Are you recommending these for the average user? I personally wouldn't as they do require some research on the results to decide whether it is a genuine rootkit, a false positive or a result that is expected.e.g.- I run the RKR 1.71 on my XP machines and always came up with an entry because it scans the HKLM\\Security security hive and gives
HKLM\\Security\\Policy\\Secrets\\SAC* HKLM\\Security\\Policy\\Secrets\\SAI* with trailing nulls. It took a while to find out that this was expected behaviour and is listed on the Sysinternals forums. I have also had inconsistent results using it on Vista SP1
The other 2 programs do not work on Vista.