View Full Version : Rootkit Revealer
Silver
February 25th, 2005, 19:25
Not exactly a tool of our trade, but Sysinternals work is interesting nonetheless.
http://www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml
RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and HackerDefender.
l0rtsu
March 15th, 2005, 14:41
http://www.f-secure.com/blacklight/
F-secure released something similar a while ago.
Extremist
March 15th, 2005, 18:13
RootkitRevealer works by diffing high-level (API) and low-level (direct data-structure interpretation) file/registry views. To hide from it, a rootkit just needs NOT to hide from it.

blabberer
March 18th, 2005, 01:10
or assign use root process

go to rootkit.com or hxdef home and read through thier forums infact some already hid it and the counter war white hacks have tried to randomize the name and the black hats have started checking the hash of process
http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx
Kayaker
March 18th, 2005, 15:44
Quote:
[Originally Posted by blabberer]http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx |
There are some nice references in there, thx.
blabberer
March 19th, 2005, 09:38
Dear kayaker,
my pleasure
yes pretty interesting techniques from horses mouth like running .gif on cmd.exe to execute an exe etc etc and unpublished forensic tools good blog so i linked it
Opcode
March 23rd, 2005, 18:55
Quote:
[Originally Posted by blabberer]http://blogs.msdn.com/robert_hensing/archive/2005/03/10/392092.aspx |
Russinovich has updated the Rootkit Revealer to block this attack.
There is no more a comand line version of this tool.
This war will be very funny.
Regards,
Opcode
Powered by vBulletin® Version 4.2.2 Copyright © 2018 vBulletin Solutions, Inc. All rights reserved.