Rootkit Unhooker v3.0 Beta 1 - 2006-10-01

Discussion in 'other security issues & news' started by Tommy, Oct 1, 2006.

Thread Status:
Not open for further replies.
  1. Tommy

    Tommy Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    1,169
    Location:
    Buenos Aires - Munic
    Whats's new in version 3.00 build 80/290 code named "Splicer" Beta 1 (01.10.2006)

    added: hidden files detection (copying, content erasing)
    added: ability to restore hooked system call instruction
    added: kernel/user mode code hooks detection and unhooking
    added: new method for processes scanning engine
    added: multi-language support
    added: processes dumping (with fix)
    improved: system call detection
    fixed: many bugs in driver and application

    Download English Version:
    http://www.rku.xell.ru/?l=e&a=dl

    The Tab 'Code Hooks Detector' crashes in my case the application.
     
    Last edited: Oct 1, 2006
  2. starfish_001

    starfish_001 Registered Member

    Joined:
    Jan 31, 2005
    Posts:
    1,041
    Thanks looks interesting

    Do you have any screen caps? How does it compare to icesword?
     
  3. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Here`s one:-
     

    Attached Files:

  4. starfish_001

    starfish_001 Registered Member

    Joined:
    Jan 31, 2005
    Posts:
    1,041
    Thanks Stem
     
  5. Longboard

    Longboard Registered Member

    Joined:
    Oct 2, 2004
    Posts:
    3,187
    Location:
    Sydney, Australia
    What does "no NTFS" support mean?

    Only operational on FAT32 file system?
     
  6. Tommy

    Tommy Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    1,169
    Location:
    Buenos Aires - Munic
    I think the basic functions like Hook and Hidden detector work also on NFTS, but features like 'Code Hooks Detector' not. Correct me when i am wrong folks.
     
  7. SirMalware

    SirMalware Registered Member

    Joined:
    Jun 6, 2006
    Posts:
    133
    The quote below is from the program's author:

    Current version of Rootkit Unhooker v3.0 is Beta 1. It not includes NTFS support. This feature will be available in Beta 2.
     
  8. Devil's Advocate

    Devil's Advocate Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    549
    I could be wrong, but the NTFS part probably refers to ADS.
     
  9. rvieler

    rvieler Registered Member

    Joined:
    Oct 17, 2006
    Posts:
    1
    The rootkitunhooker site no longer publishes the source code.
    Does anyone have an old copy?
    I am interested in restoring the SDT on a Windows 2003 OS.

    Thanks, Ric :)
     
Loading...
Thread Status:
Not open for further replies.