How to Use Trend Micro's Rootkit Remover to Install a Rootkit
d4stiny.github.io
d4stiny.github.io
As someone whose work involves screwing around with Windows' internal, whenever I see codes like this, I immediately think that the developer doesn't trust Windows' API. I guess that Trend Micro believes there's a chance that ZwQuerySystemInformation has been hooked by a malicious process and its data is unreliable, and they would rather retrieve the information themselves by scanning the memory manually.
[1] https://github.com/volatilityfoundation/volatility/wiki/Comm...
A good rootkit would certainly exclude itself from the info returned by ZwQuerySystemInformation
Surely Trend Micro should be penalised in some way by Microsoft?
* sqlite3.dll
* scan_db.sql
* DB <-- a folder name
That scan_db.sql is likely full of SQL statements.And SQLite can have user defined C functions added.
Depending on when those SQL statements are run (just for initial DB creation? during every run? etc), it could be a cheap and easy way to get your code running in a high privilege context. :)
The comment about the end, about the code looking like Proof of Concept garbage would be in line with that. ;)
Oouch!