Author Topic: F-Secure Blacklight Rootkit Detector  (Read 2016 times)

0 Members and 1 Guest are viewing this topic.

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
F-Secure Blacklight Rootkit Detector
« on: January 14, 2006, 12:59:42 AM »
Has anyone had hands on experience with F-Secure's Blacklight? I would be interested in an appraisal of this piece of kit from someone who has used it in anger.

Quote
F-Secure BlackLight can detect and eliminate active rootkits from the computer. Traditional antivirus scanners can't detect active rootkits.
On a normal system F-Secure BlackLight does not confront the user with a long list of suspected objects. This makes F-Secure BlackLight useful even for non-technical users.
F-Secure BlackLight Rootkit Elimination Technology can be used in the background during normal system operation. Other available scanners require a reboot during scan or may produce false positives if the system is used during scanning.
Source: http://www.f-secure.com/blacklight/cure.shtml
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline Die Hard

  • LzD Fallen Heroes
  • Hero Member
  • *****
  • Posts: 972
  • The Northern Berserk
Re: F-Secure Blacklight Rootkit Detector
« Reply #1 on: January 30, 2006, 07:41:39 PM »
EtR :)

I have used it. It´s a great tool when looking for just rootkit installations.

Die Hard :)


I create and edit my posts in GS-NOTES

Offline JOSEPH

  • Blogging In 2006
  • Full Member
  • ***
  • Posts: 148
Re: F-Secure Blacklight Rootkit Detector
« Reply #2 on: January 30, 2006, 08:56:07 PM »
Eric the Red, Diehard

I'm currently undergoing some intensive study of some that are currently in circulation and practice.
Blacklight oddly is not made it to my table yet but i have read many encouraging reports from various forums on the results. I hope to become more familiar with those outcomes soon. I'll be sure to pass along any new notes and findings of interest as they become available from this end.

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5124
  • Half a bubble off plumb
Re: F-Secure Blacklight Rootkit Detector
« Reply #3 on: January 30, 2006, 09:00:55 PM »
IMO, BlackLight is the easiest to use, and it scans very quickly ...

RootkitRevealer from Sysinternals is another good one.

ahulett could tell you more about Mr Softie's Malicious Software Removal Tool.   :D

Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline JOSEPH

  • Blogging In 2006
  • Full Member
  • ***
  • Posts: 148
Re: F-Secure Blacklight Rootkit Detector
« Reply #4 on: January 31, 2006, 12:03:30 PM »
I agree with RootkitRevealer from Sysinternals is another good one. A sweep reveals how well embedded SSM is stationed as defense on my machines.

Found the ENGLISH version of Ice Sword for you guys in case you haven't seen it yet. Let's see some more opinions. SYSTEM SERVICE DESCRIPTOR TABLE is a section you will want to see also.

http://www.google.com/url?sa=D&q=http://www.xfocus.net/tools/200509/IceSword_en1.12.rar

I'm going to release some Trojan Simulators and also the Hide Folders & Files (hff.exe) to my units in examinations.
Not quite ready yet to drop in any virus in testing untill SYSTEM SAFETY MONITOR is been fully configured on my boxes.
I do however suggest you download and give this program a try. It's in it's final day of Beta today and will be tentitively scheduled for release commercially Feb14 Valentine's Day.
It's an intensive rules-based ALL process and ALL applications and services Live Monitor that intercepts any and all calls before they are responded to by Windows, this includes critical Registry Keys and subs! Looks very effective and in testing on my boxes is so far proved 100% security.
Personally i don't feel it gets any better than this for full protection but any comments will definitely warrant attention.

FINAL! BETA 559 DUE FOR RELEASE TODAY!

I might add in my defense testing i also employ a really effective and low hit on the systems live directory monitor.
The program itself is about 4 years old when it was beta which it seems to been left at and abandoned.
It automatically is hard coded to monitor the hosts file while it watches for changes in real time to any folder you set in it, (mine is System32). Only for Windows XP, 2000 and NT.
FILE CHANGE ALARM
Working in combo with SSM it's adds and indeed seals your security tight!

Here is another very good read when you find time:
http://www.security.org.sg/code/kproccheck.html

Offline JOSEPH

  • Blogging In 2006
  • Full Member
  • ***
  • Posts: 148
Re: F-Secure Blacklight Rootkit Detector
« Reply #5 on: March 01, 2006, 06:01:50 AM »
Quote
ahulett could tell you more about Mr Softie's Malicious Software Removal Tool.

Anyone familiarly close to those circles likely will mention that Strider's Ghostbuster is integrated into WindowsDefender maybe? Speculation only on my part but nonetheless i would assume a pretty good educated guess. I arrived at that from the fact that no where at the Microsoft discussion sites i visited is it offered at all for download beit demo or otherwise.

I kind of like this console one by Joanna of the polish persuasion and which is featured along with her articles at both http://www.rootkit.com and her own website http://invisiblethings.org
System Virginity Verifier

Ice Sword is another very effective product that's been introduced.

Offline JOSEPH

  • Blogging In 2006
  • Full Member
  • ***
  • Posts: 148
Re: F-Secure Blacklight Rootkit Detector
« Reply #6 on: March 01, 2006, 11:06:46 AM »
Another one. Second URL below displays your screenshots of the features. Very nice.

Oddly, sometime ago i had installed hhf, better know as Hide Files And Folders. With all the research materials at hand it was a simple choice to uninstall it since it's of no real use anyway being as the only user to this box.
What was discovered however and also might never would have found out probably, was that it never really uninstalled. While conducting my research in weeding out and tracing another stealth known as vanquish i accidently run upon ALL the files and folders of that program that were invisible to the windows system. Also a very pesty driver named FDCENT.sys that i uninstalled by conventional means refused to depart. It was but with this tool below that i was able to determine EXACT locations of the cloaked program and supporting dll's etc. RKDetector does an admirable job at "wiping" those hidden files discovered too. That is all except one dll that had a pretty tight grip and apparently was linked to the FDCENT service. Even Ice Sword didn't delete it. Wouldn't you know it, just to show how clever a sharp coder with an exceptional understanding of these matters can do, the .sys driver file though was deleted or so thought, and it wasn't immediate but it automatically re-created or restored again OR ELSE by virtue of the System File Protection microsoft employs, it was replaced. It was stamped under properties as SYSTEM. My guess is that, or the DLL re-spawns it. It's now been moved instead of delete for the further study it deserves. Very interesting adventure..................

http://www.rkdetector.com/
http://www.rkdetector.com/screenshots.html