Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Malware
  New Posts New Posts RSS Feed: Another antirootkit tool: CodeWalker
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Another antirootkit tool: CodeWalker

 Post Reply Post Reply Page  12>
Author
Message
  Topic Search Topic Search  Topic Options Topic Options
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Online Status: Offline
Posts: 40
  Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Topic: Another antirootkit tool: CodeWalker
    Posted: 18 November 2008 at 8:58am
Hi all,

I've developed an antirootkit tool called CodeWalker which can:

+ Detect hidden processes
+ Detect hidden drivers
+ Detect hidden files (support NTFS only)
+ Detect hooks in both kernel mode and usermode.
+ Works on Windows English 2000/XP/2003/Vista/2008.

The tool is currently in beta stage and im looking for people for testing it. I've already tested it with all rootkits samples I have and its detection rate seems optimistic. I think it's very great if you guys test it against your rootkit zoo and provide the result you got with the tool. If there's BSOD (of cos, you can never write a bug free proggie, rite? :P), it would be very appreciated of you to upload minidumps to help me correct the tool. Thanks in advance.

I will update this tool frequently for new detection methods, bug fixs etc. Welcome for your all suggestions, bugs and minidumps :P

Here's the link:

http://cmcinfosec.com/download/cmcark.zip

EDIT: Mispells

Edited by thug4lif3 - 18 November 2008 at 11:30am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
Meriadoc View Drop Down
Senior Member
Senior Member
Avatar

Joined: 22 August 2006
Online Status: Offline
Posts: 109
  Quote Meriadoc Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:00am
Hi thug4lif3Smile I will give you as much feedback and as I can.
Back to Top
SystemPro View Drop Down
Senior Member
Senior Member
Avatar

Joined: 26 April 2007
Location: Germany
Online Status: Offline
Posts: 465
  Quote SystemPro Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:08am
IŽll check it and give you my feedback too.
When a true genius appears, you can know him by this sign: that all the dunces are in a confederacy against him.
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Online Status: Offline
Posts: 40
  Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:24am
@Meriadoc & SystemPro: Thanks :D
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Online Status: Offline
Posts: 40
  Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 8:52am
Up.

Im waiting for feedback :)

+FIX:
- fix bug in initializing & acquiring ERESOURCE


Edited by thug4lif3 - 20 November 2008 at 8:55am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
GamingMasteR View Drop Down
Senior Member
Senior Member
Avatar

Joined: 10 August 2008
Online Status: Offline
Posts: 171
  Quote GamingMasteR Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 4:42pm
many false results in kernel code hooks.
Back to Top
redhawk View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 14 September 2005
Location: United Kingdom
Online Status: Offline
Posts: 1048
  Quote redhawk Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 8:29pm
Scanning memory then locks up Windows 100% after a few seconds only the mouse moves.
Tested on XP Pro SP2, with no SSDT hooks, AV or firewall software installed.

Richard S.
Back to Top
controler View Drop Down
Senior Member
Senior Member


Joined: 01 October 2006
Online Status: Offline
Posts: 222
  Quote controler Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 11:40pm
Virus Total flagging it Rootkit tool

No BSODs at least


Edited by controler - 20 November 2008 at 11:41pm
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Online Status: Offline
Posts: 40
  Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 21 November 2008 at 2:45am
@GamingMasteR &

In next build I will try to limit the false-positive kernel code modification to lower rate. Thanks ;)

@redhawk:

I'll fix these bugs soon. May be it's becos of GUI bugs.

@controler:

Yes, virustotal always flag "rootkit tool" for programs which drop and load driver. Anyway, it's an anti-"rootkit tool", rite :D?

I will upload the new build asap. Thank you.

Edited by thug4lif3 - 21 November 2008 at 2:49am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
fl3a View Drop Down
Groupie
Groupie
Avatar

Joined: 12 October 2006
Online Status: Offline
Posts: 81
  Quote fl3a Quote  Post ReplyReply Direct Link To This Post Posted: 25 November 2008 at 5:04pm
Hi thug4lif3,
 
I've tested CodeWalker with BadRkDemo, Unreal.A, phite_ex, it works fine. Did you implemented sth new like detection of threads/processes hidden by means of own scheduler? Could you tell us which part of detection are improved?
 
@Metraton did you tested it with your PoC rootkit?
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Privacy Statement