Another new anti Rootkit and hook analyzer

Discussion in 'other anti-trojan software' started by tuatara, Nov 14, 2005.

Thread Status:
Not open for further replies.
  1. Rodehard

    Rodehard Registered Member

    Joined:
    Feb 20, 2004
    Posts:
    91
    Which is why I hang around these hallowed halls.
     
  2. But what has this to do with the Knights Templers?

    DO you think they actualy sailed to the United States during the 1300's?
    Do you think they sailed there because the Catholic Church was hunting them down like dogs?
    Listen carefully!!!!!!!!!!!!

    Do you think they carved the Kensinton Ruinstone?
    If so ,,,,,, Isn't it coded?

    Sorry I realy could not help it. That is who I am. Think coded in a non programing term LOL

    Just me '
    Mr Bruce
     
  3. controler

    controler Guest

    Oh yea Pete

    Let the battles start. LOL

    Pete don't be misslead by Polititions.

    Don't let them take our constitutuin away!!!!!!!!!!!!!!!!!

    Or I will kick their a$$

    Bruce
     
  4. korb

    korb Guest

  5. BlueZannetti

    BlueZannetti Registered Member

    Joined:
    Oct 19, 2003
    Posts:
    6,590
    That is the message you will see if that file is not present, have you verified that this file is present (C:\WINDOWS\SYSTEM32)? I'd try a reinstallation as a first measure and make sure you're allowing file writes to that folder.

    Blue
     
  6. korb

    korb Guest

    haha, thanks BlueZannetti. dunno why what happen. i search and locate the file rspsc.sys in sys32.i uninstall it and did a reinstall it fine now.i wonder if it is because i re-enable dcom services which i normally turn off unless some software do require it to turn on?

    http://picshosted.com/v/3832/ScreenShot005.jpg
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    This tool installs a driver named rspsc.sys, it´s not a standard Windows driver, I got the same message when running this tool from a USB stick. ;)
     
  8. spy1

    spy1 Registered Member

    Joined:
    Dec 29, 2002
    Posts:
    3,139
    Location:
    Clover, SC
    I assume that it has to install a driver to work, wouldn't you say?

    A screenie of the Jotti scan is included. I don't believe the "Status" warning is anything to be concerned about, given the fact that none of the scanners found anything hinky about the file. Pete
     

    Attached Files:

  9. crusader_

    crusader_ Guest

    Anybody experienced a "viexca2k.sys" module described as "InfoExpress Intruder"? Comes from CyberArmor, a personal firewall application.

    Cheers - Thomas
     
  10. controler

    controler Guest

    Thomas

    How appropriate a nick name. crusader ;)

    Appears you have studied the knights templers?
     
  11. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
  12. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    Rootkits are kernel hooks, and vice-versa; unless you are using the set of semantics that say a rootkit isn't a "rootkit" unless it's malicious.
     
    Last edited: Feb 8, 2006
  13. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
    Or, not.
    A rootkit is not "a kernel hook". A kernel hook is a kernel hook. A rootkit is a tool (usually used by an intruder) that can access computer's files and data, and that can make itself invisible by the process/file analyzing tools and commands (by replacing them, or by replacing kernel functions).
     
  14. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    Yeah, you're right. I must have been caught in yet another of my fits of sleep-deprived lightheadedness. Mark Russinovich and the founder of rootkit.com use similar definitions, respectively:

     
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Eventhough I think it´s a nice tool, I can´t rely on it since I´ve read on Kareldjag´s blog that it could not spot Hacker Defender, and perhaps it might also not be able to spot other rootkits as well. :rolleyes:
     
  16. nameless

    nameless Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    1,233
    I wonder if that's one of those cases where renaming the EXE/SYS file would get around it.
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Btw, as you might know, IceSword is also capable of showing these hooks (and more) plus a lot of people seem to rely on Icesword at the moment. So far IS has not showed me any suspicious processes or hooks. :shifty:
     
  18. No User Name

    No User Name Registered Member

    Joined:
    Feb 28, 2006
    Posts:
    13
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.