App Review Shadow Defender 1.2.0.370 vs 5 MBR/VBR Rootkits(testzabezpieczenpc)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Moose

Level 22
Jun 14, 2011
2,271
And what are some good Bookits Removal Tools? Also,your opinions on Malwarebytes Anti-Rootkits? And which Rookits/Bookits Removal Tools do you have in your Tool Box?
 

Moose

Level 22
Jun 14, 2011
2,271
I am asking 3 part questions really!

1st. And what are some good Bookits Removal Tools?

For example, Bitdefender as a Bookits Removal Tool.
1st A. Are there any better at removal and fitting/repairing damage done by a Bookits?

2nd. Malwarebytes Anti-Rootkits is in Beta! Could Kaspersky TDSS Killer be a better
choice, or ESET SysInspector, aswMBR.exe,Gmer, ect...?

2nd B. Are there any better at removal and fitting/repairing damage done by a Rookits?

So.If I get infected with a Bookits &/or a Rootkits, I would like to know a good tool for removing
the infection as soon as possible. So,less damage would be done to computer/laptop. Again,what
removal tools do you carry in your tools box meaning CD/UBS Stick? Thank for asking and hopefully this will give a better understanding of my 3 part questions.
 
R

rocky

I have been using Shadow Defender with DefenseWall because of the kids. It seems the perfect duo. If the 8 and 6 year old get into something playing games DefenseWall stops installs and Shadow Defender removes the odds and ends. And if the 2 year old twins get to the computer and change settings or delete pictures a restart saves a disaster. But I like to check with you guys here because I don't have the expertise exhibited here on a daily basis.I may tend to repeat questions because we use our computer for banking and shopping because of our distance from town. This is my lifeline for keeping up with security. Thanks
 

bitbizket

Level 3
Jul 26, 2011
250
Umbra Corp. said:
I heard of it, nothing is 100% bullet-proof but some apps like SD almost reach it.

SD was "abandonned" for around 2 years now the development restarted so we should give it some time to improve its protection against the latest sophisticated rootkit.

SD isn't 100% foolproof but still a very good light virtualization program.

Sometimes back when i feels like having SD on my machine i would usually throw in MBRGuard or AppGuard (and of course Sandboxie) to my arsenal.
If i wants to go AV-less i relies on a HIPS protection - Malware Defender is my choice, MD is a great classical HIPS programs (provided the user knows what to configure and can handles that dreadful popups for the first time) it incoparates some handy yet powerful features (if you often messing with malware) to look for and terminate infection manually.

I have great fun using this program, it has a custom color coded function showing hidden processes and threads, suspicious hooks and auto start entries, it can monitor network ports and resolve domain names and much more. Simply says its a classical HIPS plus a swiss army knife like features, its very light, does not hook kernel so its very stable and MD is almost bug free. Too bad its not 64-bit or Win 8 supported.

Back on topic..
As an experiment i did some times back, by using an application debugger i can easily bypass SD password validation. So i wouldn't be suprised if SD is'nt temper proof.

Also if you remember Umbra, according to Dax123 - SD does not provide MBR-level protection.

On a side note this video test shows the weak side of SD, not bad really as its rare to see this kind of infection in real-life scenerio, so folks don't jump up and cry wolf just because it fails a particular test.

Thanks for the video JoeN much apprciated, i wonder how DiskShot fairs against those rootkits, would be interesting...

PS: Umbra what's up with DS! tot you goes Korean?

Thanks :)
 

coranti malware

New Member
Verified
Feb 3, 2013
22
Hi Moose MBRBackup if you use it you will never need to remove a rootkit with anything else

I would use these tools to detect some rootkits ,
Malwarebytes Anti-Rootkits Kaspersky TDSS Killer ESET SysInspector, aswMBR.exe,Gmer,
 
D

Deleted member 178

bitbizket said:
PS: Umbra what's up with DS! tot you goes Korean?

DAX seems to have disappeared from the scene so without his infos and help, it is not easy to follow Diskshot development. Also, RX v9 works now on win8 x64 so i rather trust RX + SD over Diskshot.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Even today's generation, they are also aware on bypassing even virtualization using complicated codes so like this could really a bit time consuming on cleaning tools.

So Shadow Defender is still on the bucket list but you must think also having common sense when dealing a malicious programs.
 

dax123

New Member
May 11, 2013
2
Umbra Polaris said:
bitbizket said:
PS: Umbra what's up with DS! tot you goes Korean?

DAX seems to have disappeared from the scene so without his infos and help, it is not easy to follow Diskshot development. Also, RX v9 works now on win8 x64 so i rather trust RX + SD over Diskshot.

Sorry, I was busy nowadays :(

Anyway, Shadow Defender and Diskshot is still effective to protect the system.
for more information, please see http://malwaretips.com/Thread-Diskshot-Home-3-7-970-vs-5-MBR-VBR-Rootkits?pid=120007#pid120007
And For translation issues, it will definately be multilingual once the software is prepared for international purpose.. the developer team is just hesitating..
 
D

Deleted member 178

Thanks Kevins , but i stop using RX since the last time, after a powercut, it kills my MBR and forced me to delete all my partitions (datas included) so now , im just using Windows Backup and AX64 Time machine (no MBR messes possible)
 
I

illumination

Would the MBR-level protection not be a concern with the new UEFi boot protection of windows 8, and if so, would this make SD pretty much a solid choice of light virtualization? I personally do not use Shadow Defender without other security, but still find it a viable approach to a tight system.
 

Moose

Level 22
Jun 14, 2011
2,271
Umbra Polaris, Thank you! For the additional insight to the regular development. Are there any con's about SD accept, it not a 100%?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top