PDA

View Full Version : New Rootkit Detector Released


StevieO
November 14th, 2005, 12:24 PM
Rootkit V2 Detector BETA1 - FILESYSTEM ENGINE - This is an updated version of the previous Rootkit V0.62 Detector

From the DL README file


Author: Andres Tarasco Acuña

Rkdetector filesystem is an advanced rootkit detector software that includes
its own ntfs and FAT32 filesystem Driver.

This drivers allows rkdetector to perform the following tasks:

- Filesystem browser
- Rootkit detector (search for hidden files)
- ADS (alternate Data Streams) Scanner
- Wipe Disk (secure file deletion Dod Compliant Erase both file and mft entries)
- Data Recovery (recovery of deleted files)
- Registry browser (Raw registry files browser)
- Hidden registry key scanner (search for hidden keys/services)

NOT INCLUDED IN THIS BETA RELEASE:

- Export results
- Perform wipe /recovery with FAT32 filesystems.
- Search filter ( search for A/C/D/M file times)
- IAT analyzer / Patcher.
- Rootkits Patterns
- Ports monitor.
- Malware eliminator.

There is also available a private rkdetector v2.0 Filesystem console Edition edition that also includes:

- Console release
- perform Custom security checks.
- Xml /CSV results

Download here

http://translate.google.com/translate?u=http%3A%2F%2Fwww.shellsec.net%2F&langpair=es%7Cen&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools

Forum here

http://216.239.39.104/translate_c?hl=en&ie=UTF-8&oe=UTF-8&langpair=es%7Cen&u=http://foro.shellsec.net/index.php%3Fc%3D5&prev=/language_tools


StevieO

suv
November 14th, 2005, 02:20 PM
thanks steevo. System volume info is usually hidden correct? I also wondering about the "tracking log" and the "remote database"

http://img472.imageshack.us/img472/408/svi3kv.jpg (http://imageshack.us)

``--001100--``
November 16th, 2005, 04:08 AM
This could be a keeper!

Have been waiting for this for some time.
Developed by the writer of rkdetector 0.6

The 'mountain range data" file and "tracklog" file are nuisance files and crop up all over the place. seem not to be anything to be concerned about.

http://www.rkdetector.com/

controler
November 16th, 2005, 07:34 AM
Or http://www.rootkitdetector.com/

even

controler
November 16th, 2005, 07:48 AM
Not sure why but this is what I get when running this version.

PG blocked wmiprvse.exe from terminating mshta.exe

lotuseclat79
November 16th, 2005, 08:41 AM
rkdetector v2.0 beta support forum Here (http://216.239.39.104/translate_c?hl=en&ie=UTF-8&oe=UTF-8&langpair=es%7Cen&u=http://foro.shellsec.net/index.php%3Fc%3D5&prev=/language_tools).

-- Tom

T772
November 16th, 2005, 10:28 AM
Hi,

Why doea Mcafee still detect this as HKH-Keylog? There is no other info at McAfee on there site about this one - could it be a false postive??

I think its ok , but what do you guys think

T

T772
November 16th, 2005, 10:32 AM
-{ Quote: "Hi,

Why doea Mcafee still detect this as HKH-Keylog? There is no other info at McAfee on there site about this one - could it be a false postive??

I think its ok , but what do you guys think

T" }-
Updated, was a false postive

T