2007.03.14
Just another DDoS story - One Person's Perspective by Paul Laudanski
"... Around the middle of February 2007, CastleCops itself became the target of a large scale DDoS. Not new to this kind of attack, it is the first time CastleCops experienced such a large throughput at nearly 1Gbit/s ..."
2007.03.09
Andy Manchesta added catchme into SDFix tool.
2007.02.21
New version of catchme with Windows Vista support released.
Catchme has been integrated with combofix developed by sUBs. Keep up the good fight sUBs !.
2007.01.20
After over a month of fight my web page is up and running.
Thank you Paul Vixie and ISC, Matt Jonkman, guys from register.com, MR Team and everyone who helped me.
Special thanks to Paul Laudanski who won this battle.
2006.12.06
I developed sample rootkit "test.sys" which hides its file from all public rootkit detectors:
BlackLight Sophos ARK RootkitRevealer IceSword DarkSpy SVV ... GMER Rootkit doesn't create hooks ( SSDT, IRP, SYSENTER, IDT, inline, FSF ) and its modifications are not visible.
You can see it in action in these movies: test.wmv, test2.wmv ( 0.9MB, 0.7MB Windows Media Video 9 codec ).
The detection of this type of rootkit will be added into the next version.
You can scan the system for rootkits using GMER. Run gmer.exe, select Rootkit tab and click the "Scan" button.
If you don't know how to interpret the output, please Save the log and send it to my email address. Warning ! Please, do not select the "Show all" checkbox during the scan.
Question:
How to install the GMER software ?
Answer:
Just run gmer.exe. All required files will be copied to the system during the first lanuch.
Question:
My computer is infected and GMER won't start:
Answer:
Try to rename gmer.exe to test.exe and click test.exe.
Question:
How do I remove the Rustock rootkit ?
Answer:
When GMER detects hidden service click "Delete the service" and answer YES to all questions.
Question:
How do I show all NTFS Streams ?
Answer:
On the "Rootkit Tab" select only: Files + ADS + Show all options and then click the Scan button.
Question:
Can I launch GMER in Safe Mode ?
Answer:
Yes, you can launch GMER in Safe Mode, however rootkits which doesn't work in Safe Mode won't be detected.
Question:
I am confused as to use delete or disable the hidden "service".
Answer:
Sometimes "delete the service" option wont work because the rootkit protects its service. So, in such case use: 1) "disable the service", 2) reboot your machine, and 3) "delete the service".