The attacker failed to update the signature file for detecting antivirus scanners. That’s how F-Secure claims its Backlight scanner intercepted Golden Hacker Defender… the rootkit. If that hadn’t happened, Golden Hacker Defender would have disabled F-Secure’s antivirus protection in Windows, and delivered its payload.
What payload? Whatever the attacker chose to hide beneath Golden Hacker Defender’s cloak: virus, backdoor, spyware, or you-name-it. The authors of rootkits like Golden Hacker Defender couldn’t care less. They just provide the software that disables antivirus scanners… which they detect much like antivirus scanners detect them: with binary signature files.
All versions of Hacker Defender test for Avast!, AVG, Kaspersky, McAfee, NOD32, Norton, Panda, and PC-cillin. Once aboard, most versions trap all your logon info… including administrative services.
F-Secure says Golden Hacker Defender’s special because, unlike its open source version, Hacker Defender, it detects several commercial antivirus scanners. The creators of Golden Hacker Defender aren’t as impressed. For a real antivirus killer, they recommend their top-of-the-line Brilliant Hacker Defender. What? US$695 a bit over your budget? Hacker Defender has something on the shelf to fit any blackhat’s wallet.
Trashed By Hacker Defender
| Silver | Golden | Brilliant | |
| F-Secure BlackLight 2.1.1019 | |||
| F-Secure BlackLight 1.0.1017.0, 1.2.1003.0, 1.3.1015, 1.4.1003, 1.5.1002, 2.0.1008, 2.1.1010, 2.1.1012, 2.1.1013, 2.1.1018 | |||
| F-Secure BlackLight Console 1.25.1006.0, 1.28.1006.0 | |||
| Flister 0.1 | |||
| Klister 0.4 | |||
| KProcCheck 0.2-beta2 | |||
| RootkitRevealer v1.31, v1.32, v1.33, v1.40, v1.51, v1.53, v1.54, v1.55 | |||
| RootkitRevealer v1.00, v1.01, v1.10, v1.20 | |||
| UnHackMe 2.5 beta, 2.5 beta2, 2.5, 3.0 beta | |||
| UnHackMe 1.0, 2.0 | |||
| Find Hidden Service 1.0, 1.1 | |||
| Kernel SC 1.3 | |||
| Kernel PS 0.4, 1.0 | |||
| KHS 0.1 | |||
| Process Magic V1.0 by WinEggDrop | |||
| RegdatXP 1.41, 1.42 | |||
| RootKitShark 3.11, 3.22, 3.27 | |||
| TaskInfo 6.0.1.134, 6.2.0.170 | |||
| IceSword 1.04, 1.06, 1.06b, 1.08, 1.10, 1.12 | |||
| modGREPER 0.1, 0.2 | |||
| Process Hunter | |||
Hacker Defender project leader holy_father claims,”There is no known public rootkit detector that can reveal the presence of Hacker defender rootkit with this antidetection engine.”
He says antivirus companies simply wait to see new virus patterns, then add signature files. holy_father insists commercial vendors,”sell the fake sense of security but they do not bring the real security to your computer.”
“The real dangers,” he says,”are pointed attacks where private tools are used. These tools uses the same methods as our tools but are not detected because security companies have no chance to download them and add those few bytes in their database. And because they catch only tools they know and do not solve the cause attackers will succeed with their tools… There is no good AV product today.”
Until there’s a good AV product, you may want to isolate your Windows computers from the Internet with a solid wall of non-Windows firewalls and gateways… and keep those antivirus signature files up-to-date.
Background (updated):

5 comments
Comments feed for this article
October 19th, 2005 at 6:18 pm
waterboy
why no link to hacker defender???
October 19th, 2005 at 8:57 pm
SpannerITWks
All you need to do if for eg you are using IE is to Lockdown it down Securely.
Disable/Prompt - ActiveX/Active Scripting/Java and don’t allow Auto Installs.
A good FW set up for MAX Security.
And if you don’t visit dodgy sites etc And/Or click on unknown crap on ANY site or in emails you have very little if Anything to fear.
hf and co are the ones who give the ” security ” people a good needed kick up the rear to wake them up and improve things.
What others do with these ” RK’s ” is a different matter though !
Spanner
October 20th, 2005 at 4:03 pm
oliveoil
I don’t get it. Why is it legal to sell a product with which to perform illegal acts?
October 21st, 2005 at 8:06 am
SpannerITWks
You can buy petrol to run a vehicle, or burn a house down with people inside.
And there are lots of other examples of things which can be used for different purposes, good or bad.
What an individual etc does with whatever is down to them to make the right choices, or NOT !
Writing and selling an RK is NOT illegal, it’s the other stuff that’s tagged onto it by bad people that does the harm. A ” pure ” RK on its own does no damage, it would just sit there doing nothing. It’s just a way to gain part or full hidden access to a computer. In order for something nasty/dodgy to happen, an RK has to come with an attached payload. The RK is just the carrier/hider of something worse.
The term RK is used in Anti Virus, Security etc circles as a generic name which includes, with and without the payload, the actual Trojan etc.
Either way you wouldn’t want one in your comp, and eliminating them Completely can be a nightmare. The ONLY real way to be sure it’s gone, is to fdisk and then reformat, and then Reinstall everything.
You might like to check some of these threads out for further info etc on Detection/Removal -
http://www.testing.onlytherightanswers.com/
modules.php?name=Forums&file=viewforum&f=9&
sid=e846d86f554b722714d9f4349b67bd2c
Spanner
October 22nd, 2005 at 10:06 am
waterboy
holy_father on story: hmm, seems to be not so usuall type of text about antidetection, there are not many texts like this one - not offending my point of view, good! maybe we’ll really change the world