SysProt AntiRootkit v1.0.0.3 Beta - Now out!
Goto page 1, 2  Next
CastleCops -> Rootkit Revelations

Author: swatkatLocation: India PostPosted: Sat Mar 17, 2007 6:43 pm    Post subject: SysProt AntiRootkit v1.0.0.3 Beta - Now out!

Hi all,

Update!
Latest Version:
SysProt AntiRootkit v1.0.0.4

I am happy to release the SysProt AntiRootkit v1.0.0.3 Beta. Thanks to CC and all who have helped me!
Features:


OS supported:
Windows 2000/XP/2003

Download link: CastleCops Link/zx/swatkat/SysProt.zip

Screenshot:
image

Feedbacks are welcome Wink


Last edited by swatkat on Sun Jun 17, 2007 9:02 pm, edited 1 time in total

Author: nosirrahLocation: USA PostPosted: Sat Mar 17, 2007 6:58 pm    Post subject:

Anyone interested in some research rootkits can get them here : CastleCops Link/t180919-MalRootkit_droppers_assorted_for_archiving_sharing.html .

I am on my there now .

Author: swatkatLocation: India PostPosted: Sat Mar 17, 2007 7:05 pm    Post subject:

@nosirrah
Thanks for the info. Downloading them Wink

Author: nosirrahLocation: USA PostPosted: Sat Mar 17, 2007 7:17 pm    Post subject:

Looks like SysProt can't see the SSDT hooks of wincom32.sys .

Code:
No SSDT Hooks found

Author: swatkatLocation: India PostPosted: Sun Mar 18, 2007 3:23 pm    Post subject:

Hi,
Thanks for testing SysProt AntiRootkit. I have made some updates, please download the tool from the link given in my first post here.
BTW, I am able to see Wincom32 and Nailuj rootkits in my test box.
image
image

Author: nosirrahLocation: USA PostPosted: Sun Mar 18, 2007 11:50 pm    Post subject:

Will retest tonight . Is there any chance that SP1 and SP2 would function differently ?

Author: SpannerITWksLocation: Uk PostPosted: Wed Mar 21, 2007 10:53 pm    Post subject:

swatkat

Hi,

I'm a little bit later than i would have liked in saying thanx for this, and may i encourage you to update it as often as you can.

I did however manage to include it as soon as you released it over in the SysInternals Rootkit thread - http://forum.sysinternals.com/forum_posts.asp?TID=962&PN=1&TPN=30

All the best,

Spanner

Author: negster22 PostPosted: Thu Mar 22, 2007 3:11 am    Post subject:

Good job, Mahesh, and Congrats. I know you've been working very hard Smile

Also, very nice of Spanner to insert a link to your program in the Sysinternals thread. I haven't checked out your latest version of SysProt ARK yet, but plan to soon.

Author: swatkatLocation: India PostPosted: Sun Mar 25, 2007 9:12 pm    Post subject:

Hi all,
Thanks for all the support @negster22 and SpannerITWks Smile I will be try my best to keep the tool up-to-date.
And, thank you SpannerITWks, for listing SysProt AntiRootkit at Sysinternals thread Smile

Author: SpannerITWksLocation: Uk PostPosted: Sun Mar 25, 2007 11:36 pm    Post subject:

swatkat

Pleasure, and please do try and keep it updated. Don't forget the cheque now will ya, in $ lol.

Spanner

Author: negster22 PostPosted: Mon Mar 26, 2007 1:47 am    Post subject:

swatkat wrote:
Thanks for all the support @negster22 and SpannerITWks Smile I will be try my best to keep the tool up-to-date.

I'm sure your tool is representative of all the great work you do and will continue to do.

Author: swatkatLocation: India PostPosted: Mon Apr 09, 2007 4:40 am    Post subject:

Hi all,
Update:
1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection

Author: negster22 PostPosted: Mon Apr 09, 2007 2:57 pm    Post subject:

Thanks, swat.
Quote:
1] Added "Extended Driver Scan" feature
2] Fixed some bug in Kernel Inline hook detection


Can you explain what an Extended Driver Scan is?

Author: swatkatLocation: India PostPosted: Mon Apr 09, 2007 4:41 pm    Post subject:

Hi,
It searches for Driver Objects, based on some signature, in Kernel memory area, similar to modGREPER. That's why the "Extended Driver Scan" takes time to complete. But, it can't detect driver objects of rootkits which zero out/alter the contents of driver object header (ex: Unreal.A and BadRkDemo?!).

Author: SpannerITWksLocation: Uk PostPosted: Mon Apr 09, 2007 6:00 pm    Post subject:

Hi, i'll help spread the word !

Thanx,

Spanner



CastleCops -> Rootkit Revelations

All times are GMT

Goto page 1, 2  Next
Page 1 of 2


Powered by phpBB © 2001 phpBB Group