![]() |
Another antirootkit tool: CodeWalker |
Post Reply
|
Page 12> |
| Author | |
thug4lif3
Groupie
Joined: 05 August 2008 Location: Vietnam Online Status: Offline Posts: 40 |
Quote Reply
Topic: Another antirootkit tool: CodeWalkerPosted: 18 November 2008 at 8:58am |
|
Hi all,
I've developed an antirootkit tool called CodeWalker which can: + Detect hidden processes + Detect hidden drivers + Detect hidden files (support NTFS only) + Detect hooks in both kernel mode and usermode. + Works on Windows English 2000/XP/2003/Vista/2008. The tool is currently in beta stage and im looking for people for testing it. I've already tested it with all rootkits samples I have and its detection rate seems optimistic. I think it's very great if you guys test it against your rootkit zoo and provide the result you got with the tool. If there's BSOD (of cos, you can never write a bug free proggie, rite? :P), it would be very appreciated of you to upload minidumps to help me correct the tool. Thanks in advance. I will update this tool frequently for new detection methods, bug fixs etc. Welcome for your all suggestions, bugs and minidumps :P Here's the link: http://cmcinfosec.com/download/cmcark.zip EDIT: Mispells Edited by thug4lif3 - 18 November 2008 at 11:30am |
|
|
stay hungry, stay foolish.
CodeWalker AntiRootkit: http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar |
|
![]() |
|
Meriadoc
Senior Member
Joined: 22 August 2006 Online Status: Offline Posts: 109 |
Quote Reply
Posted: 18 November 2008 at 10:00am |
|
Hi thug4lif3
I will give you as much feedback and as I can.
|
|
![]() |
|
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 465 |
Quote Reply
Posted: 18 November 2008 at 10:08am |
|
IŽll check it and give you my feedback too.
|
|
|
When a true genius appears, you can know him by this sign: that all the dunces are in a confederacy against him.
|
|
![]() |
|
thug4lif3
Groupie
Joined: 05 August 2008 Location: Vietnam Online Status: Offline Posts: 40 |
Quote Reply
Posted: 18 November 2008 at 10:24am |
|
@Meriadoc & SystemPro: Thanks :D
|
|
|
stay hungry, stay foolish.
CodeWalker AntiRootkit: http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar |
|
![]() |
|
thug4lif3
Groupie
Joined: 05 August 2008 Location: Vietnam Online Status: Offline Posts: 40 |
Quote Reply
Posted: 20 November 2008 at 8:52am |
|
Up.
Im waiting for feedback :) +FIX: - fix bug in initializing & acquiring ERESOURCE Edited by thug4lif3 - 20 November 2008 at 8:55am |
|
|
stay hungry, stay foolish.
CodeWalker AntiRootkit: http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar |
|
![]() |
|
GamingMasteR
Senior Member
Joined: 10 August 2008 Online Status: Offline Posts: 171 |
Quote Reply
Posted: 20 November 2008 at 4:42pm |
|
many false results in kernel code hooks.
|
|
![]() |
|
redhawk
Moderator Group
Joined: 14 September 2005 Location: United Kingdom Online Status: Offline Posts: 1048 |
Quote Reply
Posted: 20 November 2008 at 8:29pm |
|
Scanning memory then locks up Windows 100% after a few seconds only the mouse moves.
Tested on XP Pro SP2, with no SSDT hooks, AV or firewall software installed. Richard S. |
|
![]() |
|
controler
Senior Member
Joined: 01 October 2006 Online Status: Offline Posts: 222 |
Quote Reply
Posted: 20 November 2008 at 11:40pm |
|
Virus Total flagging it Rootkit tool
No BSODs at least Edited by controler - 20 November 2008 at 11:41pm |
|
![]() |
|
thug4lif3
Groupie
Joined: 05 August 2008 Location: Vietnam Online Status: Offline Posts: 40 |
Quote Reply
Posted: 21 November 2008 at 2:45am |
|
@GamingMasteR &
In next build I will try to limit the false-positive kernel code modification to lower rate. Thanks ;) @redhawk: I'll fix these bugs soon. May be it's becos of GUI bugs. @controler: Yes, virustotal always flag "rootkit tool" for programs which drop and load driver. Anyway, it's an anti-"rootkit tool", rite :D? I will upload the new build asap. Thank you. Edited by thug4lif3 - 21 November 2008 at 2:49am |
|
|
stay hungry, stay foolish.
CodeWalker AntiRootkit: http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar |
|
![]() |
|
fl3a
Groupie
Joined: 12 October 2006 Online Status: Offline Posts: 81 |
Quote Reply
Posted: 25 November 2008 at 5:04pm |
|
Hi thug4lif3,
I've tested CodeWalker with BadRkDemo, Unreal.A, phite_ex, it works fine. Did you implemented sth new like detection of threads/processes hidden by means of own scheduler? Could you tell us which part of detection are improved?
@Metraton did you tested it with your PoC rootkit?
|
|
![]() |
|
Post Reply
|
Page 12> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |