A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #4352  by bwfc1989
 Sat Jan 08, 2011 11:48 am
As part of a university final year project I am focusing on rootkits, I need two different kind of rootkits which can be used, all I can find through searching the internet is rootkit defences which is not what I need, I would be greatful if anyone could help me or know where I can find rootkit software.

Regards
 #4355  by Alex
 Sat Jan 08, 2011 12:59 pm
Hi,

Please visit this topic - Demo Rootkits.
 #4369  by Alex
 Sat Jan 08, 2011 7:58 pm
I don't know which one bwfc1989 is looking for, but now he can find here all of them.
 #4390  by spaceman
 Tue Jan 11, 2011 3:45 am
I agree with Frank, is there any reason not to add current rootkits like Rustock, TDL, Zeus, Black Energy, etc. to the Demo Rootkits topic? That way you have a consolidated list.
 #4395  by bwfc1989
 Tue Jan 11, 2011 1:33 pm
Where would I be able to get rustock.c or tdl4? The rootkits on the demo list how would they be installed? I need to run two at seperate occasions within a virtual machine
 #4398  by a_d_13
 Tue Jan 11, 2011 3:15 pm
frank_boldewin wrote:
Alex wrote:Hi,

Please visit this topic - Demo Rootkits.
why not using real rootkits like rustock.c or tdl4? ;)
Hello,

I have posted a topic with a set of real rootkits that can be used for testing. Most of them are old and easily detected and removed, but are good for testing any sort of antirootkit.

Thanks,
--AD