Hi,
Basically I'm using Rootkit-Unhooker as my first Anti-Rootkit software, also beside Rku, Icesword & Gmer are great tools .
recently I was curious about terminating rku,
seems, there's no specific method for terminating RKU process ... ( regardless of that, it's possible but it's difficult :) ) . (Process Monitoring & such a like softwares could not termiate it ... )
I tried many tools with no success (Personally, I didn't try any programmatic solution till now) but I'm curious about this way ... .
It's interesting to note about other Anti-Rootkits (Kernel detective, Gmer, IceSword & many others) didn't use any self-protection mechanism & this is like a joke in case of a software in the field of system protection ...,These softwares could be terminated as simple as task manager could do this !
I want to get information about this technique (the technique that EP used in his software (RKU)) ... .
Any help & useful information would be appreciated .
thanks .
Basically I'm using Rootkit-Unhooker as my first Anti-Rootkit software, also beside Rku, Icesword & Gmer are great tools .
recently I was curious about terminating rku,
seems, there's no specific method for terminating RKU process ... ( regardless of that, it's possible but it's difficult :) ) . (Process Monitoring & such a like softwares could not termiate it ... )
I tried many tools with no success (Personally, I didn't try any programmatic solution till now) but I'm curious about this way ... .
It's interesting to note about other Anti-Rootkits (Kernel detective, Gmer, IceSword & many others) didn't use any self-protection mechanism & this is like a joke in case of a software in the field of system protection ...,These softwares could be terminated as simple as task manager could do this !
I want to get information about this technique (the technique that EP used in his software (RKU)) ... .
Any help & useful information would be appreciated .
thanks .
- Individuality