure's technology) are you saying it does essentially the same thing & is not new technology?
__________________
Larry |
|
#22
|
||||
|
||||
|
Quote:
|
|
#23
|
||||
|
||||
|
i find onecares reply quite confusing, to say they cant protect against rootkits and basically nobody can is just stupid.
i feel extremely confident that my drweb can easily detect and clean a rootkit, without microsoft spreading this rubbish to its customers. note: Drweb was the ONLY antivirus to successfully clean the rootkit in the removal test at anti-malware.ru (which is really quite alarming) , the new drweb shield technology was specifically created for rootkit detections, and it works a treat! Quote:
well well..... |
|
#24
|
|||
|
|||
|
I find that hard to swallow as well, Chris. Norton has rootkit detection, F-Secure has it through Blacklight and I am sure more others have it as well.
AVG doesn't have it so I have use a separate scanner. EDIT: At least AVG tells you up front that it doesn't have it unlike MS's "circular" talk, lol.
__________________
[Desktop] Acer Aspire M5620| W7 HP 64 SP1 [Laptop] Dell Inspiron 17r| W7 Pro 64 SP1/Ubuntu 11.10 [HTPC] Foxconn 45CSX ITX Mobo | W7 HP 64 SP1 [Tablet] Toshiba Thrive AT100| Android HC 3.2 Last edited by midway40 : January 3rd, 2008 at 07:36 PM. |
|
#25
|
||||
|
||||
|
Looks like i need to install kis again... Or DR. web. How is the Doctor on vista?
__________________
http://www.vipreantivirus.com/ |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|