C0D4R
May 30 2004, 04:30 AM
Online Virus Scanner http://www.kaspersky.com/scanforvirus.htmlhttp://www3.ca.com/securityadvisor/virusinfo/scan.aspxhttp://www.bitdefender.com/scan/Msie/index.phponly kaspersky can detect the Hxdef Rootkit~ and it can detect the drivers.sys also i think kaspersky detect the drivers.sys in the hxdef100.exe,and it called hxdef100.exe is a virus so how to modify the drivers.sys
VannDeR
May 30 2004, 09:57 AM
not only the .sys is detected. i tried modifying almost line per line in hxdef100.dpr , (without the sys compiled) and kaspersky still detects it, i tried too to edit assembler functions but i had no success  , i dont understand what string or functions is looked for by the kaspersky
123spawnie123
May 31 2004, 01:27 AM
avg6 detects it too :| norton corporate and mcafee didn't
HiBob
May 31 2004, 12:30 PM
Thanks for the tut, seems very in depth and I am going to try it soon
braini
Jul 1 2004, 05:33 PM
i really like that tut and gonna test that now...
big big thnx for that info...
Player
Jul 2 2004, 04:23 AM
is using hxdef better than using radmin?
8Ball
Jul 2 2004, 12:36 PM
hxdef is some kind of rootkit, that means it hides ur files, services and processes it has a backdoor, shell based
radmin is alike vnc or shadow, its used to control remotly the system
Player
Jul 2 2004, 05:23 PM
ok thanks for the explanation 8ball, if i don't need to necessarily be able to control the box by mouse and keyboard, just possibily be able to view the screen (this is not big importance) and to send commands via prompt and transfer files, what do you all suggest?
saetji
Aug 24 2004, 02:07 PM
player: radmin or remote anywhere
i tried but it gets detected by f-secure which is damn well annoying :|
phaeton
Oct 24 2004, 09:25 PM
Ok, I still get PMs (which is cool) about this topic... So, I will be posting a updated tutorial that doesn't require cracking etc etc, with some tricks to bypass KAV as of today (October 24th). It'll hopefully be up later this week in a new thread to keep easier track of replies  hxxp://s91259931.onlinehome.us/files/hxdef-builder-3.rar This allows you to compile entire hxdef, just extract *.dpr files to the base dir w/ BATs, then extract the driver.[h/c] to the driver directory and hit build-all when done! Enjoy!
BaLooN
Nov 2 2004, 09:39 PM
QUOTE(ArEs @ May 4 2004, 02:00 PM) yeah wodnerful thx it looks great haven`t tested yet but really sounds good !!!!! hmmm i can`t find xp ddk on filemirror...as it seems ddk ( driver development kit) is only availibele from msdn now ? and u have ti register a .net passport for that...any othe sources ? Try this link: http://club.shelek.com/download.php?id=5Otherwise search for ddk_xp.iso at google.com and u'll find a bunch of mirrors. Or i noticed atm. Search for ddk_xp.iso at filemirrors.com and u'll find results
lavey666uk
Nov 3 2004, 04:27 PM
thx for the tut.. was looking for something like this... modded all the parts.. but when I run the rk it doesnt drop the driver file? no driver - no connex... any ideas? am using as a test .. can see exe running in process list on test machine.. QUOTE Microsoft Windows XP [Version 5.1.2600] © Copyright 1985-2001 Microsoft Corp.
D:\Personal\Test Stuff\rootkit source\bdcli100.exe Host: 192.5.10.113 Port: 139 Pass: test connecting server ... receiving banner ... opening backdoor ..................... backdoor is not installed on 192.5.10.113:139
>>edit.. ok dumb me.. forgot to change driverfilename in ini file.. driver file now drops but still no connection ?
