Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > RootkitRevealer Usage
  New Posts New Posts RSS Feed: ** RootKit Detection + Prevention ! **
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

** RootKit Detection + Prevention ! **

 Post Reply Post Reply Page  <1 1112131415 41>
Author
Message
  Topic Search Topic Search  Topic Options Topic Options
Poorguy View Drop Down
Senior Member
Senior Member
Avatar

Joined: 17 July 2006
Location: Argentina
Online Status: Offline
Posts: 419
  Quote Poorguy Quote  Post ReplyReply Direct Link To This Post Topic: ** RootKit Detection + Prevention ! **
    Posted: 13 October 2006 at 6:10pm
Yeah i saw the PM, but nothing useful (don't get angry).
Luis Fernando De La Fuente
Back to Top
<DNY> View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 June 2006
Location: Germany
Online Status: Offline
Posts: 402
  Quote <DNY> Quote  Post ReplyReply Direct Link To This Post Posted: 14 October 2006 at 9:22am
Originally posted by Poorguy

Hi, SpannerITWks, there is a tool that doesn't crash win 2003? because the kernel is too sensitive, i mean, the trouble is in the Ring 0 layer when the O.S is loading the device driver (i.e. rootkit driver), and then crashes (try this, and if you have installed this kind of tools succesfully on Win 2003 or Vista, post it, im only have success with the sysinternals tools), man, this sucks, in win 2000 sp4 this thing doesn't happen, the kernel is insensitive, well i don't have time to check this things (but i tell you my experiences) , bye.



rootkit unhooker doesnt crush win2003, darkspy almost working under win2003
but i dont know about vista :(
< DNY >
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
  Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 15 October 2006 at 6:53pm

Poorguy

Jeepers, no i'm Not angry or anything, no worries !

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
  Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 15 October 2006 at 6:54pm

UPDATE

Rootkit Unhooker Beta 2 online now.

Beta 2 contains random naming of the main executable, and some minor fixes/internal improvements.

NTFS support still not added as yet, but hopefully will be soon.

Free from - http://rku.xell.ru/?l=e&a=main

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
  Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 17 October 2006 at 5:18pm

UPDATE

IceSword 1.20

Yes it's been a while, but it's out now ! Unfortunately it hasn't been translated, so is still in it's native Chinese. Some people were able to work with the first versions released in Chinese, so they may have the edge with this one.

-

Quote -

" FileReg plugin to use their own file system rather than the system ntfs.sys/fastfat.sys. "

-

There has been a very quick reworking to fix a few things. " IceSword amendment to the Chinese version of v061,016 1.20 "

Use at your own risk !

Free DL from the author ( PJF ) - http://www.blogcn.com/user17/pjf/index.html

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
Poorguy View Drop Down
Senior Member
Senior Member
Avatar

Joined: 17 July 2006
Location: Argentina
Online Status: Offline
Posts: 419
  Quote Poorguy Quote  Post ReplyReply Direct Link To This Post Posted: 17 October 2006 at 6:16pm

Originally posted by <DNY>

Originally posted by Poorguy

Hi, SpannerITWks, there is a tool that doesn't crash win 2003? because the kernel is too sensitive, i mean, the trouble is in the Ring 0 layer when the O.S is loading the device driver (i.e. rootkit driver), and then crashes (try this, and if you have installed this kind of tools succesfully on Win 2003 or Vista, post it, im only have success with the sysinternals tools), man, this sucks, in win 2000 sp4 this thing doesn't happen, the kernel is insensitive, well i don't have time to check this things (but i tell you my experiences) , bye.



rootkit unhooker doesnt crush win2003, darkspy almost working under win2003
but i dont know about vista :(

LOL, i think that your experience with win 2003 is limited, check a rootkit app (or app with rootkit driver) and try to use it on win 2003 and you'll see what i'm talking about (plus with SP1), if you don't tried this on Vista, don't tell me.

Luis Fernando De La Fuente
Back to Top
EP_X0FF View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 4753
  Quote EP_X0FF Quote  Post ReplyReply Direct Link To This Post Posted: 18 October 2006 at 8:57am
Poorguy. We are talking not about rootkits here, about antirootkit programs. Improve your reading skills.
Ring0 - the source of inspiration
Back to Top
Poorguy View Drop Down
Senior Member
Senior Member
Avatar

Joined: 17 July 2006
Location: Argentina
Online Status: Offline
Posts: 419
  Quote Poorguy Quote  Post ReplyReply Direct Link To This Post Posted: 18 October 2006 at 4:26pm

Originally posted by EP_X0FF

Poorguy. We are talking not about rootkits here, about antirootkit programs. Improve your reading skills.

Well, "Antirootkits" apps, use rootkit kernel based drivers technology to "search" rootkits in the Ring 0 layer, (see RootkitRevealer or your apps EP_X0FF !!!).



Edited by Poorguy - 18 October 2006 at 6:39pm
Luis Fernando De La Fuente
Back to Top
EP_X0FF View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 4753
  Quote EP_X0FF Quote  Post ReplyReply Direct Link To This Post Posted: 18 October 2006 at 8:04pm
I see no reasons why my program should not work under Windows 2003. I think, I know about windows 2003 kernel more than you, Poorguy.
Ring0 - the source of inspiration
Back to Top
Poorguy View Drop Down
Senior Member
Senior Member
Avatar

Joined: 17 July 2006
Location: Argentina
Online Status: Offline
Posts: 419
  Quote Poorguy Quote  Post ReplyReply Direct Link To This Post Posted: 19 October 2006 at 3:28pm

Originally posted by EP_X0FF

I see no reasons why my program should not work under Windows 2003. I think, I know about windows 2003 kernel more than you, Poorguy.

Really?, you have tried the Windows 2003 server (and with SP1?)?, you really know the Win 2003 kernel?, well you don't know me and if you're saying that you know more (the Win 2003 kernel) then me, well, teach me then!.



Edited by Poorguy - 19 October 2006 at 3:32pm
Luis Fernando De La Fuente
Back to Top
 Post Reply Post Reply Page  <1 1112131415 41>

Forum Jump Forum Permissions View Drop Down

Privacy Statement