Rootkit?

Discussion in 'other anti-malware software' started by Rilla927, Sep 28, 2005.

Thread Status:
Not open for further replies.
  1. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    I have some questions about Rootkits. So far I have never found any info stating Rootkits do anything positive to our computers. If these Rootkits are so malicious to our systems; why are these people allowed to develop them without getting in trouble?

    The only positive I do see, is to test our security programs for holes. I don't have the knowledge most people have at this forum, so I thought this would be the best place to ask.

    Thanks for all your comments! :D
     
  2. Ilya Rabinovich

    Ilya Rabinovich Developer

    Joined:
    Sep 13, 2005
    Posts:
    1,543
    The best place is <snip>


    edited to remove link to malware development site - Detox
     
    Last edited by a moderator: Sep 29, 2005
  3. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    Sorry but the certificate for <snip> could not be validated. Maybe I'm in the wrong section of the forum, but surely Rootkits can be discussed somewhere in this forum.

    edited to remove link to malware development site - Detox
     
    Last edited by a moderator: Sep 29, 2005
  4. r00+3r

    r00+3r Guest

    Your in the right section of the forum, you just have to wait for the other rootkit experts here to find your thread.

    But to try to answer your first question, why are rootkits allowed to be developed? Well, I guess it's something like freedom of speech. They are allowed to develop these things because on the site they claim they're only for testing purposes, or something along those lines.

    Also I think it's good business for the anti-malware companies if these guys stay in business. Really, on at least one level sites like rootkit.com are helpful because they openly discuss these rootkit projects, so we can see what's going on in SOME of the latest developments with rootkits. Would you rather these things remain completely secret?

    If your looking for software to detect rootkits, UnHackme, Blacklight beta & RootkitRevealer are all some good rootkit detectors. There are others too, but I am very cautious myself about using or downloading any of them, because you never know what you might be getting.
     
  5. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    I was just trying to understand more about them, thats all. I read somewhere about a program called Icesword that is supposedly able to detect HD, Copycat. :)
     
  6. JRCATES

    JRCATES Registered Member

    Joined:
    Apr 7, 2005
    Posts:
    1,205
    Location:
    USA
    Icesword supposedly can detect the new "brilliant" version of HD which makes it different from the others......but UnHackMe can also detect all other versions of HD (although not the latest "brilliant version as of yet). Not sure about Blacklight (although I believe that it is similar to UnHackMe, maybe just not quite as advanced)......
     
  7. nick s

    nick s Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    1,430
    The current IceSword, 1.12, cannot detect the current HD-Brilliant, but Icesword 1.14 is due to be released...and the cat-and-mouse game will go on. A short but interesting interview published yesterday: Windows rootkits come of age.

    Nick
     
  8. controler

    controler Guest

    I could be wrong since I have not used rootkit revealer for a while now but I don't think it has any cleaning ability.

    I can say The present version of IceSword does have many more features then just detection and it a very simple program to use. Yes it does have a quick button that takes you to your registry, which is not that hard to do anyway LOL

    BUT it has a powerful process viewer, kernel viewer and process and modual killer.

    I guess I am looking forward to the next release. I think I will include a screenshot later.

    controler
     
  9. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    A screenshot sounds good Controler! I'd like to see it myself. ;)
     
  10. controler

    controler Guest

    Thie does not show the lower options.
     

    Attached Files:

  11. controler

    controler Guest

    Guess the size limit , limited me from posting a better shot.
     
  12. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    Awsome controler! Where did you find it? Is it FREE?
     
  13. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
    There is so much malware that it takes a lot of specialized programs to secure one's system.
    Having said that, is there a single person here that has been infected or attacked by a rootkit?

    I sometimes wonder if we are not paranoid. Sure it is better to err on the side of safety. However, I know a lot of people who have and use computers, and probably not one could define a rootkit, or has been infected by a rootkit.

    Jerry
     
  14. StevieO

    StevieO Guest

  15. controler

    controler Guest

    Jerry M


    Yes I have been infected intentionaly but not sure if I ever had been by accident. ( except maybe rootkit.com )
    BoOrfice was one of the fisrt rootkits I hear.
    I think the current fear is some are being used in maleware.

    I don't know if the link is still there but a while back I was browsing rootkit.com
    and was reading a blog there. From that blog I linked to a users site to download a program. I was hit by a driveby. I think this had small rootkit attached.
    Drivebys are nothing new but most in the past and still today use browser weakness.
     
  16. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
    controler,
    Thabnks for the reply.

    Regards,
    Jerry
     
  17. Arup

    Arup Guest

    Rilla 927,

    Samurai also removes existing rootkits as well as prevent new ones from being instaled.
     
  18. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    @StevieO

    Thanks for link!

    @Arup

    I knew it had something for a rootkit, but didn't know exactly what. Wow, that's a trip! I am so glad you told me that. I sure hope those two programs (Samurai and Harden-It) work on my computer. It's a newer AMD 64 FX-53.

    That would make me a Happy Camper! :D
     
  19. Arup

    Arup Guest

    Rilla,

    They will fly on the AMD, no fears.
     
  20. Rilla927

    Rilla927 Registered Member

    Joined:
    May 12, 2005
    Posts:
    1,742
    Arup, you made me feel even better!:cool:

    Thanks so much.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.