Accedi per seguire   
Seguaci 0
Kuma

Mcafee Antirootkit

4 messaggi in questa discussione

McAfee: rootkit +700% rispetto al 2005

Sono in pesante aumento le minacce derivanti dai rootkit, rispetto al primo trimestre dell’anno scorso, si è registrato un aumento del 700%.

A fornirci questi dati è il rapporto dei laboratori di ricerca McAfee, secondo i quali i rootkit stanno diventando sempre più complessi e largamente utilizzati..........

McAfee Rootkit Detective Beta

McAfee Rootkit Detective Beta is a program designed and developed by McAfee Avert Labs to proactively detect and clean rootkits that are running on the system.

McAfee Rootkit Detective should only be used by knowledgeable individuals at the direction of, and with the support of, a representative from McAfee Avert Labs or McAfee Technical Support. Improper usage of this tool could result in damage to your applications or operating system.

Download it

The Rootkit Detective Beta can be downloaded here.

  • Designed to proactively detect the system objects like processes, files and registry that are hidden to the user.
  • Provides information about all running processes in the system.
  • Provides information about various system hooks like SSDT(System Service Descriptor Table) hooks, user/kernel IAT/EAT(Import/Export Address Table) hooks.
  • Allows the user to clean/remove the malicious objects from the system by renaming/deleting the hidden files/registry.
  • Allows the user to terminate the malicious processes.
  • Users can submit samples using the submission feature present in the tool.
  • Users can also collect the samples manually after renaming them and submit to stinger@avertlabs.com for further analysis.

Supported Operating Systems

  • Windows XP Home Edition with SP2
  • Windows XP Professional Edition with SP2
  • Windows 2000 with SP4
  • Windows 2000 Server
  • Windows 2003 Server SP1

foto001qe5.jpg

Known Issues

  1. This tool will detect registry entries pertaining to McAfee Entercept Products if installed on your system.
  2. This tool will detect mfehidk.sys file pertaining to McAfee Antispyware Enterprise (Standalone) as a hooked service.
  3. This tool will detect IAT/EAT hooks in Windows 2000 SP4 system pointing to shim.dll.
  4. This tool will detect vsdatant.sys from Zone Alarm as hooked service for rootkit like behavior.
  5. This tool will detect Goback2k.sys as hooked service on system having Go Back software installed system for rootkit like behavior.
  6. This tool will detect fsndis5.sys as hooked service from F-Secure if F-Secure Internet Security Suite 2006 is installed on the system.
  7. This tool will detect klif.sys as hooked service from Kaspersky if Kaspersky Internet Security 2006 is installed on the system.
  8. This tool will detect FireTDS.sys as hooked service from McAfee if McAfee Desktop Firewall is installed on the system.
  9. This tool will detect Hidsys.sys as hooked service from McAfee if McAfee Host Intrusion Prevention is installed on the system.
  10. This tool will detect Service Name ZwCreateThread when VSE product is installed on the system.
  11. This tool will not run on Windows 2000 platforms when Kaspersky Internet Security 2006 is installed.
  12. This tool will detect many IAT/EAT hooks and SSDT hooks of legitimate applications.

NOTE: Some or all of the above issues may be addressed in the future releases.

HOMEPAGE

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

ciao Kuma :P

nn ho capito come funziona questo programmino...potresti illustrarmi meglio? :)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Ciao,

da quello che ho capito, devi solo cliccare su SCAN...

(puoi comunque anche modificare le opzioni, ma penso che quelle predefinite siano sufficienti)

l'ho provato sul mio Pc, ma non essendo infetto non mi compare nulla :)

di più non saprei dirti.... servirebbe qualcuno che sia infetto da qualche rootkit per avere più risposte

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

eh già... fortunatamente nn appare niente neanke a me... grazie Kuma :)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti
Accedi per seguire   
Seguaci 0