Showing posts with label Rootkit. Show all posts
Showing posts with label Rootkit. Show all posts

Monday, November 23, 2009

0

RootRepeal - Rootkit Detector

  • Monday, November 23, 2009
  • Runtrailblog
  • RootRepeal is a small, portable and freeware tool to uncover rootkits.Generally this  tool is useful  for advanced users  those who know what the normal Windows drivers, processes and services are.

     

    Features

    1. Easy to use - a user with little to no computer experience should be able to use it.
    2. Powerful - it should be able to detect all publicly available rootkits.
    3. Stable - it should work on as many different system configurations as possible, and, in the event of an incompatibility, not crash the host computer.
    4. Safe - it will not use any rootkit-like techniques (hooking, etc.) to protect itself.
    5. RootRepeal has the ability to scan and display all currently loaded drivers and tell you whether they are hidden and whether the drivers file is visible on disk.
    6. Scans for hidden, locked or fraudulent files on the system
    7. Scans and displays the currently running processes ( shows if the process is hidden or locked).
    8. Scans the SSDT (system service descriptor table) to see if any services are hooked.
    9. Scans for Stealth objects which looks for rootkit symptoms in general.
    10. Scans for Hidden services and displays them.

    11-23-2009 05-11-43

     

    It is better to disable your antivirus, antispyware, and firewalls before continuing or they may block RootRepeal from running properly.If you have  found something malicious, right click on the driver/file/service and either copy, wipe or force delete it.You can  save the scan  report , which you can attach to  various forums for analysis if needed.

     

    11-23-2009 05-35-53

     

    dl2  RootRepeal |454KB

    Read more...

    Tuesday, April 7, 2009

    0

    GMER - Rootkit Detector and Remover

  • Tuesday, April 7, 2009
  • Runtrailblog
  • Are  you worried about rootkits? GMER is a scanner that can find many of the most stubborn rootkits

     

    4-7-2009 10-31-52 AM

     

     

    It scans for:

    • hidden processes
    • hidden threads
    • hidden modules
    • hidden services
    • hidden files
    • hidden Alternate Data Streams
    • hidden registry keys
    • drivers hooking SSDT
    • drivers hooking IDT
    • drivers hooking IRP calls
    • inline hooks

     

    GMER also allows to monitor the following system functions:

    • processes creating
    • drivers loading
    • libraries loading
    • file functions
    • registry entries
    • TCP/IP connections
    • GMER runs on Windows NT/W2K

    105 GMER | Freeware | 384KB | Home page  http://www.gmer.net/index.php

     

    Also Read:Rootkit & Removers

    Read more...

    Monday, February 23, 2009

    0

    Zemana AntiLogger V1.7.2.960 - Free 1 Year License

  • Monday, February 23, 2009
  • Runtrailblog
  • Key logger is a small piece of software that monitors your keystrokes, logging them to a file and sending them off to remote attackers.Keyloggers can record all keystrokes, or they can monitor a specific activity .

     

    Keyloggers are used in IT organizations to troubleshoot technical problems . It can also be used by a family to monitor the network usage of people without their direct knowledge. But  some  individuals may use keyloggers on public computers to steal passwords or credit card information.

     

    Detecting the presence of a keylogger on a computer can be difficult. Many anti-keylogging softwares  are available in net and these are  effective when used properly.Zemana AntiLogger protects your system from keyloggers and other threats with the intent to steal your personal information.It provide protection against keystroke logging, webcam logging, screen logging, clipboard logging, SSL logging and other activities that may pose a risk to your privacy.It works in conjunction with all major security products. AntiLogger improves your existing security by providing protection against the very latest Spyware, Rootkits,Trojans, Viruses, Bots, Adware and Password Stealers.