EEnd
Nov 4 2004, 10:55 PM
thx a million for this one dude  :D:D u dont know how much u helped me whit this  thx again!
ninar12
Nov 5 2004, 02:27 AM
thx i gonna try this one also
morphin also helps
strych_nine
Nov 6 2004, 09:47 AM
i have one big problem. the .ini file is detected by av, even if i rename it to whatever (tried several names and fileextensions). even the extra characters that can be used didn't fix the problem.
any suggestions?
ninar12
Nov 6 2004, 06:15 PM
use some special carakter like toldin the readme
Rafter
Nov 9 2004, 10:46 AM
Hi thanks for this great tutorial  I just have a (small) problem while using the hxdef builder  The driver is not being compiled, and strangly i don't get any error message from the build, and nothing in the objw2k_fre.log too ! So I checked the bat files and also the setw2k.bat to see what was going wrong... nothing suspicious  I also changed the pathes in the build.dat file so that it fits my own environment  I'm stucked there and didn't have time yesterday to dig deeply into it, but maybe someone has an idea which would help ?  Anyway the build of hxdef (with the old driver.sys) is working beautifully, and is not being detected  I just need the driver now
lavey666uk
Nov 9 2004, 08:56 PM
I did the same VaanDer.. modded both the header file and c file for the driver including all variables, etc.. still Kav catches the damn sys file!... lol phaeton... hangign on for this post dude  QUOTE some tricks to bypass KAV as of today (October 24th).
eftex
Nov 17 2004, 03:09 PM
i did both versions.... on "classic" and one with the hxdef-builder... the hxdef-builder has several errors with i was not able to fix completely... the delphi-building is no prob but the c-driver doesn't get compled  must be a error in one of the macro-files i guess... will see.... my prob is that the ddk_xp.iso isn't available anymore on filemirrors and i dind't find it anywhere else for download... only dead links... i downloaded the ddk_xp.iso three times before but all have been corruptet so i wasn't able to install it... if somebody could be so patient to send, up, or tell me where to get it i would be very appreciated and thankfull!!!
ghorghut
Nov 25 2004, 02:19 AM
tnx alot dude! good post and nice reading :-)
KarachiKing555
Nov 26 2004, 03:27 PM
QUOTE(eftex @ Nov 17 2004, 03:09 PM) i did both versions.... on "classic" and one with the hxdef-builder... the hxdef-builder has several errors with i was not able to fix completely... the delphi-building is no prob but the c-driver doesn't get compled  must be a error in one of the macro-files i guess... will see.... my prob is that the ddk_xp.iso isn't available anymore on filemirrors and i dind't find it anywhere else for download... only dead links... i downloaded the ddk_xp.iso three times before but all have been corruptet so i wasn't able to install it... if somebody could be so patient to send, up, or tell me where to get it i would be very appreciated and thankfull!!! Yeah same prob here ! cant find it anywhere !
Intox
Nov 27 2004, 10:40 PM
why not changing all the variables names ? you're sure to have an undetect exe... no ?
kinkey_wizard
Nov 28 2004, 12:21 AM
QUOTE(Intox @ Nov 28 2004, 12:40 AM) why not changing all the variables names ? you're sure to have an undetect exe... no ? No... Rarely AVs use variables names in their signs... It would be too easy... :] Moreover I think that with variables names the sign could change with a different configuration of the server, and at the begining the signs shouldn't change if you want to identify the RAT...
JuVeNiLe
Jan 1 2005, 12:53 AM
XP DDK (filemirrors.com -> xp_ddk.iso) broken link? i search this tool, or help
JuVeNiLe
Jan 1 2005, 03:34 AM
its all ok, sry .d
ninar12
Jan 4 2005, 05:48 PM
first of all take out that backdoor from that scource
then u should do it like in that tut
then use some packer and edit that file
code graves could help u
changeing that entirpoit is next step
phaeton
Jan 5 2005, 03:35 PM
Could you specify what you mean by the backdoor? (the built in backdoor by hxdef?)
Also, you need to change the references to the table names from the INI now, make sure you update your ini accordingly, or you can just compile some specific settings also to change the signature of the file...
ninar12
Jan 6 2005, 09:53 PM
yeah i deleted that build in backdoor (4 antirootkitdetektortrick) then i changed that switches (e.g. -install) renamed the prozedurnames some little code manipulation
build it -> works
then edit my .exe -- added some tables,made an other entrypoint,used code caves 2 jump
checked it -> works
uploaded it 2 an scan site ->undetected used 2 diffrent rootkitdetector -> could not found it
yeah thats all
isnt life easy?
