PDA

View Full Version : RootKit - General Query



Fred232
2009-06-06, 15:37
I currently run AVG8.5(free) and Spybot S&D. Keeping both updated, and running Spybot full scan about twice a month.

I noticed that AVG8.5 says it does not detect RootKits, and found Avast(free) which claims it does.

This just got me wondering, does Spybot detect all/some/none RootKits :confused:



PS - Thanks for the product and your work.

Matt
2009-06-06, 23:36
Hi Fred232,

RootAlyzer (http://forums.spybot.info/downloads.php?id=8) is a special tool from TeamSpybot to find Rootkits.
Spybot can detect rootkits, like for example the TDSS Rootkit.

If you want to use RootAlzer, download it and follow these instruction:

Unzip it to a folder on your desktop, close all windows, and run RootAlyzer.exe
Click Ok to the two prompts and let the program run it's Quick Scan automatically, this should only take a few seconds
Click the Deep Scan tab, check all the boxes and click Ok. Let the scan run un-interrupted, it will take a few minutes.
When it is finished scanning, a Log tab will appear at the top, click that. Highlight all the text, right-click on it and press Copy.
Paste that information back here by pressing Ctrl + V, or right-click and press Paste. Also mention if you had any problems.
:thanks:

Fred232
2009-06-07, 00:29
OK, thanks for the quick reply.

I've not noticed any problems as such, but after I noticed that AVG(free) did not detect them, was concerned that I may need something to check for them. From what you have said, Spybot will catch some, at least.

As I have no known or noticed problems, and an AVG and Spybot SCAN passes OK (apart from tracking cookies), I guess I'm likely to be clean. Is this a safe assumption?

Anyway, I will have a look at RootAlyzer, thanks for the info.

Matt
2009-06-07, 00:39
As I have no known or noticed problems, and an AVG and Spybot SCAN passes OK (apart from tracking cookies), I guess I'm likely to be clean. Is this a safe assumption?

No tool can detect 100% of the Malware, that is out there... :fear: but I think it's ok. :) Make sure that all your tools and your OS are always up to date.