Study: Symantec Best at Removing Rootkits; Microsoft Worst

Study: Symantec Best at Removing Rootkits; Microsoft Worst

Written By
Ryan Naraine
Ryan Naraine
Nov 3, 2006
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Among existing desktop security software, Symantecs Norton AntiVirus 2007 suite is the best at detecting and removing stealth rootkits, according to a study done by Thompson Cyber Security Labs.

In the study, which was commissioned by Symantec and conducted by veteran anti-virus expert Roger Thompson, 20 randomly chosen pieces of rootkit-laden malware files were pitted against the major anti-virus and anti-spyware vendors to rate detection and removal capabilities.

In both categories, Symantecs Norton came out tops, although the tool did not fully remove all 20 rootkits.

The application that performed the poorest, according to Thompson, was Microsofts Microsoft Windows Defender (Beta 2), which is being built into the Windows Vista operating system.

In the detection category, Thompson tested the softwares ability to find the presence of a rootkit after it is installed on a computer. If a particular rootkit is not detected, it could be due to either engine limitations or missing detections for a particular version of the rootkit, according to the report released by Symantec on Nov. 3, here in PFD form.

The software suites were rated separately on remediation capabilities, which tested the ability of the product to remove the components so that the rootkit is no longer left running on the system, as well as the ability of the product to completely remove the side effects of a rootkit, including registry keys.

In the detection category, Symantec Norton scored the highest, followed by McAfee Internet Security 2006, Webroot SpySweeper, F-Secure Internet Security Suite 2006 and Sunbelt CounterSpy.

Microsofts Windows Defender only detected five of the 20 rootkits.

In the clean-up category, Symantec also scored the highest, well ahead of Webroot, F-Secure, McAfee, Sunbelt and Microsoft.

However, affording to Thompsons findings, most of the security tools did not fully remove more than half of the rootkits. Sunbelt, Microsoft and Trend Micro deleted only five of the 20 rootkits.

Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.