CariDotMy

 Forgot password?
 Register

ADVERTISEMENT

View: 4080|Reply: 8

ROOTKIT : anti-rootkit /rootkit revealer

[Copy link]
Post time 6-1-2010 10:29 PM | Show all posts |Read mode
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

RootkitRevealer v1.71
By Bryce Cogswell and Mark Russinovich

Published: November 1, 2006

Download RootkitRevealer (231 KB)



Introduction

RootkitRevealer is an advanced rootkit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects many persistent rootkits including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys). If you use it to identify the presence of a rootkit please let us know!

The reason that there is no longer a command-line version is that malware authors have started targetting RootkitRevealer's scan by using its executable name. We've therefore updated RootkitRevealer to execute its scan from a randomly named copy of itself that runs as a Windows service. This type of execution is not conducive to a command-line interface. Note that you can use command-line options to execute an automatic scan with results logged to a file, which is the equivalent of the command-line version's behavior.



What is a Rootkit?


The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.

Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt, to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.
Reply

Use magic Report


ADVERTISEMENT


Post time 6-1-2010 10:32 PM | Show all posts
pakai ajer Avast...mmg anti rootkit...boleh scan luar windows...kalau tidak berjuta kali delete ...virus tetap ada...
Reply

Use magic Report

 Author| Post time 6-1-2010 10:33 PM | Show all posts
sbenarnya aku pun tktau apa rootkit sbenarnya.

sapa2 bleh explain tak?

tools yg ada kat atas tu ialah utk selongkar system windows korang dan cari "rootkit". apa itu root kit? aku quote ayat kat atas : "mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities.".

so, rasanya berbeza dari hijackthis. sbb scan log dia totally tak sama, dan rootkit scanner ni bleh scan hddisk tambahan aku yg lain, sedangkan hijackthis cuma scan system windows aje...


ada sapa2 bleh bg maklumat tambahan, cemana nk guna ini rootkit? kredit tambahan menanti korang...
Reply

Use magic Report

Post time 6-1-2010 11:03 PM | Show all posts
sbenarnya aku pun tktau apa rootkit sbenarnya.

sapa2 bleh explain tak?

tools yg ada kat atas tu ialah utk selongkar system windows korang dan cari "rootkit". apa itu root kit? aku quote ...
bzzts Post at 6-1-2010 22:33


dalam kebanyakkan antivirus/malware mmg ada anti root kit ni bzzst....cuma bagus x bagus ajer...

cuba tgk tutorial bawah ni...

Rate

1

View Rating Log

Reply

Use magic Report

 Author| Post time 6-1-2010 11:47 PM | Show all posts
thanks abgboroi...

skrg ni kalu dah jumpa rootkit, cemana naktau which one threats or not? mana 1 nk delete? dah jadi cam hijackthis plak...

tkpe, aku cari rootkit detector ghostbuster/blacklight sat... test....
Reply

Use magic Report

Post time 7-1-2010 12:12 AM | Show all posts
kalu pakai malicious software removal tools bleh buang x rootkit nih?
Reply

Use magic Report

Follow Us
 Author| Post time 7-1-2010 12:36 AM | Show all posts
Post Last Edit by bzzts at 7-1-2010 00:38

6# hBk


tah le. tengok le keupayaan dia cemana.

aku dh donlod blacklight (freeware) : http://www.softpedia.com/get/Ant ... kit-Detection.shtml
so far, okey la.

sbenarnya... aku dpt pop-up error berulangkali dari 1 program yg aku install sbelom ni. aku dah uninstall 1 minggu lebih... skali aku dah scan registry, dah delete smua entry, check BHO, hijackthis smua... terlintas la pulak rootkit ni... still takde jawapan kpada masalah ni. rupanya2 problem tu duk kat " Control Panel >  Scheduled Task " je...

apa2 pun, smuga thread ni sukses dan membantu
Reply

Use magic Report

Post time 7-1-2010 12:12 PM | Show all posts
rootkit revealer.. rasa susah guna tuh. dia just tunjuk. elok tak elok korang tentukan

teringat pasal sony buat rootkit untuk cd lagu diorang

ye ke benda tu rootkit.. aku pun dah lupa.. rasanya betul
Reply

Use magic Report


ADVERTISEMENT


Post time 7-3-2010 10:40 AM | Show all posts
aku selalu bile bukak internet avast detect rootkit..ape maknenyer tue..aku bukan taw pe2 ha..plez explaian kan kat aku
Reply

Use magic Report

You have to log in before you can reply Login | Register

Points Rules

 

ADVERTISEMENT


Forum Hot Topic
...BYE 2024, HELLO 2025...
seribulan...BYE 2024, HELLO 2025...
Views : 54446 Replies : 4
...AZAM TAHUN 2025...
seribulan...AZAM TAHUN 2025...
Views : 54459 Replies : 20
Mutu penganjuran konsert Biduanita-Judika hauk (taraf funfair ramai rasa tertipu)
maklukpenggodaMutu penganjuran konsert Biduanita-Judik
Views : 15446 Replies : 31
madu gula tok matahari
aaanf14madu gula tok matahari
Views : 98662 Replies : 1017
Hafidz Roshdi vs. Ngai
maklukpenggodaHafidz Roshdi vs. Ngai
Views : 282585 Replies : 8332
"Kita usaha, bukannya duduk saja", Zain Saidin akhirnya bersuara, sedang gigih jual minyak wangi
maklukpenggoda"Kita usaha, bukannya duduk saja", Zain
Views : 57284 Replies : 124
Pelancong Malaysia Dihantar Pulang Walaupun Telah Melengkapkan Semua Dokumen Termasuk K-ETA (Korea Electronic Travel Authorization) , Mengapa Makin Susah Nak Masuk Korea?
YgBenarPelancong Malaysia Dihantar Pulang Walau
Views : 49083 Replies : 76
Sindiket 'Counter Setting' masih beroperasi di KLIA, dakwa sumber
AbahmungSindiket 'Counter Setting' masih
Views : 55281 Replies : 5
Tahniah Ina ! selamat pengantin baru sekali lagi UPDATE : DAH SELAMAT DIIJABKABUL 8Nov
anony-mousTahniah Ina ! selamat pengantin baru sek
Views : 146957 Replies : 2475
Pasca Penceraian Fattah Amin: Edisi Bedah Siasat/Ulasan/Gosip Santai (Post #1 UPDATED)
kakasotongPasca Penceraian Fattah Amin: Edisi Beda
Views : 191790 Replies : 10011

 

ADVERTISEMENT


 


ADVERTISEMENT
Follow Us

ADVERTISEMENT


Mobile|Archiver|Mobile*default|About Us|CariDotMy

16-12-2024 06:52 AM GMT+8 , Processed in 0.074891 second(s), 27 queries , Gzip On, Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

Quick Reply To Top Return to the list