![]() |
** RootKit Detection + Prevention ! ** |
Post Reply
|
Page <1 1112131415 41> |
| Author | |
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Topic: ** RootKit Detection + Prevention ! **Posted: 20 February 2007 at 9:16pm |
|
UPDATE Avira AntiRootkit Tool - Beta 3 Avira Rootkit Detection (ARK) is designed to detect active rootkits on Windows systems with Microsoft Windows 2000 and above. Installation Please note that you must be logged-in as ?Administrator? or as a user with administrative rights in order to install or run Avira RootKit Detection ? Beta. Please start SETUP.EXE and follow the instructions. Background ?Rootkit? is usually defined as a software code intending to hide a resource from the user. Avira AntiRootkit Tool ? Beta supports detection of hidden processes, registry entries and files. Some malware frequently hide their processes, registry entries and files to bypass detection by anti-virus products. If a hidden object is detected in the system, then Avira AntiRootkit Tool ? Beta shows it and offers supplementary options accessible by doing a right click on the object. The button ?Quarantine all? first shows a list of the files that will be quarantined; please note that registry entries are not deleted or quarantined. Moreover, we would like to draw you attention to the fact that some commercial products deliberately hide their own resources. Not all applications which hide their tracks should be considered as being malware. The period of time needed for the scan, dependes on how many files, registry entries or processes you have on the system. Therefore, the option ?Fast Scan? is now available. If this is activated the only location scanned is the one used by malware. Supported platforms: - Windows Server/Workstation 2000 Service Pack 4 or more This is a BETA product. Do not install it on a production machine. ************************************************* Any feedback is very much appreciated. antivir_rootkit_beta.exe - 2.2 MB MD5 = 2bdbb1bfa1f72d30114ca73ed3acff58 Available Free both in English + German here - http://betatest.avira.com/beta/index.php?lang=en - Spanner |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Posted: 20 February 2007 at 9:13pm |
|
Steo Thanx for posting the news. I wonder if the Linux peeps are getting worried lol. And this release comes not long after the ARK for the Mac OSX ! Spanner |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
steo
Newbie
Joined: 14 April 2006 Online Status: Offline Posts: 18 |
Post Options
Quote Reply
Posted: 20 February 2007 at 5:51pm |
|
New Rootkit Scanner for Linux: Rootkit Profiler LX Overview RKPmod is a kernel module that gets loaded on the system that should be checked for the presence of a kernel rootkit. There are other ways to perform data collection, but currently only this approach is publicly available. RKPconsole is a userland program that can be used to analyse the collected information. Features - Generic kernel code modification Check out http://www.trapkit.de/research/rkprofiler/rkplx/rkplx.html for more info and download, regards
|
|
![]() |
|
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Posted: 18 February 2007 at 4:31pm |
|
UPDATE Rootkit Unhooker now = v3.20.130.388 Improved - Program random-naming Fixed - NTFS Wipe / Copy File bug BSOD's during Hidden Processes / Code Hooks Detector Scans - RkU3.20.130.388.exe - 144kb - MD5 = F79F711BD54BFC9F297EEEFEE69F8705 Free from http://rku.xell.ru/?l=e&a=dl Spanner |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Posted: 18 February 2007 at 4:29pm |
|
UPDATE Process Walker v1.0.05 Process Walker unzippped = pwalker.exe + pwalker.sys Process Walker App = pwalker.exe = Internally numbered as v1.0.0.340 Process Walker Driver = pwalker.sys = Internally numbered as v3.0.40.0 Fixed - A bug that can lead to BSOD's on some machines UI bug - For Windows XP SP2 Only. Console version only. Zip MD5 = 51F6A0C14513199B9913ACE5A812926F Free from http://rku.xell.ru/?l=e&a=dl Spanner Edited by SpannerITWks - 18 February 2007 at 4:31pm |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Posted: 18 February 2007 at 4:25pm |
|
UPDATE Since my posting of rootchk above, ejvindh has now created a new English forum area. The English Room In this room I present English translations of some of the info that I have presented in Danish. If you, as a non-Danish person, want my help in analysing and removing rootkits, you are also welcome to create a threat. http://www.ejvindh.net/viewforum.php?f=9&sid=69cac51db19 95d2984f3d30027dc7525 I think he means Thread not Threat, well i hope so anyway lol ! Spanner |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
SpannerITWks
Senior Member
Joined: 14 August 2005 Location: United Kingdom Online Status: Offline Posts: 896 |
Post Options
Quote Reply
Posted: 14 February 2007 at 4:16pm |
|
rootchk Here's an ARK made by ejvindh. It's doesn't pretend to be All inclusive, but you might find it useful or interesting ! Translated from Danish - - I have made a small tool to check a few, well-known rootkit's. It's Only one diagnosis-tool. If you do not know how to fix the infections, you can establish a thread in here, I will try to help you off with it. And even if the tool doesn't find anything, there isn't any guarantee that there isn't a rootkit in the computer. In one respect the check is far from thorough. In one respect they can examine rootkit's it's also very easy to avoid detection, if they change their name. But it's better than nothing. I'll try to keep it brought up to date, as I am able. - Fetch this tool, and keep it on your desk: Http://www.uploads.ejvindh.net/rootchk.exe Run the programme. After a short time a logfile will turn up. Copies the contents of the log in here in the thread. - Following drivers are checked also for. But only on experimental basis. I.e. I am not completely certain whether rootchk actually can find them (haven't been able to track down the infections in order to test. ): rootchk.exe - 251kb - MD5 = DD6D95AFF7997C9974280575A0E306B8 Free from - http://www.ejvindh.net/viewtopic.php?t=91&sid=1ba77615bb 0b45d3b06809c35e7cb912 Spanner |
|
|
Stay Safe - SpannerITWks/SpannerInTheWorks -
BOClean AntiMalware - http://www.nsclean.com/boclean.html |
|
![]() |
|
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 14 February 2007 at 9:55am |
|
RkUService.exe renames RkUnhooker.exe to something like DDD6FCA2.exe and creates shortcuts in the Start menu. After that installer deletes RkUService.exe
Edited by EP_X0FF - 14 February 2007 at 9:56am |
|
|
Ring0 - the source of inspiration
|
|
![]() |
|
EASTER
Senior Member
Joined: 27 October 2006 Location: United States Online Status: Offline Posts: 336 |
Post Options
Quote Reply
Posted: 12 February 2007 at 9:28pm |
|
I saw that too But i'm sure either can offer you a reasonably logical explaination. |
|
|
INTENSIVE TECHNICAL RESEARCH ANALYSIS AND STEALTH EXAMINER.
|
|
![]() |
|
Dragon
Groupie
Joined: 27 April 2006 Online Status: Offline Posts: 48 |
Post Options
Quote Reply
Posted: 12 February 2007 at 12:09pm |
|
I saw an error after I tried run a RKU:
Driver is already loaded! After ok' program start. Where is that file which I saw after install it : RkuService.exe ? It's not allways is extracting after uninstal and install again RKU. I don't see it in /drivers, /system32 even hidden files after RKU scan. Where is it EP_X0FF? -- Dragon |
|
![]() |
|
Post Reply
|
Page <1 1112131415 41> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |