2008-03-25, 11:53
i have downloaded the update from spybot but can not find an option in the sbybot interface to run this tool?

Am i being a complete idiot? do i need to download something additionally?


md usa spybot fan
2008-03-25, 14:31

Spybot-S&D now has some rootkit scans built in to its "Check for problems". However, the tool referred to in the this forum (RootAlyzer (http://forums.spybot.info/forumdisplay.php?f=46)) is a separate tool and can be downloaded from the link in the first post (http://forums.spybot.info/showpost.php?p=163800&postcount=1) in this thread:
2008-03-25, 19:58
Hi guys.
I think RootAlyzer is a great tool - I myself have only just heard about Rootkits and how dangerous they are.

But to quote PepiMK from the thread mentioned above:

Spybot-S&D usually detects threats in our database only; RootAlyzer just shows any things it identified as hidden, without relating them to known malware. So you could use RootAlyzer to detect even rootkits that are not known yet; but one of the new plugins for Spybot-S&D includes kind of a rootkit heuristics (which is not as generic though).

In summary: use RootAlyzer if Spybot-S&D hasn't found the culprit and you're suspecting an unlisted malware.

2008-03-26, 13:33
cheers for the quick response, i have downloaded the seperate file as well now.

2008-04-22, 22:57
Wondering if we will ever be able to save the list that is created in the 'DeepScan' part of 'RootAlyzer'? When first run and several since even in the 'DeepScan' nothing was found, now the list is eleven and a ~quarter pages long. Nothing is found in the 'QuickScan' portion.

2008-04-23, 10:21
When the scan is finished, a "Logs" page will appear. Granted, I maybe should add another, more "plain text" log type, but at least it helps store the results, though you would have to wait for the next release to see the detail column filled in there as well. That one will need only a bit more testing of the ACL detection stuff, I'll probably prepare a bunch of smaller updates for various apps later this week (see our bugtracker section). Meanwhile, just being curious, what exactly is the type of these many entries (Details column)?

(edit: see this link (http://forums.spybot.info/project.php?projectid=11) for the bugtracker for RootAlyzer, including the latest changes)

2008-04-25, 04:28

Thank you for this reply and acknowledgment of my small request. Where would I find these logs, now this is not the logs that are done by SBS&D this is for RootAlyzr that I have made this reference. Or do we not have access to this info until you do the next major update, my system is acting a little strange, at least different than a few days ago. I think it was Sunday last that my system required me to re-login to my ISP which has never occurred before just after my login earlier that day. I am usually kept loggedin for two weeks by a cookie this time it was required again. The color of the boarders has changed and it has reverted to the Win98SE style instead of the WinXP version. The software is still XP SP2, plus they are coming out with the SP3 on 4/29/2008 and maybe I should not update to that until I have found out what has caused all of these changes. I did NOT make the change in color nor the style.

2008-10-28, 01:58

As you can see from my sig the situation at my location has changed a bit, like a difference from night to day. Plus have not used any of your other software on this system, yet, my plans are to do some of that later on. Still working with training wheels on this Vista Home Premium. The security is so different and not allowed access to some areas with some software being reinstalled, after I have disabled it, when doing a reboot. Attempting to have Dell assist me with some of this problem, their servers are down for maintenance. Maybe tomorrow . . .

2008-10-28, 13:16
Meanwhile I guess that "next release" is there ;)
You can see the logs on the screenshots of the http://forums.spybot.info/downloads.php?id=8download page (http://forums.spybot.info/downloads.php?id=8).

2008-10-29, 00:22

Thank you for this information, one question? Maybe two seems that was one, will this be compatible with Vista SP1? My previous system was Windows XP SP2.