i have been using chkrootkit in my debian and ubuntu install,its a small utility which scans ur "/" root directory for rootkits known
afaik.it finishes scan in below 10 seconds.although it doesn't found any rkits in my instlns

.it will needs to update its database with time.
BTW rkhunter is cool one too.
firestarter is a GUI for iptables.under the hood is iptables only.if ur security phreak,u can go on and install shorewall..
afaik iptables don't have anything to protect rootkits..
there is no problem in downloading dependencies from reliable sites or its mirrors.u can verify those packages by checking GPG keys given.