Phil
Jan 14 2005, 12:56 PM
Xion
Jan 15 2005, 02:03 AM
all link for hxdef-build are dead, do you have the hxdef-builder ???
KillerTom
Jan 30 2005, 09:42 AM
i have a new link for hxdef-builder LinkMfG KillerTom
otcem
Jan 30 2005, 11:13 AM
where can i get xp_ddk.iso?
Dubby
Jan 30 2005, 02:24 PM
@KillerTom: Link not working.: "Angelfire does not allow direct linking from offsite, non-Angelfire pages, to files hosted on Angelfire."
Titus
Jan 30 2005, 03:47 PM
@otcem
h*$p://shelek.tmf.ru/archive/ddk/DDK_XP.ISO
XtrA
Jan 31 2005, 01:40 AM
@ Killer Tom
"The page you are attempting to access has been removed because it violated Angelfire's Terms of Service."
otcem
Jan 31 2005, 12:12 PM
QUOTE(Titus @ Jan 30 2005, 03:47 PM) @otcem h*$p://shelek.tmf.ru/archive/ddk/DDK_XP.ISO The only thing i was getting was 404's when i googled it! Thanks Titus
TheX
Feb 7 2005, 11:15 AM
Could anyone post a working link for the hxdef builder cause they're all dead!
passi
Feb 10 2005, 05:28 PM
Yeah anyone please upload the builder again! And this time please attach it and don't upload it to webpsace. Thanks
tibbar
Feb 12 2005, 12:05 AM
QUOTE(Titus @ Jan 30 2005, 03:47 PM) @otcem h*$p://shelek.tmf.ru/archive/ddk/DDK_XP.ISO DDK is only available from MS website by ordering a cd. This is bordering on a warez link. Also note that you really should be building drivers with latest DDK which is DDK Server 2003.
nicolas9510
Feb 12 2005, 12:12 AM
hmmm i have the other ddk when did ddk 2003 come out? still only on ms site? stupid ms
TheX
Feb 12 2005, 12:02 PM
The problem is that we don't need the ddk but the hxdef builder
tibbar
Feb 13 2005, 09:31 AM
building hxdef is very simple... from a ddk free build environment you type build... and then you load up delphi and compile the userland part.
you really dont need a "hxdef builder".
TheX
Feb 13 2005, 01:55 PM
yes but unfortunately the avs detect hxdef when its compiled with the delphi trail no matter what you change in the code and thats why i want the hxdef builder
cowsonfire
Feb 14 2005, 10:54 AM
h**p://rapidshare.de/files-en/599195/hxdef-builder-3.rar.html
OleaSTeR
Feb 14 2005, 10:58 AM
thanks you cowsonfire, your link working fine
TheX
Feb 14 2005, 06:22 PM
yeah thanks for the link cowsonfire u helped me a lot!
tibbar
Feb 14 2005, 10:43 PM
lol i can't believe it...a n00bs hxdef building tool...how sad!
this wont help u stay undetected, you need to modify the source code for that.
Blade
Feb 20 2005, 09:28 PM
okay i modded the source, but where to put the src files in the "hxdef-builder-3 dir"
thanks for hints
my src files are in a dir called src
Dubby
Feb 21 2005, 12:07 AM
hxdef-builder is a tool to complie hxdef in one easy step rather than compiling everything step by step liek phaeton explains on page one. nonetheless his way is stil working and as there is no valid link to hxdef builder atm,. you will need to compile with Delpfi and DDK and stuff like phaeton explained.
TheX
Feb 23 2005, 01:54 PM
The only problem with the delphi trail is that it adds some kind of code to the exe and the avs detect this no matter what u change but my version is now undetected and i compiled it with the hxdef builder and @ tibbar no one said that this tool is able to make hxdef undetected ... .
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
|