|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
Survey |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5253
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5253
|
Posted: Tue Jun 03, 2008 3:02 am Post subject: |
|
|
When it comes to rootkits and Vista, it is wise to leave UAC turned on.
As most of you know the default in Vista is to run as a standard user. Standard user = NO Admin Privileges.
Why is this important when considering rootkits?? Because kernel mode rootkits need Admin privileges to install. UAC enables a standard user to elevate to Admin mode when necessary to perform functions that they would otherwise not be able to perform. UAC is turned on by default in Vista!
The following article describes a study in which thirty rootkits were thrown at both XP and Vista platforms to assess the effectiveness of standalone anti-rootkit tools and antivirus suites at detecting and removing rootkits . One offshoot of this study is that it revealed just how effective Vista is at preventing rootkit installation when UAC is turned ON.
http://www.pcworld.com/businesscenter/article/146256/vistas_despised_uac_nails_rootkits_tests_find.html
Here are some more excerpts from this study:
Of 30 rootkits thrown at XP anti-malware scanners, none of the seven AV suites found all 30, a similar story to the six web-based scanners assessed. Only four of the 14 specialized anti-rootkit tools managed a perfect score:
AVG Anti-Rootkit Free, GMER, Rootkit Unhooker LE, and Trend Micro Rootkit Buster
The results for Vista products were harder to assess because only six rootkits could run on the OS, but the testers had to turn off UAC to get even this far. Vista's UAC itself spotted everything thrown in front of it.
Only three of the 17 AV tools for Vista managed to both detect and successfully remove them, F-Secure Anti-Virus 2008, Panda Security Antivirus 2008, and Norton Antivirus 2008.
The best of the all-purpose suites was Avira AntiVir Premium Security Suite, which found 29 active rootkits, with Norton finding as few as 18. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
PCBruiser
SRT Team Lead
 Forums Admin
 Joined: May 11, 2005 Posts: 11723
|
Posted: Tue Jun 03, 2008 2:45 pm Post subject: |
|
|
Note: AVG Anti-Rootkit Free is no longer available as a free standing program. It has, unfortunately, been integrated into AVG 8. _________________ Don't read? Can't learn!
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|