Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


anti-rootkit

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking
View previous topic :: View next topic  
Author Message
johnnygg
Advanced Cheater
Reputation: 0

Joined: 20 Jan 2010
Posts: 51

PostPosted: Mon Jun 25, 2012 4:19 am    Post subject: anti-rootkit Reply with quote

hi,
this maybe asking a bit much, but anyone know where I can find information about editing a rootkit at run-time?


More specifically, I don't want to find the rootkit file and delete it/stop it from running--that's what my antivirus is for. Instead, I want to know if its possible to analyze/edit the rootkit process at run time.

For example, a child rootkit process is started by a mother-application to
A. report any access to mother-application memory to mother-application
B. hooking onto certain Windows APIs and blocking some inputs/function calls (SendInput(), keybd, etc).
Meanwhile, the mother-application monitors the rootkit, and if the rootkit goes down, it self terminates.
So I'm looking for info on how to get past this.

If this is beyond the scope of this forum, or I'm posting in the wrong area, or mods think I shouldn't be asking this question, then I'm sorry in advance, and feel free to remove the post/reword it however you like.

thanks

johnny
Back to top
View user's profile Send private message
Fresco
Grandmaster Cheater
Reputation: 4

Joined: 07 Nov 2010
Posts: 600

PostPosted: Mon Jun 25, 2012 4:26 pm    Post subject: Reply with quote

are you looking for a way to turn the rootkit app into a mother one, so it can handle himself without being watched by the mother app ?
is so, have you asked yourself, can the rootkit run without mother ?
i think not, the rootkit it's most likely a dll not exe
anyways, you can hack the mother app to let the rootkit run by himself.
you just need to find out in the mother app the functions that keeps the rootkit alive, isolate them, and create a new exe with the basic core.
just like crackers do with steam games, they have found that the minimum requirement is not steam.exe but a dll, they created an app like cheat engine to inject that dll into the process of the game, and voila the game works without steam.
the point is that it's an advanced thing, and you would probably fail in this.
if the mother app that controls the rootkit is the antivirus, then forget about it, it's an antivirus, you can disable it or tell it to make an exception tor that rootkit.
btw, is the mother that shuts down when an error occurs to the rootkit ? is that correct ?
if it's not that you want the rookit to be mother, then forget a said anything and clarify yourself.
Smile

_________________
... Fresco
Back to top
View user's profile Send private message
johnnygg
Advanced Cheater
Reputation: 0

Joined: 20 Jan 2010
Posts: 51

PostPosted: Tue Jun 26, 2012 12:46 am    Post subject: Reply with quote

well my problem is that I want to edit the mother app. However, the rootkit is preventing me from doing so >.> So I wanted to edit the rootkit at runtime (like with cheatengine); but its hooking all the tools I can use to modify it at runtime :/ ie. it can detect cheatengine binding to its process (as well as any other assembly/memory editors that I tried). So I'm wondering if there is something else I can do to edit the rootkit

I could just remove the rootkit completely, but then the motherapp doesn't work >.> and the motherapp checks the rootkit's dll files to make sure it is valid at launch so replacing it with another dll that simulates it is out of the question


soooo...where do i go from here?
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites