There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
blue screen blue screen of death boot computer connection cpu crash css dell display driver drivers email error ethernet excel firefox firefox 3 game hard drive hardware internet internet explorer itunes laptop malware monitor network networking nvidia outlook outlook 2003 outlook express partition printer problem problems router security slow software sound trojan usb video virus vista windows windows xp wireless
Tech Tips & Tricks
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > General Technology > Tech Tips & Tricks >
Tip: Learn about Rootkits


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
lotuseclat79's Avatar
Distinguished Member with 10,577 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
23-May-2006, 01:24 PM #1
Tip: Learn about Rootkits
Here, and here.

See the video here by clicking on Rootkits in the middle of the webpage, and read the transcript here.

-- Tom
aarhus2004's Avatar
Computer Specs
Distinguished Member with 2,261 posts.
 
Join Date: Jan 2004
Location: Western Canada
Experience: Windows Millennium only
23-May-2006, 03:21 PM #2
Hello Tom,

I was curious about this latest thread of yours and followed the links you gave. It may well be the future of real concerns about internet security - Rootkits that is.

I am presently running the evaluation copy of F-Secure Internet Security (the one for use on WinME etc). and will post on my thread here in T,T and T as to how I find the software. At this time I am uncertain as to whether the version I have has the capacity to detect rootkits or whether the latest version (for the newer systems only) is the one which takes these type of threats into account.

Your threads are very worthwhile (even if dealing with complex matters).

Cheers.

Ben.

Edit. It purports to have the capacity for rootkit detection.

Last edited by aarhus2004 : 23-May-2006 03:48 PM.
lotuseclat79's Avatar
Distinguished Member with 10,577 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
23-May-2006, 03:45 PM #3
Hi aarhus2004,

Yes, the projections for rootkits are that by 2008 roughly 80+% of infections will occur by way of rootkits.

F-Secure is but one tool, and we should all use several. I also use RootkitRevealer from Sysinternals.com and Rootkit Hook Analyzer from Resplendence.com.

Here is the latest English version (not the help file) of IceSword recently made available:
IceSwordv1.18en: http://rapidshare.de/files/21011497/...1.18en.7z.html

Its touted for advanced users, and can detect and remove Hacker Defender rootkit - but the author of Hacker Defender, Holy Father - now is in the game for more than fun, i.e. profit, and he and the author of IcsSword are both trying to outwit the other.

Process Guard (paid) is probably the tool of choice to defend against kernel rootkits - I'm running the free version now, but plan to switch over sometime in the future when I can migrate my firewall (to Jetico) after my AV license is up, and I decide on NOD32 or Kaspersky AV, and I finally get a DSL line and install a hardware firewalled router with NAT and SPI.

Also, SocketShield looks like a winner - now in Beta test with version 0.96 - its already stopped serveral attacks from meta file and iframers launcher scripts exploits.

I also run Firefox 1.5.0.3 with the NoScript extension although Java and JavaScript are turned on - this blocks the JavaScripts from running by default, and I have to allow them on a temporary basis - I even block the Google syndication and google-analytics from TSG and use the CustomizeGoogle extension with Privacy checking to block Google from gathering a file on my Internet use. Also, running SpoofStick extension to Firefox.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
aarhus2004's Avatar
Computer Specs
Distinguished Member with 2,261 posts.
 
Join Date: Jan 2004
Location: Western Canada
Experience: Windows Millennium only
23-May-2006, 03:55 PM #4
On checking ProcessGuard I find it is available only for 2000, XP, 2003.

Ben. (WinME User).
zoned2000's Avatar
Junior Member with 8 posts.
 
Join Date: Jun 2005
31-May-2006, 10:04 PM #5
Hi,
I have found there are many different programs that find many different things.

The is a big list of antirootkit software at http://www.antirootkit.com

There are also many articles on rootkits especially for beginners.

Rootkits will indeed be a big thing in the coming years, especially with talk of BIOS rootkits and virtual machine rootkits that load first when your PC is turned on, it then loads your normal operating system and then has complete control....
the mind boggles

regards
Zoned2K
Kenny94's Avatar
Senior Member with 811 posts.
 
Join Date: Dec 2004
Location: South Carolina
03-Jun-2006, 10:44 AM #6
Tom I enjoyed the video on Rootkits. The editor did a nice job explaining this in laymen's terms... I love the part where he said "Jedi mind trick"...
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 03:41 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.