|
From: offtopic <offtopic@mail.ru>
Date: Thu May 13 2004 - 02:06:32 EDT
http://www.security.nnov.ru/search/document.asp?docid=6198
Rkdetect is a little anomaly detection tool which can find services hidden by generic Windows rootkits like Hacker Defender.
Tool very simply. It enumerates services on remote computer through WMI (user level) and Services Control Manager (kernel level), compare result and display difference. In this way we can find hidden services which usual used to start rootkit.
Rkdetect available here:
http://www.security.nnov.ru/files/rkdetect.zip
Tool consists from VBScript file rkdetect.vbs and sc.exe utility.
Usage:
cscript rkdetect.vbs <machine_name/ip>
Example:
C:\detector>cscript rkdetect.vbs 200.4.4.4 Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001.
Query services by WMI...
Possible rootkit found: HXD Service 100
C:\detector>
Thanks to 3APA3A for testing and hosting.
Thanks for your attention and sorry for my English.
GL.
_______________________________________________
This archive was generated by hypermail 2.1.8 : Thu May 13 2004 - 03:04:18 EDT |
Custom Search
|