Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Malware
  New Posts New Posts RSS Feed - Another antirootkit tool: CodeWalker
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Another antirootkit tool: CodeWalker

 Post Reply Post Reply Page  12>
Author
Message
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Status: Offline
Points: 62
Post Options Post Options   Thanks (0) Thanks(0)   Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Topic: Another antirootkit tool: CodeWalker
    Posted: 18 November 2008 at 8:58am
Hi all,

I've developed an antirootkit tool called CodeWalker which can:

+ Detect hidden processes
+ Detect hidden drivers
+ Detect hidden files (support NTFS only)
+ Detect hooks in both kernel mode and usermode.
+ Works on Windows English 2000/XP/2003/Vista/2008.

The tool is currently in beta stage and im looking for people for testing it. I've already tested it with all rootkits samples I have and its detection rate seems optimistic. I think it's very great if you guys test it against your rootkit zoo and provide the result you got with the tool. If there's BSOD (of cos, you can never write a bug free proggie, rite? :P), it would be very appreciated of you to upload minidumps to help me correct the tool. Thanks in advance.

I will update this tool frequently for new detection methods, bug fixs etc. Welcome for your all suggestions, bugs and minidumps :P

Here's the link:

http://cmcinfosec.com/download/cmcark.zip

EDIT: Mispells

Edited by thug4lif3 - 18 November 2008 at 11:30am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
Meriadoc View Drop Down
Senior Member
Senior Member
Avatar

Joined: 22 August 2006
Status: Offline
Points: 240
Post Options Post Options   Thanks (0) Thanks(0)   Quote Meriadoc Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:00am
Hi thug4lif3Smile I will give you as much feedback and as I can.
Back to Top
SystemPro View Drop Down
Senior Member
Senior Member
Avatar

Joined: 26 April 2007
Location: Germany
Status: Offline
Points: 510
Post Options Post Options   Thanks (0) Thanks(0)   Quote SystemPro Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:08am
IŽll check it and give you my feedback too.
Concentrate on your strengths.
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Status: Offline
Points: 62
Post Options Post Options   Thanks (0) Thanks(0)   Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 10:24am
@Meriadoc & SystemPro: Thanks :D
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Status: Offline
Points: 62
Post Options Post Options   Thanks (0) Thanks(0)   Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 8:52am
Up.

Im waiting for feedback :)

+FIX:
- fix bug in initializing & acquiring ERESOURCE


Edited by thug4lif3 - 20 November 2008 at 8:55am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
GamingMasteR View Drop Down
Senior Member
Senior Member
Avatar

Joined: 10 August 2008
Status: Offline
Points: 245
Post Options Post Options   Thanks (0) Thanks(0)   Quote GamingMasteR Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 4:42pm
many false results in kernel code hooks.
Back to Top
redhawk View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 14 September 2005
Location: United Kingdom
Status: Offline
Points: 1333
Post Options Post Options   Thanks (0) Thanks(0)   Quote redhawk Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 8:29pm
Scanning memory then locks up Windows 100% after a few seconds only the mouse moves.
Tested on XP Pro SP2, with no SSDT hooks, AV or firewall software installed.

Richard S.
Back to Top
controler View Drop Down
Senior Member
Senior Member


Joined: 01 October 2006
Status: Offline
Points: 222
Post Options Post Options   Thanks (0) Thanks(0)   Quote controler Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2008 at 11:40pm
Virus Total flagging it Rootkit tool

No BSODs at least


Edited by controler - 20 November 2008 at 11:41pm
Back to Top
thug4lif3 View Drop Down
Groupie
Groupie
Avatar

Joined: 05 August 2008
Location: Vietnam
Status: Offline
Points: 62
Post Options Post Options   Thanks (0) Thanks(0)   Quote thug4lif3 Quote  Post ReplyReply Direct Link To This Post Posted: 21 November 2008 at 2:45am
@GamingMasteR &

In next build I will try to limit the false-positive kernel code modification to lower rate. Thanks ;)

@redhawk:

I'll fix these bugs soon. May be it's becos of GUI bugs.

@controler:

Yes, virustotal always flag "rootkit tool" for programs which drop and load driver. Anyway, it's an anti-"rootkit tool", rite :D?

I will upload the new build asap. Thank you.

Edited by thug4lif3 - 21 November 2008 at 2:49am
stay hungry, stay foolish.

CodeWalker AntiRootkit:
http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar
Back to Top
fl3a View Drop Down
Groupie
Groupie
Avatar

Joined: 12 October 2006
Status: Offline
Points: 84
Post Options Post Options   Thanks (0) Thanks(0)   Quote fl3a Quote  Post ReplyReply Direct Link To This Post Posted: 25 November 2008 at 5:04pm
Hi thug4lif3,
 
I've tested CodeWalker with BadRkDemo, Unreal.A, phite_ex, it works fine. Did you implemented sth new like detection of threads/processes hidden by means of own scheduler? Could you tell us which part of detection are improved?
 
@Metraton did you tested it with your PoC rootkit?
Back to Top
 Post Reply Post Reply Page  12>
  Share Topic   

Forum Jump Forum Permissions View Drop Down