Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > Returnil releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 5th, 2010, 07:19 AM
usagi usagi is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 2
Default Returnil vs Rootkits?

Does Returnil protects my computer completely against rootkits?

Can some types of rootkits bypass Returnil (such as those which have their own driver to have direct disk access or hypervisor rootkits such as the old blue pill)?

I'm planning to turn on my computer 24/7, connected to the internet, with Returnil activated. Will it be safe? I'm afraid I'll get some infections if some malware are able to bypass Returnil.

Thanks in advance
  #2  
Old April 5th, 2010, 07:31 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Returnil vs Rootkits?

You are very safe and no need to be afraid. If you are asking can you be 100% safe then the answer can't be 100% accurate
More general info
http://www.wilderssecurity.com/showthread.php?t=255228
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old April 5th, 2010, 08:20 PM
usagi usagi is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 2
Default Re: Returnil vs Rootkits?

Thanks for your response

How about those rootkits which come with their own direct disk access drivers?
Or hypervisor rootkits which will attempt to put Windows under their virtual environment?
Can Returnil protect my computer from those rootkits?
  #4  
Old April 6th, 2010, 10:46 PM
ace55 ace55 is offline
Regular Poster
 
Join Date: Mar 2010
Posts: 91
Default Re: Returnil vs Rootkits?

Although I cannot answer your question, there will always be theoretical vulnerabilities, even in security software. Thus, I would advise not relying on Returnil alone. Using it in combination with a HIPS would provide stronger protection. Even programmers of security software are human, thus their code is still susceptible to vulnerabilities, like any other software. For the same reason, Returnil will provide additional protection for any other security software on your machine.

But I look forward to Coldmoon's answer, particularly regarding blue pill.
  #5  
Old April 7th, 2010, 01:59 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,744
Default Re: Returnil vs Rootkits?

RVS includes protection for the MBR and low sector editing which is effective against the majority of malware out there. There are a small number of families that can get around virtualization and is one of the most important reasons we added antimalware/antiexecute/behavior analysis functionality in 2010. Also, there is no software solution that will ever be able to protect against exploitation when the attacker has physical access to the target computer...

You can be confident in RVS's protection ability as well as the improvements it introduces over traditional approaches/solutions. As there is no way to predict what the malware devs are going to come up with next, you should still practice good computing as the most important link in your security is you and what you do...

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #6  
Old September 30th, 2010, 07:44 AM
regeu regeu is offline
Infrequent Poster
 
Join Date: Oct 2009
Location: Mumbai, India
Posts: 15
Default Re: Returnil vs Rootkits?

Possibly a combination of firewall, antivirus and Returnil may help.
  #7  
Old September 30th, 2010, 12:51 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,744
Default Re: Returnil vs Rootkits?

Quote:
Originally Posted by regeu
Possibly a combination of firewall, antivirus and Returnil may help.

Perhaps, but the keys with RKs are:

1. Avoid them (best idea if possible)
2. Don't let the infecter activate. In this scenario you work to ensure that the RK installer never gets a chance to work and is a partial reason for the Anti-execute functionality in RVS/RSS.

For the scenario where a RK already exists, we are working to upgrade the Virus Guard with support for detection and removal. It is still a work in progress, but progressing well.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
 

Wilders Security Forums > Official Returnil Support Forum > Returnil releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:21 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums