Forums: Rootkits Are **** - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Rootkits Are ****

#1 User is offline   Nap 

  • Private
  • Icon
  • Group: Members
  • Posts: 6
  • Joined: 07-September 03

Posted 31 October 2004 - 04:16 AM

Hi
somebody know a good anti rootkit detector ??
i google and found

Rootkit Detector Profesional 2004 v0.62
Rootkit Detector Profesional 2004
Programmed by Andres Tarasco Acuna
Copyright © 2004 - 3wdesign Security
Url: http://www.3wdesign.es

very good program and it founds a rootkit on my remote box but if i stops the service from the rootkit it is allwaystill hide (rootkits-prozess, service and regkey entries)

look @ results

[code]. .. ...: Rootkit Detector Profesional 2004 v0.62 :... .. .
Rootkit Detector Profesional 2004
Programmed by Andres Tarasco Acuna
Copyright © 2004 - 3wdesign Security
Url: http://www.3wdesign.es


-Gathering Service list Information... ( Found: 256 services )
-Gathering process List Information... ( Found: 32 process )
-Searching for Hidden process Handles. ( Found: 0 Hidden Process )
-Checking Visible Process.............
c:\winnt\system32\smss.exe
c:\winnt\system32\csrss.exe
c:\winnt\system32\winlogon.exe
c:\winnt\system32\lsass.exe
c:\winnt\system32\dllhost.exe
c:\winnt\system32\termsrv.exe
c:\winnt\system32\svchost.exe
c:\winnt\system32\msdtc.exe
c:\progra~1\navnt\vptray.exe
c:\winnt\system32\svchost.exe
c:\imail\iwebcal.exe
c:\imail\iwebmsg.exe
c:\progra~1\micros~3\mssql\binn\sqlservr.exe
c:\program files\persits software\aspemail\bin\emailagent.exe
c:\imail\pop3d32.exe
c:\winnt\system32\mstask.exe
c:\imail\smtpd32.exe
c:\winnt\system32\wbem\winmgmt.exe
c:\winnt\system32\inetsrv\inetinfo.exe
c:\program files\navnt\rtvscan.exe
c:\winnt\system32\msgsys.exe
c:\winnt\system32\dllhost.exe
c:\progra~1\micros~3\mssql\binn\sqlagent.exe
c:\winnt\system32\winlogon.exe
c:\winnt\explorer.exe
c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
c:\rkdetector.exe
c:\winnt\system32\csrss.exe
c:\winnt\system32\cmd.exe
c:\winnt\system32\rdpclip.exe
-Searching again for Hidden Services..
-Gathering Service list Information... ( Found: 0 Hidden Services)
-Searching for wrong Service Paths.... ( Found: 24 wrong Services )
-------------------------------------------------------------------------------
*SV: alerter (alerter) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: AppMgmt (Application Management) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Browser (Computer Browser) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Dhcp (DHCP Client) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: dmserver (Logical Disk Manager) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Dnscache (DNS Client) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Eventlog (Event Log) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: HackerDefenderDrv084 (HackerDefenderDrv084) PATH: c:\winnt\system32\temps\tmp\hxdefdrv.sys
-------------------------------------------------------------------------------
*SV: lanmanserver (Server) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: lanmanworkstation (Workstation) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: LmHosts (TCP/IP NetBIOS Helper Service) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Messenger (Messenger) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: PlugPlay (Plug and Play) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: ProtectedStorage (Protected Storage) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: seclogon (RunAs Service) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: TrkSvr (Distributed Link Tracking Server) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: TrkWks (Distributed Link Tracking Client) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: W32Time (Windows Time) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
*SV: Wmi (Windows Management Instrumentation Driver Extensions) PATH: c:\winnt\system32\services.exe
-------------------------------------------------------------------------------
-Searching for Rootkit Modules........ ( Found: 0 Suspicious modules )
-Trying to detect hxdef with TCP data..( Found: 0 running rootkits)
-Searching for hxdef hooks............ ( Found: 1 running rootkits)
-------------------------------------------------------------------------------
*ROOTKIT HACKER DEFENDER >= v0.82 FOUND. Path not available

i stops the rootkit service but i dont come in the path (c:\winnt\system32\temps\tmp) Win2k says "nothing found"

i run norton anti viru but it found nothing
0

#2 User is offline   Reckless 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 103
  • Joined: 31-January 04

Posted 31 October 2004 - 12:18 PM

Yes, Hackerdefender makes the folder virtually non-existent. That is why c:\winnt\system32\temps\tmp couldn't be found. If the folder "dosen't exist".. then its quite obvious the a/v scanner cannot scan it ... Unless the hexdef.ini file or the client backdoor is detected by an antivirus, the rest of the files can't be found..

there was a tool on rootkit.com , i think it was called "WISE" .. not too sure.. cannnot verify as the site is down rite now..

Rootkitdetector 0.62 <-- that was posted on gso, but i think its in the "Member only" file download section ..

The best solution would be to reformat...
0

#3 User is offline   r3L4x 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 168
  • Joined: 13-August 03

Posted 31 October 2004 - 12:37 PM

boot into dos and take it out. Or a live distro of linux (knoppix)
0

#4 User is offline   Bombers 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 118
  • Joined: 16-August 03

Posted 31 October 2004 - 10:20 PM

I think those detectors must be banned from the internet... a rootkit is a method to hide stuff from other processes or users... This never ever may be broke by antything! It's a techonology
0

#5 User is offline   ice_cold45 

  • Private
  • Icon
  • Group: Members
  • Posts: 6
  • Joined: 12-October 04

Posted 01 November 2004 - 03:36 AM

Bombers, on Nov 1 2004, 12:20 PM, said:

I think those detectors must be banned from the internet... a rootkit is a method to hide stuff from other processes or users... This never ever may be broke by antything! It's a techonology

lol they must be :D
anyway as long as we boot in windows i think you are rightt they may never be broken
but we could add a few lines to the autoexec.bat to make sure our the system is clean like dir /s hxdef*.*
0

#6 User is offline   tnp 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 38
  • Joined: 17-February 04

Posted 01 November 2004 - 03:57 AM

isn't it able to undetect rootkit with morphine or a simple hexeditor?
0

#7 User is offline   Bombers 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 118
  • Joined: 16-August 03

Posted 01 November 2004 - 12:07 PM

the detectors will always see the hooked api's.. you can try to hide common rootkit detectors in your rootkit configuration... that's what i do :)
0

#8 Guest_ScriptGod_*

  • Group: Guests

Posted 02 November 2004 - 06:14 AM

A rootkit that is really undetectable is impossible, because somewhere in the kernel this hidden stuff must exist or it can't be used be root processes or somethink like that. The user mode rootkits like hxdef etc. are really easy to bypass just reload your common dlls or go to kernel mode. (There is also one possibillity for hxdef. hxdef only hooks APIs like CreateFile but not NtCreateFile directly so you can use this APIs and see everythink).

The hidden threads of the hidden process must exist in the kernel in a list are windows won't run this anymore. You can enumerate this list to see hidden threads/processes. You can use alternative NTFS drivers to see hidden files...

The rootkit detectors development is more sophisticated than the rootkits development. The detectors can detect more than there is implemented in rootkits at the moment.

So you can make it hard to find the stuff but not impossible
0

#9 User is offline   strych_nine 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 71
  • Joined: 08-September 04

Posted 02 November 2004 - 06:45 AM

can you tell us the names of the files that needs to be hidden?
0

#10 Guest_blowspark_*

  • Group: Guests

Posted 02 November 2004 - 12:15 PM

HI,

HXD cant hide Processes through Netbios .....

Connect to remote Box with Dameware ... search the Services ... and remember the name of tHe HXD exe file ...

Then use a simple FTP server ... (for those things i use serv-u 2.5 ) and name the exe of the ftp server the same as the rootkit exe ...
Then execute.... and connect ..... youll see all the hidden dirs and so on ....

Now its easy to uninstall all the hidden services and the rootkit ..
0

#11 User is offline   jubbly 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 89
  • Joined: 08-September 03

Posted 02 November 2004 - 02:18 PM

winrar gives good browsing of a hdd to remove files/folders that are hidden but I would take r3L4x's advice and use a live linux cd to boot from and remove it that way.
0

#12 Guest_Kendox_*

  • Group: Guests

Posted 12 November 2004 - 12:15 AM

also you can test the Security Taskmanager (you can find it easy with google)

he shows you hidden prozesses.

mfg
Memento
0

#13 Guest_speCt0R_*

  • Group: Guests

Posted 12 November 2004 - 08:38 PM

Open Ports v1.2 @ http://rootkit.host.sk

Detectcon by Kd-Team @ http://www.kd-team.com

enjoy ^^
0

#14 User is offline   Serhat 

  • Second Lieutenant
  • Icon
  • Group: Members
  • Posts: 803
  • Joined: 13-January 04

Posted 14 November 2004 - 12:08 AM

I deleted somthing like this once..
just by using my cygwin installation.. SSH'ing to it.. and use rm filename .. pretty weird..
I think it somehow hooks some api calls.. and returns nothing back when it got the path of the rootkit?

Serhat
0

#15 User is offline   teamcrunk2k5 

  • Private
  • Icon
  • Group: Members
  • Posts: 4
  • Joined: 02-November 04

Post icon  Posted 14 November 2004 - 11:10 AM

Sorry to ask this question, but i was just woundering, does anyone know any good sites for root kits or autoroot kits, and how would i go about rooting webdev? i've tried sql, i would like to know other ways and where i can get rootkits or autoroot kits or information about other rooting ways thanks, from a noobie<---------
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting