[ANN] AVG Anti-Rootkit Beta available

  • Thread starter Vinzenz Feenstra
  • Start date
A

Arne Anka

I alt.comp.anti-virus, sa Vinzenz Feenstra utan att tänka först:
Just want to let you know that the Grisoft AVG Anti-Rootkit Beta is
available now:

And when it's a finished product, will it be free- or payware?

--
Arne Anka

Om femhundra år är det ingen jävel som minns att en yster
anka gick här och viftade med simfötterna och hade ståkuk!

<http://starcruiser.dk/conny>
 
V

Vinzenz Feenstra

Arne said:
I alt.comp.anti-virus, sa Vinzenz Feenstra utan att tänka först:


And when it's a finished product, will it be free- or payware?
Hi,

Currently it is beta, I don't about the plans what will be. I'm just a
small innocent developer :/

I just wanted to notify you about that. :)
 
Q

QuincyN

Hi,

Currently it is beta, I don't about the plans what will be. I'm just a
small innocent developer :/

I just wanted to notify you about that. :)

Thanks for the heads up. Was looking for exactly something like
that and this one checks out nicely. I was happy to find I had
no rootkits.

Quint
 
E

edgewalker

Vinzenz Feenstra said:
Hi,

Currently it is beta, I don't about the plans what will be. I'm just a
small innocent developer :/

I just wanted to notify you about that. :)

From a developer's standpoint, do you think it will detect other anti-rootkit
programs as rootkits, and will those others in turn detect it?
 
V

Vinzenz Feenstra

Hi,
From a developer's standpoint, do you think it will detect other anti-rootkit
programs as rootkits, and will those others in turn detect it?

Hi,

This is a good question :) We know that this has happened in our tests,
but we're improving it and fixing such "false positives". It can be that
others will detect our anti-rootkit software as a rootkit but of course
we cannot ensure that we don't have any further false positive. This is
a reason why we're currently in beta only.

The main problem with developing rootkit revealer is that other
anti-rootkit applications often behave almost like a rootkit. So the
detection is somehow correct.

However, as far as I know this will be a longer beta period. And we have
to rely on the users expiriences to improve the detection and prevent
false positives.
 
E

edgewalker

Vinzenz Feenstra said:
Hi,

This is a good question :) We know that this has happened in our tests,
but we're improving it and fixing such "false positives".

IMO such detections would not be false positives. If it "walks like a duck...",
as they say...

I can see a sort of whitelisting for known legitimate "rootkits" being implemented
and then exploited by malware wishing to appear legitimate to the scanner. A 'sig'
that further identifies the legit "rootkit" as part of the scanner's verification process.
It can be that
others will detect our anti-rootkit software as a rootkit but of course
we cannot ensure that we don't have any further false positive. This is
a reason why we're currently in beta only.

The main problem with developing rootkit revealer is that other
anti-rootkit applications often behave almost like a rootkit. So the
detection is somehow correct.

In this view, what behavior is "rootkit-like" or not?
However, as far as I know this will be a longer beta period. And we have
to rely on the users expiriences to improve the detection and prevent
false positives.

Good luck with the project - the marketplace is ripe for the picking. :)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top