| View previous topic :: View next topic |
| Author |
Message |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6293 Location: USA
|
|
| Back to top |
|
 |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
Posted: Sat Mar 17, 2007 7:05 pm Post subject: |
|
|
@nosirrah
Thanks for the info. Downloading them  _________________ Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6293 Location: USA
|
Posted: Sat Mar 17, 2007 7:17 pm Post subject: |
|
|
Looks like SysProt can't see the SSDT hooks of wincom32.sys .
| Code: | | No SSDT Hooks found |
| Description: |
|
| Filesize: |
17.06 KB |
| Viewed: |
150 Time(s) |

|
|
|
| Back to top |
|
 |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6293 Location: USA
|
Posted: Sun Mar 18, 2007 11:50 pm Post subject: |
|
|
Will retest tonight . Is there any chance that SP1 and SP2 would function differently ?
|
|
| Back to top |
|
 |
SpannerITWks
Sergeant

 Joined: Dec 15, 2006 Posts: 91 Location: Uk
|
Posted: Wed Mar 21, 2007 10:53 pm Post subject: |
|
|
swatkat
Hi,
I'm a little bit later than i would have liked in saying thanx for this, and may i encourage you to update it as often as you can.
I did however manage to include it as soon as you released it over in the SysInternals Rootkit thread - http://forum.sysinternals.com/forum_posts.asp?TID=962&PN=1&TPN=30
All the best,
Spanner _________________ Stay Safe - BOClean AntiMalware -
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5253
|
|
| Back to top |
|
 |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
|
| Back to top |
|
 |
SpannerITWks
Sergeant

 Joined: Dec 15, 2006 Posts: 91 Location: Uk
|
Posted: Sun Mar 25, 2007 11:36 pm Post subject: |
|
|
swatkat
Pleasure, and please do try and keep it updated. Don't forget the cheque now will ya, in $ lol.
Spanner _________________ Stay Safe - BOClean AntiMalware -
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5253
|
Posted: Mon Mar 26, 2007 1:47 am Post subject: |
|
|
| swatkat wrote: | | Thanks for all the support @negster22 and SpannerITWks Smile I will be try my best to keep the tool up-to-date. |
I'm sure your tool is representative of all the great work you do and will continue to do. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
Posted: Mon Apr 09, 2007 4:40 am Post subject: |
|
|
Hi all,
Update:
1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection _________________ Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5253
|
Posted: Mon Apr 09, 2007 2:57 pm Post subject: |
|
|
Thanks, swat.
| Quote: | 1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection |
Can you explain what an Extended Driver Scan is? _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
swatkat
Security Expert
 Joined: Mar 04, 2005 Posts: 2036 Location: India
|
Posted: Mon Apr 09, 2007 4:41 pm Post subject: |
|
|
Hi,
It searches for Driver Objects, based on some signature, in Kernel memory area, similar to modGREPER. That's why the "Extended Driver Scan" takes time to complete. But, it can't detect driver objects of rootkits which zero out/alter the contents of driver object header (ex: Unreal.A and BadRkDemo?!). _________________ Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
|
|
| Back to top |
|
 |
SpannerITWks
Sergeant

 Joined: Dec 15, 2006 Posts: 91 Location: Uk
|
Posted: Mon Apr 09, 2007 6:00 pm Post subject: |
|
|
Hi, i'll help spread the word !
Thanx,
Spanner _________________ Stay Safe - BOClean AntiMalware -
|
|
| Back to top |
|
 |
|
|