Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > RootkitRevealer Usage
  New Posts New Posts RSS Feed: ** RootKit Detection + Prevention ! **
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

** RootKit Detection + Prevention ! **

 Post Reply Post Reply Page  <1 1112131415 41>
Author
Message Reverse Sort Order
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Topic: ** RootKit Detection + Prevention ! **
    Posted: 20 February 2007 at 9:16pm

UPDATE

Avira AntiRootkit Tool - Beta 3

Avira Rootkit Detection (ARK) is designed to detect active rootkits on Windows systems with Microsoft Windows 2000 and above.

Installation
============

Please note that you must be logged-in as ?Administrator? or as a user with administrative rights in order to install or run Avira RootKit Detection ? Beta. Please start SETUP.EXE and follow the instructions.

Background
==========

?Rootkit? is usually defined as a software code intending to hide a resource from the user.

Avira AntiRootkit Tool ? Beta supports detection of hidden processes, registry entries and files. Some malware frequently hide their processes, registry entries and files to bypass detection by anti-virus products. If a hidden object is detected in the system, then Avira AntiRootkit Tool ? Beta shows it and offers supplementary options accessible by doing a right click on the object. The button ?Quarantine all? first shows a list of the files that will be quarantined; please note that registry entries are not deleted or quarantined.

Moreover, we would like to draw you attention to the fact that some commercial products deliberately hide their own resources. Not all applications which hide their tracks should be considered as being malware.

The period of time needed for the scan, dependes on how many files, registry entries or processes you have on the system. Therefore, the option ?Fast Scan? is now available. If this is activated the only location scanned is the one used by malware.

Supported platforms:

- Windows Server/Workstation 2000 Service Pack 4 or more
- Windows XP
- Windows Server 2003
- Windows Vista
 
*********************W A R N I N G *****************

This is a BETA product. Do not install it on a production machine.

*************************************************

Any feedback is very much appreciated.

antivir_rootkit_beta.exe - 2.2 MB

MD5 = 2bdbb1bfa1f72d30114ca73ed3acff58

Available Free both in English + German here -  http://betatest.avira.com/beta/index.php?lang=en

-

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 20 February 2007 at 9:13pm

Steo

Thanx for posting the news. I wonder if the Linux peeps are getting worried lol. And this release comes not long after the ARK for the Mac OSX !

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
steo View Drop Down
Newbie
Newbie


Joined: 14 April 2006
Online Status: Offline
Posts: 18
Post Options Post Options   Quote steo Quote  Post ReplyReply Direct Link To This Post Posted: 20 February 2007 at 5:51pm

New Rootkit Scanner for Linux:

Rootkit Profiler LX

Overview
RKProfiler LX is divided into two parts: a data collection component called "Rootkit Profiler Module" (RKPmod) and a data interpretation component called "Rootkit Profiler Console" (RKPconsole).

RKPmod is a kernel module that gets loaded on the system that should be checked for the presence of a kernel rootkit. There are other ways to perform data collection, but currently only this approach is publicly available.

RKPconsole is a userland program that can be used to analyse the collected information.

Features
Detection: RKProfiler LX checks the whole kernel code as well as different kernel data sections and cpu registers regarding possible modifications and hidden components:

- Generic kernel code modification
- Syscall table address modification
- Syscall address modification
- Syscall code modification
- Interrupt handler address modification
- Interrupt handler code modification
- Page Fault Handler modification
- Kernel symbol modification
- SYSENTER register modification
- Virtual File System function pointer modification
- Hidden processes and threads
- Hidden kernel modules

Check out http://www.trapkit.de/research/rkprofiler/rkplx/rkplx.html for more info and download,

regards

Steo
www.antirootkit.com

 

Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 18 February 2007 at 4:31pm

UPDATE

Rootkit Unhooker now = v3.20.130.388

Improved -

Program random-naming

Fixed -

NTFS Wipe / Copy File bug

BSOD's during Hidden Processes / Code Hooks Detector Scans

-

RkU3.20.130.388.exe - 144kb - MD5 = F79F711BD54BFC9F297EEEFEE69F8705

Free from http://rku.xell.ru/?l=e&a=dl

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 18 February 2007 at 4:29pm

UPDATE

Process Walker v1.0.05

Process Walker unzippped = pwalker.exe + pwalker.sys

Process Walker App = pwalker.exe = Internally numbered as v1.0.0.340

Process Walker Driver = pwalker.sys = Internally numbered as v3.0.40.0

Fixed -

A bug that can lead to BSOD's on some machines

UI bug

-

For Windows XP SP2 Only.

Console version only.

Zip MD5 = 51F6A0C14513199B9913ACE5A812926F

Free from http://rku.xell.ru/?l=e&a=dl

Spanner



Edited by SpannerITWks - 18 February 2007 at 4:31pm
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 18 February 2007 at 4:25pm

UPDATE

Since my posting of rootchk above, ejvindh has now created a new English forum area.

The English Room 
 
Rootkits and anti-rootkit tools.

In this room I present English translations of some of the info that I have presented in Danish. If you, as a non-Danish person, want my help in analysing and removing rootkits, you are also welcome to create a threat.

http://www.ejvindh.net/viewforum.php?f=9&sid=69cac51db19 95d2984f3d30027dc7525

I think he means Thread not Threat, well i hope so anyway lol !

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
SpannerITWks View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 August 2005
Location: United Kingdom
Online Status: Offline
Posts: 896
Post Options Post Options   Quote SpannerITWks Quote  Post ReplyReply Direct Link To This Post Posted: 14 February 2007 at 4:16pm

rootchk

Here's an ARK made by ejvindh. It's doesn't pretend to be All inclusive, but you might find it useful or interesting !

Translated from Danish -

-

I have made a small tool to check a few, well-known rootkit's. It's Only one diagnosis-tool. If you do not know how to fix the infections, you can establish a thread in here, I will try to help you off with it. And even if the tool doesn't find anything, there isn't any guarantee that there isn't a rootkit in the computer. In one respect the check is far from thorough. In one respect they can examine rootkit's it's also very easy to avoid detection, if they change their name. But it's better than nothing. I'll try to keep it brought up to date, as I am able.

-

Fetch this tool, and keep it on your desk: Http://www.uploads.ejvindh.net/rootchk.exe Run the programme. After a short time a logfile will turn up. Copies the contents of the log in here in the thread.

-

Following drivers are checked also for. But only on experimental basis. I.e. I am not completely certain whether rootchk actually can find them (haven't been able to track down the infections in order to test. ):

rootchk.exe - 251kb - MD5 = DD6D95AFF7997C9974280575A0E306B8

Free from - http://www.ejvindh.net/viewtopic.php?t=91&sid=1ba77615bb 0b45d3b06809c35e7cb912

Spanner

Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html
Back to Top
EP_X0FF View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 4753
Post Options Post Options   Quote EP_X0FF Quote  Post ReplyReply Direct Link To This Post Posted: 14 February 2007 at 9:55am
RkUService.exe renames RkUnhooker.exe to something like DDD6FCA2.exe and creates shortcuts in the Start menu. After that installer deletes RkUService.exe

Edited by EP_X0FF - 14 February 2007 at 9:56am
Ring0 - the source of inspiration
Back to Top
EASTER View Drop Down
Senior Member
Senior Member
Avatar

Joined: 27 October 2006
Location: United States
Online Status: Offline
Posts: 336
Post Options Post Options   Quote EASTER Quote  Post ReplyReply Direct Link To This Post Posted: 12 February 2007 at 9:28pm

Where is that file which I saw after install it : RkuService.exe ?

I saw that too   I never concern myself too much over those interesting appearances because i know MP_ART/EP_XOFF have a firm handle on their excellent RK Detector and take their creation very seriously.

But i'm sure either can offer you a reasonably logical explaination.

 

INTENSIVE TECHNICAL RESEARCH ANALYSIS AND STEALTH EXAMINER.
Back to Top
Dragon View Drop Down
Groupie
Groupie
Avatar

Joined: 27 April 2006
Online Status: Offline
Posts: 48
Post Options Post Options   Quote Dragon Quote  Post ReplyReply Direct Link To This Post Posted: 12 February 2007 at 12:09pm
I saw an error after I tried run a RKU:
Driver is already loaded!
After ok' program start.
Where is that file which I saw after install it : RkuService.exe ?
It's not allways is extracting after uninstal and install again RKU.
I don't see it in /drivers, /system32 even hidden files after RKU scan.
Where is it EP_X0FF?

--
Dragon
Back to Top
 Post Reply Post Reply Page  <1 1112131415 41>

Forum Jump Forum Permissions View Drop Down