Log in

View Full Version : Rootkit Revealer


Silver
February 25th, 2005, 19:25
Not exactly a tool of our trade, but Sysinternals work is interesting nonetheless.

http://www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml

RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and HackerDefender.

l0rtsu
March 15th, 2005, 14:41
http://www.f-secure.com/blacklight/

F-secure released something similar a while ago.

Extremist
March 15th, 2005, 18:13
RootkitRevealer works by diffing high-level (API) and low-level (direct data-structure interpretation) file/registry views. To hide from it, a rootkit just needs NOT to hide from it.

blabberer
March 18th, 2005, 01:10
or assign use root process go to rootkit.com or hxdef home and read through thier forums infact some already hid it and the counter war white hacks have tried to randomize the name and the black hats have started checking the hash of process
http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx

Kayaker
March 18th, 2005, 15:44
Quote:
[Originally Posted by blabberer]http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx


There are some nice references in there, thx.

blabberer
March 19th, 2005, 09:38
Dear kayaker,
my pleasure
yes pretty interesting techniques from horses mouth like running .gif on cmd.exe to execute an exe etc etc and unpublished forensic tools good blog so i linked it

Opcode
March 23rd, 2005, 18:55
Quote:
[Originally Posted by blabberer]http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx


Russinovich has updated the Rootkit Revealer to block this attack.
There is no more a comand line version of this tool.

This war will be very funny.

Regards,
Opcode