CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer

SysProt AntiRootkit v1.0.0.3 Beta - Now out!
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Apr 09, 2007 6:02 pm    Post subject:
Reply with quote

Hi SpannerITWks,
Thanks again for the support Very Happy Thumbs Up


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5229

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Wed Apr 11, 2007 9:43 pm    Post subject:
Reply with quote

SysProt AntiRootkit is also listed on AntiRootkit.com
http://antirootkit.com/software/SysProt-AntiRootkit.htm

Looks great!!


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
SpannerITWks

Sergeant
Sergeant


Joined: Dec 15, 2006
Posts: 91
Location: Uk

PostPosted: Sun Apr 15, 2007 1:26 am    Post subject:
Reply with quote

I started a new thread about this in here - http://www.dslreports.com/forum/svendors - on the same day i posted in here - http://forum.sysinternals.com/forum_posts.asp?TID=962&PN=31

The info i posted on dsl was Exactly the same as in the SysInternals !

For some " Unknown " reason the dsl thread was removed without ANY warning or explanation ? Nor did i get a PM from anyone about it being deleted either ?

Anybody know why this could have happened ?

I'm sorry it was removed, but it was not my doing.

Spanner


_________________
Stay Safe - BOClean AntiMalware -
Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Tue Apr 17, 2007 3:44 pm    Post subject:
Reply with quote

Hi SpannerITWks,
Thanks for your cooperation. I wonder why what happened at DSL Reports!
Anyway, as far as SysProt AntiRootkit is considered, I have made a small update. Now, it shows whether a process has visible window or not. This might be useful to catch some trojans. For example, Nailuj.A starts IExplore.exe process, but IE's window will not be visible.


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Apr 30, 2007 5:50 pm    Post subject:
Reply with quote

Update:
[+] Full path of processes
[+] phide_ex detection


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Tue Jun 12, 2007 6:52 pm    Post subject:
Reply with quote

Update:
SysProt AntiRootkit v1.0.0.4
[+] Faster
[+] Kernel inline hooks removal
[+] Detection and removal of hidden Services Registry keys


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5229

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Tue Jun 12, 2007 8:07 pm    Post subject:
Reply with quote

Thanks, Mahesh - sounds good!


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 16858

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Thu Jun 14, 2007 9:36 pm    Post subject:
Reply with quote

Great work! Thumbs Up


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2036
Location: India
MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Jun 17, 2007 8:50 pm    Post subject:
Reply with quote

Hi all,
One more update Smile
[+] SSDT hooks removal


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
IP: 217.171.*.*

Guest






PostPosted: Mon Jun 25, 2007 2:55 pm    Post subject:
Reply with quote

Hi swatkat !

Thank you for SysProt AntiRootkit !

I tested it using too IceSword (IS), RkUnhooker (RkU), Regshot and a very few things on a two years old laptop whith Windows Home Edition and 512Mb of memory.

First small test ...
*-* Regshots detects 6 new Registry keys, 15 new values and 6 modified values. RkU detects two Sysprot hooks : IAT modifications. IS estimates SysProt memory usage between 4268kb and 5004kb (peak). RkU and IS show "SysProtDrv.sy"s into kernel.
*-* Problems ...
..... SysProt delayed a little bit on showing processes and very much for "Ports" and "File System"
..... SysProt show nothing into other modules when the list of Kernel Inline Hooks should include the hooks of IceSword.
..... After several attempts, IS refused to function (not enough memory).
...... Sysprot error message when using it I tried to kill IS.

Second small test ...
*-* No more memory problem using together Sysprot and IceSword (IS) and better delay on listing. I like very much Window visible into process module.
*-* Problems ...
..... Sysprot error message when using it I tried to kill IS.
..... SysProt show nothing into "Kernel Inline Hooks" when it should include the hooks of IceSword (6 Inline – RelativeJump).
..... Sysprot process is killed using IS.

What is the "Registry" module usage ?
What do you think about a translation of Sysprot into Spanish and French ?

Kind Regards.
Txon.

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer