eTrust PestPatrol Anti-Spyware 2005 - 1 year for free!

It is possible to detect a rootkit from the same system using a tool such as RootKitRevealer but it is not gauranteed. RootKitRevealer is a very effective program but the RootKit writers have already began to attack RootKitRevealer, which is why Mark keeps releasing newer versions to combat the problem. Just make sure you have the latest version. Otherwise you have to scan the drive from a Bootable CD or another system.

The problem is true RootKits can severly compromise core Windows System files which means cleaning it may make the system unusable.

Protection is the same as with other Malware. RootKits install through the same security holes that other Malware use, so being proactive about patching, using updated AV and a firewall will also protect against RootKits.

If you want a software solution, you need to get a program like ProcessGuard. AntiVirus companies are working on their own solution.

Well this sounds reasonable, still a very unwanted situation.

polonus

Is it safe to assume that an IDS(of which there are several) would be bypassed under present situation?

ProcessGuard is the only program that can effectively block unknown rootkits. However modern AV such as Avast should catch all known RootKits before they install, if it is running and properly updated.

The systems I find infected with Malware consistently have the same problems:

  1. Security Patches were not applied.
  2. AV not installed, disabled, outdated or not properly updated.
  3. MSJVM installed.
  4. No Firewall.

What IDS are you refering to?

A squared have one bundled into their personal program which seems to work well , Kerio pf has one within its program although having used it i never saw it activate, Prev X I believe is much the same and certainly does detect and stop suspicious behaviour.

Their IDS would be similiar to AV.

I guess the real issue is isolation and identification rather than just being able to stop unknown code from executing.

Microsoft Anti-Spyware to remain free? According to this article that you can view HERE possibly not. Check it out.

Not True:

Windows AntiSpyware to Remain Free (BetaNews)

Windows enthusiast sites flew into a tizzy this week following a Windows OneCare beta chat session in which a Microsoft employee inferred that Windows AntiSpyware would be dropped at the conclusion of its beta program. There was only one problem with the news: it wasn't true.

While an enterprise version of Windows AntiSpyware will be offered to businesses for a cost and OneCare is also slated include the technology, Microsoft plans to continue making the software available at no charge for end-users.

“Users who validate their Windows install through WGA will be allowed to download the AntiSpyware beta, as well as the full standalone version of AntiSpyware when it releases to the web. This has not changed since Bill Gates announced this information at the RSA conference in February,” wrote developer Steve Dodson on his Web log.

“For users who want more services including AntiVirus, computer backup, and AntiSpyware we will be offering Windows OneCare live. Windows OneCare Live is currently in beta, but when it releases to the web it will be available to users with a cost,” Dodson added.

Guess we can wait and see who is right in these two articles. At this time and point I tend to believe the post I made. To each their own. Guess it should read “possibly not true”.

::slight_smile:

Steve Dodson work at Microsoft on Microsoft AntiSpyware.

AntiSpyware and OneCare Live

Today when I came in to the office, I was made aware of an issue which stated that a Microsoft Representative was quoted as saying Windows AntiSpyware would no longer be available for free.

The statement quoted in many forums is not true.

As we have been saying since day one, Microsoft Windows AntiSpyware will be available at no charge to licensed users of Windows. Users who validate their Windows install through WGA will be allowed to download the AntiSpyware beta, as well as the full standalone version of AntiSpyware when it releases to the web. This has not changed since Bill Gates announced this information at the RSA conference in February. The enterprise version of Windows AntiSpyware is targeted to companies who want to centrally manage their Windows AntiSpyware infrastructure. The enterprise version of Windows AntiSpyware will be available for a cost (which has not been determined yet). For users who want more services including AntiVirus, computer backup, and AntiSpyware we will be offering Windows OneCare live. Windows OneCare Live is currently in beta, but when it releases to the web it will be available to users with a cost.

There are many exciting security offerings coming from Microsoft over the next year and I am just glad they let me blog about these exciting things happening at Microsoft!

I personally like Neowin but they have gotten into trouble with things like this before.

I guess the question posed somewhere within Neals link that still goes unanswered is will MS antispy always remain in its present form .
And if not then how long before it becomes so heavily integrated into WOC that it ceases to be a stand alone utility and therefore free.

Latest anti-spyware comparative test from a UK computer magazine:

http://www.pcpro.co.uk/labs/133/anti-spyware/introduction.html

CounterSpy gets very good reviews in most of the reviews I have read, it is in effect the parent program of MS anti-spy, or rather the program that MS bought off Giant. As far as I’m aware Sunbelt Software have a license to sell the CounterSpy product for a couple of years.

So MS anti-spy should also do well, although CounterSpy is supposed to have a higher detection rate.

Spyware Warrior Test ← This is a more accurate test where they disclose their results. This was also before Giant became Microsoft AntiSpyware and Adaware started releasing very frequent definitions.

The last link I posted was very clear. It shows that Microsoft is going to release a standalone version for end-users for free.

CounterSpy is a Giant/Microsoft AntiSpyware knockoff which currently relies on Microsoft for definition updates through 2007. While it is true it detects slightly more since Microsoft stripped out cookie detection and Claria GAIN, Adaware and Spybot will remove these.

I don’t consider knockoff products as their own.

Well Sunbelt had a the CounterSpy license before MS bought Giant (otherwise they wouldn’t have been able to continue to distribute/sell it), so hardly a knock off.

Another point, MS crippled the Giant anti spyware product, by limiting it to XP and above to try and get people to upgrade their OS, ‘CounterSpy works with Windows 98SE/Me/2000/XP.’

P.S. I don’t use CounterSpy or MS anti-spy (certainly not until it is out of beta).

Thanks for the Spyware Warrior link, but as you say it is getting a little long in the tooth (Oct. 13-15, 2004), even then Giant was well ahead of the field. Yes reviews without what they tested, how they tested, etc. hold less weight than the likes of this test/review. It would be nice to see them repeat it a year down the track.

While CounterSpy is a legitimate product it is not fully it’s own application, for which I cannot put much faith in it long term.

Microsoft AntiSpyware works with Windows 2000 and XP. Which is all anyone should be running today if they run Windows. Microsoft AntiSpyware while still in BETA is very safe and all the false positives were taken care of in the first few months.

The Spyware Warrior link is one of the only ones I have been able to find that discloses the full test results. Literally every other comparison test has each application on top and in a different order. It also follows very closely with real world results. As Microsoft AntiSpyware consistently detects more then the rest.

While CounterSpy is a legitimate product it is not fully it's own application, for which I cannot put much faith in it long term.
If you are buying a yearly license (reasonably priced $19.95), long term is hardly an issue, if as you said it is ok to 2007?
CounterSpy is just $19.95 per machine, and that includes a one year subscription with updates, upgrades and technical support, (real live humans from right here in the US at 888-688-8457). Best of all, it's the only antispyware that gets regular spyware threat database updates from three sources: Sunbelt's own Spyware Research Team, CounterSpy users like you that are a member of our ThreatNet Community, and from Microsoft's own spyware research group.
So this may account for the better detections.

This certaintly WAS interesting reading:

http://forum.avast.com/index.php?topic=14736.0

If you are buying a yearly license (reasonably priced $19.95), long term is hardly an issue, if as you said it is ok to 2007?
Yes but why pay anything for an application that does not realistically give you any better detection then the free scanners?
http://forum.avast.com/index.php?topic=14736.0
That is very old news. Run Adaware it will find Claria.