CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Rootkit Unhooker
Goto page Previous  1, 2
 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Mixel

Cadet
Cadet


Joined: Sep 08, 2006
Posts: 5
Location: Mexico

PostPosted: Sat Sep 09, 2006 6:03 pm    Post subject:
Reply with quote

jejej i found the BadRKDemo ...
let me play with it.... Twisted Evil
SVV i will download it later.....
Smile



Last edited by Mixel on Tue Sep 12, 2006 12:57 am, edited 1 time in total
Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Sat Sep 09, 2006 6:42 pm    Post subject:
Reply with quote

Looking forward to the results and check out the GMER video too, because the study did not reveal all of GMER's features - it can remove badRKdemo.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sat Sep 09, 2006 7:23 pm    Post subject:
Reply with quote

LOL, the guy's really pissed off at you people for saying it's unstable.

Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Sun Sep 10, 2006 6:18 pm    Post subject:
Reply with quote

I have found an interesting RKUnhooker study which measures RKUnhooker's abiltity to detect seven rookits that use a diverse range of techniques. The test rootkits include FuTO enhanced (DKOM), BadRKDemo (DKOM), pe386 - Rustock.A (SYSCALL hook), AFX rootkit 2005, and HackerDefender & Vanquish (both user mode rootkits).

The study is wriiten in German so just click the "English Translation" button provided on the upper right corner of the page, to get the English translation.

Since the instability issues concerning RKUnhooker result from rootkit tool driver conflicts, if you want to try RKUnhooker, my suggestion is to do it before running run any rootkit tools, and then reboot afterwards. If you have used other detectors, you can just do this before running RKUnhooker:

1. Reboot to unload any anti-rootkit program drivers used previously
2. Run RKUnhooker
3. Reboot to remove the RKUnhooker driver

This same procedure may be applied to other detectors that do not unload their drivers, as well. This will eliminate crashes that occur from driver conflicts.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sun Sep 10, 2006 8:12 pm    Post subject:
Reply with quote

I just reimage.

Back to top
View users profile Send private message
Mixel

Cadet
Cadet


Joined: Sep 08, 2006
Posts: 5
Location: Mexico

PostPosted: Tue Sep 12, 2006 12:54 am    Post subject:
Reply with quote

Hi everybody

like i was expectin RKU can detect w/o a problem BadRKDemo

i attach the picture of it

svv must have to wait...




found!!!.JPG
 Description:
Yes it can detect it
 Filesize:  130.99 KB
 Viewed:  336 Time(s)

found!!!.JPG


Back to top
View users profile Send private message
Mixel

Cadet
Cadet


Joined: Sep 08, 2006
Posts: 5
Location: Mexico

PostPosted: Tue Sep 12, 2006 1:02 am    Post subject:
Reply with quote

About of the Joerg Klemenz blog is a little out of date
....
first thst post is about RKU 2.0 and actual release is 2.022 which is more stable and give less false positives...

so i think evrybody must to try the most new release before of post something...

Saludos desde Durango

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Sep 13, 2006 4:11 am    Post subject:
Reply with quote

ErikAlbert wrote:
LOL, the guy's really pissed off at you people for saying it's unstable.


Our Rootkit experts are just that, experts. If our CastleCops rootkit experts have an opinion on a tool then I'd side with them over anyone else. Sure, we're all human and can make mistakes, but that is what makes our experts unique. Their opinions are based on scientific and objective testing. And that is gold in my book.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Thu Oct 05, 2006 2:17 pm    Post subject:
Reply with quote

We are locking this topic for now. Please try to understand that this forum is unlike the rest of CastleCops in the following respect. We decide what programs or applications are safe and appropriate for use here.

Any links posted in the Rootkit Revelations forums to applications that we have not approved will be removed forthwith.


Best regards and have a nice day.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer