吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 4691|回复: 1
收起左侧

RkUnhooker2.0_src

[复制链接]
zzage 发表于 2008-9-30 12:20
Service Descriptor Table State Monitoring/Restoring

Hidden Processes Detector (ultimate, powered by Stealth Engine)

Hidden Drivers Detector (powerful, powered by DnG Core)

System Call Hook Detection

Ability to Generate Report



Note: there are small amount of BSOD's was reported when used "Unhook" functions



RkU contains super code that can be used only if "Run Always" is enabled



RkU requires Administrator privileges to run and work.



When "Run Always" is enabled RkU will works in Safe Mode.





SSDT Hooks Detector/Restorer

Hidden Processes Detector

Hidden Drivers Detector

Report





Here description of each of them.



SSDT Hooks Detector/Restorer



To speak user friendly - System Service Descriptor Table is an place where system stores pointers on the main system functions. Some kernel mode rootkits usually using the following technic - replace actual address of function in this table on address of their own handler-function. Some commercial software also uses this technic, for example Panda Antivirus hooks NtTerminateProcess function to prevent terminating of antivirus executables. Agnitum Outpost uses the same and additionally hooks NtWriteVirtualMemory to protect users from malware technics known as code injection. Alcohol\Daemon Tools CD emulation software hooks registry-related functions to defeat DRM.



RkU can show you actual state of SSDT, show which functions (they also called services in MS terminology) are hooked and unhook them. When RkU makes unhook its replace hooked addresses with original.



Hidden Processes Detector



Main purpose of rootkits - hide itself from user. Some of rootkits hides its executables from API, so standard processes monitoring tools like Task Manager, Process Explorer can't see them. RkU uses ultimate processes detection engine that shows you everything.



Hidden Drivers Detector



Rootkits also hides their own drivers to prevent user from removing them. RkU powered by special core that can detect hidden drivers.



Report



When you are asking for help it is very useful to get report of your system state. This page gives you that possibility.
12.JPG

RkUnhooker2[1].0_src.zip

71 KB, 下载次数: 27, 下载积分: 吾爱币 -1 CB

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

Hmily 发表于 2008-9-30 12:55
RUK也开源,很强大的反黑工具!
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-4-25 12:37

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表