CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer

SysProt AntiRootkit v1.0.0.3 Beta - Now out!
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sat Mar 17, 2007 6:43 pm    Post subject: SysProt AntiRootkit v1.0.0.3 Beta - Now out!
Reply with quote

Hi all,

Update!
Latest Version:
SysProt AntiRootkit v1.0.0.4

I am happy to release the SysProt AntiRootkit v1.0.0.3 Beta. Thanks to CC and all who have helped me!
Features:

  • Hidden process detection and removal
  • Hidden drivers detection
  • SSDT Hooks detection and remvoal
  • Kernel Inline hooks detection and removal
  • Sysenter Hook detection
  • TCP/UDP Ports Info
  • File System browser
  • Hidden Services Registry keys detection and removal


OS supported:
Windows 2000/XP/2003

Download link: CastleCops Link/zx/swatkat/SysProt.zip

Screenshot:
image

Feedbacks are welcome Wink


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein


Last edited by swatkat on Sun Jun 17, 2007 9:02 pm, edited 1 time in total
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6292
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sat Mar 17, 2007 6:58 pm    Post subject:
Reply with quote

Anyone interested in some research rootkits can get them here : CastleCops Link/t180919-MalRootkit_droppers_assorted_for_archiving_sharing.html .

I am on my there now .

Back to top
View users profile Send private message Send email
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sat Mar 17, 2007 7:05 pm    Post subject:
Reply with quote

@nosirrah
Thanks for the info. Downloading them Wink


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6292
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sat Mar 17, 2007 7:17 pm    Post subject:
Reply with quote

Looks like SysProt can't see the SSDT hooks of wincom32.sys .

Code:
No SSDT Hooks found




1.jpg
 Description:
 Filesize:  17.06 KB
 Viewed:  143 Time(s)

1.jpg


Back to top
View users profile Send private message Send email
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Mar 18, 2007 3:23 pm    Post subject:
Reply with quote

Hi,
Thanks for testing SysProt AntiRootkit. I have made some updates, please download the tool from the link given in my first post here.
BTW, I am able to see Wincom32 and Nailuj rootkits in my test box.
image
image


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6292
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sun Mar 18, 2007 11:50 pm    Post subject:
Reply with quote

Will retest tonight . Is there any chance that SP1 and SP2 would function differently ?

Back to top
View users profile Send private message Send email
SpannerITWks

Sergeant
Sergeant


Joined: Dec 15, 2006
Posts: 91
Location: Uk

PostPosted: Wed Mar 21, 2007 10:53 pm    Post subject:
Reply with quote

swatkat

Hi,

I'm a little bit later than i would have liked in saying thanx for this, and may i encourage you to update it as often as you can.

I did however manage to include it as soon as you released it over in the SysInternals Rootkit thread - http://forum.sysinternals.com/forum_posts.asp?TID=962&PN=1&TPN=30

All the best,

Spanner


_________________
Stay Safe - BOClean AntiMalware -
Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5229

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Thu Mar 22, 2007 3:11 am    Post subject:
Reply with quote

Good job, Mahesh, and Congrats. I know you've been working very hard Smile

Also, very nice of Spanner to insert a link to your program in the Sysinternals thread. I haven't checked out your latest version of SysProt ARK yet, but plan to soon.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Mar 25, 2007 9:12 pm    Post subject:
Reply with quote

Hi all,
Thanks for all the support @negster22 and SpannerITWks Smile I will be try my best to keep the tool up-to-date.
And, thank you SpannerITWks, for listing SysProt AntiRootkit at Sysinternals thread Smile


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
SpannerITWks

Sergeant
Sergeant


Joined: Dec 15, 2006
Posts: 91
Location: Uk

PostPosted: Sun Mar 25, 2007 11:36 pm    Post subject:
Reply with quote

swatkat

Pleasure, and please do try and keep it updated. Don't forget the cheque now will ya, in $ lol.

Spanner


_________________
Stay Safe - BOClean AntiMalware -
Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5229

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Mon Mar 26, 2007 1:47 am    Post subject:
Reply with quote

swatkat wrote:
Thanks for all the support @negster22 and SpannerITWks Smile I will be try my best to keep the tool up-to-date.

I'm sure your tool is representative of all the great work you do and will continue to do.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Apr 09, 2007 4:40 am    Post subject:
Reply with quote

Hi all,
Update:
1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5229

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Mon Apr 09, 2007 2:57 pm    Post subject:
Reply with quote

Thanks, swat.

Quote:
1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection


Can you explain what an Extended Driver Scan is?


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Apr 09, 2007 4:41 pm    Post subject:
Reply with quote

Hi,
It searches for Driver Objects, based on some signature, in Kernel memory area, similar to modGREPER. That's why the "Extended Driver Scan" takes time to complete. But, it can't detect driver objects of rootkits which zero out/alter the contents of driver object header (ex: Unreal.A and BadRkDemo?!).


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
SpannerITWks

Sergeant
Sergeant


Joined: Dec 15, 2006
Posts: 91
Location: Uk

PostPosted: Mon Apr 09, 2007 6:00 pm    Post subject:
Reply with quote

Hi, i'll help spread the word !

Thanx,

Spanner


_________________
Stay Safe - BOClean AntiMalware -
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer