avast!WEBforum
November 22, 2009, 01:35:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: avast! Home Edition - free for home non-commercial use!
 
   Home   Help Search Calendar Login Register  
Pages: [1] 2 3 4 5 6 ... 10   Go Down
  Print  
Author Topic: Beta version of avast! antirootkit tool (standalone)  (Read 47094 times)
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« on: March 07, 2008, 07:49:17 PM »

Hi guys,

as promised, here's the beta of the new avast! antirootkit tool. It was designed with simplicity in mind.

In most cases, it shouldn't find (report) anything. Smiley
It is very important to run the program with no other applications running though - otherwise, strange things may happen.


Known problems:
- the hidden services scan is not yet ideal (will be changed)
- on 64-bit systems, we have seen some strange false positives (a huge number of regkeys suddenly reported as hidden)

There'll probably be more bugs, but these are the two major outstanding issues.


Here's the download link: http://files.avast.com/files/beta/aswar.exe


Enjoy!
Vlk
Logged

If at first you don't succeed, then skydiving's not for you.
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #1 on: March 07, 2008, 07:53:19 PM »

Testing now...
Is it better to run it at Safe Mode?
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« Reply #2 on: March 07, 2008, 07:58:26 PM »

Testing now...
Is it better to run it at Safe Mode?

No. Smiley

The point is, the rootkit needs to be active for the program to work. Some rootkits don't load in SafeMode.
Logged

If at first you don't succeed, then skydiving's not for you.
RejZoR
avast! Evangelist
*****
Offline Offline

Gender: Male
Slovenia Slovenia

Posts: 5331


We are supersheep, resistance is futile!


WWW Personal Message (Offline)
« Reply #3 on: March 07, 2008, 08:00:30 PM »

Code:
avast! Antirootkit, version 0.9.2
Scan started: 7. marec 2008 21:53:19

Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] s1=771343423  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] s2=285507792  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] h0=1  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] p0="C:\Program Files\Alcohol Soft\Alcohol 52\"  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] h0=0  **HIDDEN**
Registry item [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] ujdew=(binary value)  **HIDDEN**

Scan finished: 7. marec 2008 21:56:44
Hidden files found: 0
Hidden registry items found: 7
Hidden processes found: 0
Hidden boot sectors found: 0


----------

It found this stuff on my PC. From what i know these are hidden entries from Alcohol 52% (and probably also 120%) virtual drive.
It also appears it can identify hidden but not dangerous entries (which user cannot delete, just check them).
« Last Edit: March 07, 2008, 08:02:25 PM by RejZoR » Logged


Member of Malware Research
My blog and new official webpage: http://www.rejzor.tk
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« Reply #4 on: March 07, 2008, 08:03:04 PM »

This is OK, that's as expected... (but it said "unharmful hidden items found", right?)
Logged

If at first you don't succeed, then skydiving's not for you.
essexboy
avast! Evangelist
*****
Offline Offline

Gender: Male
United Kingdom United Kingdom

Posts: 2640


Dragons by Sasha


WWW Personal Message (Offline)
« Reply #5 on: March 07, 2008, 08:08:26 PM »

Going to use it now on a possible bagle/beagle infection I will post the link later
Logged

Vista Ultimate
Windows 7
Avast
RejZoR
avast! Evangelist
*****
Offline Offline

Gender: Male
Slovenia Slovenia

Posts: 5331


We are supersheep, resistance is futile!


WWW Personal Message (Offline)
« Reply #6 on: March 07, 2008, 08:10:49 PM »

Yep, unharmful items found. Wouldn't it be better if these are shown only if users wants to (may be enabled in Scan Options menu).
This way regular users won't be scared if not necessary (they usually jump oh my god something was detected and start burning their PC and stuff). Just a hint.
Logged


Member of Malware Research
My blog and new official webpage: http://www.rejzor.tk
joaopr
Full Member
***
Offline Offline

Gender: Male
Posts: 145



Personal Message (Offline)
« Reply #7 on: March 07, 2008, 08:15:07 PM »

Yep, unharmful items found. Wouldn't it be better if these are shown only if users wants to (may be enabled in Scan Options menu).
This way regular users won't be scared if not necessary (they usually jump oh my god something was detected and start burning their PC and stuff). Just a hint.

Testing now too.
Thanks RejZoR !!! Grin
Logged
bob3160
avast! Evangelist
*****
Online Online

Gender: Male
United States United States

Posts: 12510


http://www.organdonor.gov/


WWW Personal Message (Online)
« Reply #8 on: March 07, 2008, 08:38:55 PM »

Nothing to report which is good news.

I guess the update check hasn't been activated yet Huh
Logged

HelpAlice: . . . . . . . . .  http://www.protopage.com/bob3160
My Webpage: . . . . . .   http://home.comcast.net/~bob03160/
MySharedFiles: . . . . .  http://home.comcast.net/~mysharedfiles/
HighlyRecommended:  http://tinyurl.com/2385hp
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« Reply #9 on: March 07, 2008, 08:53:24 PM »

I guess the update check hasn't been activated yet Huh

Correct. But this can be activated / implemented even without changing the program...

Thanks
Vlk
Logged

If at first you don't succeed, then skydiving's not for you.
sanctuary24
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 324


Personal Message (Offline)
« Reply #10 on: March 07, 2008, 08:54:22 PM »

a quick question, is this rootkit technology going to be the same as the rootkit module in Avast 4.8 and will it be an always active module like standard shield (ie background running)?
« Last Edit: March 07, 2008, 08:56:03 PM by sanctuary24 » Logged
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« Reply #11 on: March 07, 2008, 08:56:54 PM »

a quick question, is this rootkit technology going to be the same as the rootkit module in Avast 4.8 and will it be an always active module like standard shield

There's nothing like "always active antirootkit" (in the classical sense of word). If the rootkit is not yet active, it's not really a "rootkit" (i.e. can be detected using normal methods, e.g. by the Standard Shield).

So, to answer the question, this is the same technology that will be used in avast 4.8.
Logged

If at first you don't succeed, then skydiving's not for you.
sanctuary24
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 324


Personal Message (Offline)
« Reply #12 on: March 07, 2008, 09:24:35 PM »

so does that mean that while its inactive it will be picked up by other modules but if it is running the antirootkit module will catch it, sorry if this is wrongly interpreted as I'm not to understanding on these functions Embarrassed
Logged
joaopr
Full Member
***
Offline Offline

Gender: Male
Posts: 145



Personal Message (Offline)
« Reply #13 on: March 07, 2008, 09:27:11 PM »

Tested.
100% working.
Thanks.
Logged
Vlk
Global Moderator
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 9509


Please don't send me IM's. Email only. Thx.


WWW Personal Message (Offline)
« Reply #14 on: March 07, 2008, 09:38:40 PM »

so does that mean that while its inactive it will be picked up by other modules but if it is running the antirootkit module will catch it, sorry if this is wrongly interpreted as I'm not to understanding on these functions Embarrassed

Yes. A rootkit is tough to detect only if it is active. Before it activates, it can be detected as any other piece of malware (e.g. by a simple signature etc.). But once it activates, it masks itself - sometimes so well that it's virtually impossible to detect in all cases.

It's a cat'n'mouse game, really.
Logged

If at first you don't succeed, then skydiving's not for you.
Pages: [1] 2 3 4 5 6 ... 10   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.086 seconds with 18 queries.