fu rootkit

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Just a simple Question:
Why doesn't windows defender fail to detect fu rootkit?
it's updated with the latest definition file.
Thanks.
Ken.
 
I just wanted to check whether rootkits are detected by MS Defender or not.
So I downloaded fu rootkit from www.rootkit.com and ran fu.exe with –prl
parameter. Fu installs msdirectx.sys as a kernel-mode driver. The severity
level is marked as moderate. You can see it at
http://www.microsoft.com/security/encyclopedia/details.aspx?name=VirTool:WinNT/FURootkit.A
The odd thing is that the Microsoft tool , Malicious Software Removal Tool ,
detects and removes this rootkit.This is why i asked the question. To me, it
raises another new question: will i need another tool against malware, since
this one doesn't seem very reliable?
Thanks ,
Ken
 
Here's what I think: Yes, you do need multiple tools, and always will.

Even if you wish to just stick with Microsoft tools, Microsoft has three
areas of functionality: Antivirus, Antispyware, and the Malicious Software
Removal tool, which specifically targets rootkits, but also other high
profile malicious software--the targets vary over time as their research
determines.

Microsoft has a consumer product--OneCare, which provides both antivirus and
antispyware coverage.

Microsoft has a corporate product - Microsoft Forefront Client Security,
which also provides both antivirus and antispyware coverage, and is designed
for ease of management across enterprises of any size.

In addition to these, the Malicious Software Removal tool is cumulative--new
items are added monthly--and will continue to be issued monthly.

I wouldn't expect them to duplicate coverage between the categories,
although there's some doubt in my mind about the divisions between
antispyware and antivirus, since much spyware rides on trojans.

In addition, every thoughtful review I've seen in the antispyware area
recommends using multiple products--the definitions are not hard and fast,
there's no formal information sharing mechanism between vendors, and things
change quickly.

Windows Defender has targetted rootkits and rootkit-like software--the Sony
DRM rootkit was one example of this but there have been others.

I can't say for sure why Windows Defender doesn't detect this rootkit, but
if the Malicious Software Removal tool does, I would suspect that not
duplicating the coverage is some part of the reason.

--
 
Back
Top