     

    2-23-2009 4-04-41 PM

     

    Features

    • Proactive protection from unknown threats
    • Advanced anti-rootkit technology
    • Boost your PC’s performance
    • Compatible with Windows Vista and Windows XP
    • Key Logger protection
    • Screen Logger protection
    • Clipboard Logger protection
    • SSL Logger protection
    • Webcam Logger protection
    • System Defense

      By joining the Zemana beta program, users can use Zemana Anti-KeyLogger for free at no cost with 1 year subscription.To register and receive a free product key to use Zemana AntiLogger for free for 1 year, submit your details at the following URL:

       

      http://www.zemana.com/list/list.aspx?ktgr_id=414

       

      Spark018

      Provide your email id & fill other columns .Check your email and will get the license number.Download the latest version (1.7.2.960 | 4.42 MB ) of Zemana AntiLogger from here, install  .You can enter serial number at Service -> License -> Enter License text box, and then click on “Renew License”.

      Via[mydigitallife.info]

      Read more...

      Sunday, August 31, 2008

      0

      Malwarebytes' Anti-Malware

    • Sunday, August 31, 2008
    • Runtrailblog
    • Have you ever considered what makes an anti-malware application effective?Whether you know it or not your computer is always at risk of becoming infected with viruses, worms, trojans, rootkits, dialers, spyware, and malware that are constantly evolving and becoming harder to detect and remove. Only the most sophisticated anti-malware techniques can detect and remove these malicious programs from your computer

      Malwarebytes' Anti-Malware is a utility that monitors your system and thoroughly removes even the most advanced malware. It can detect and remove malware that even the most well-known Anti-Virus and Anti-Malware applications on the market today cannot. Malwarebytes' Anti-Malware monitors every process and stops malicious processes before they even start. The Realtime Protection Module uses our advanced heuristic scanning technology which monitors your system to keep it safe and secure.

      anti-malware1

      Key Features

      • Support for Windows 2000, XP, and Vista.
      • Light speed quick scanning.
      • Ability to perform full scans for all drives.
      • Malwarebytes' Anti-Malware Protection Module. (requires registration)
      • Database updates released daily.
      • Quarantine to hold threats and restore them at your convenience.
      • Ignore list for both the scanner and Protection Module.
      • Settings to enhance your Malwarebytes' Anti-Malware performance.
      • A small list of extra utilities to help remove malware manually.
      • Multi-lingual support.
      • Works together with other anti-malware utilities.
      • Command line support for quick scanning.
      • Context menu integration to scan files on demand.
        SysReq: Microsoft ® Windows 2000, XP, Vista Trail Ver 1.99MB
        Download icon
        From 4Shared.com

      From Rapidshare

      Malwarebytes.Anti-Malware.1.24. Malwarebytes_Anti-Malware_1.24

      From Easyshare

      Malwarebyte's AntiMalware

      Read more...

      Friday, December 21, 2007

      0

      Spyware ,Virus Symptoms &Cure

    • Friday, December 21, 2007
    • Runtrailblog
    • Spyware Symptoms

    • One of the oldest and most common spyware tricks is to automatically change your Web browser's default or start-up homepage - the page that first appears when you start your browser or click the "home" button.
    • You end up in a same strange site, whenever you perform a search.
    • Your firewall and antivirus programs are frequently turned off automatically.
    • Your network connection's activity lights blink a lot, when you are not actively doing anything on the internet.
    • You are unable to stop the excessive popup windows that appears from nowhere.
    • Your computer (not just your connection speed) slows down significantly whether online or offline.
    • Strange icons and new shortcuts lurking in your taskbar, system tray or on your desktop.
    • You find new programs in the add/remove programs of your control panel which you don't ever remember installing.
    • You notice an unusual amount of new favorites and are not sure how they got there.
    • Strange problems occur within windows, (performance issues, programs not working as they should, etc)
    • You are redirected to a strange site instead of 404 error page, when a web page isn't found.
    • You get frequent alerts from your firewall about an unknown program or process trying to access the internet.
    • You get a lot of bounced back mail and see evidence of e-mails being sent without your knowledge.
    • Your browsing speed becomes very slow since you installed the "ultimate search companion".
    • Strange and unexpected toolbars appear in your web browser and you don't know how it got there.
    • Your phone company charges you for '1-900' phone calls you didn't make.
    • When you try to open spyware eradicating programs like Spybot S&D, Adaware or windows programs like Task manager, Regedit and Msconfig, they just pop up on your screen momentarily and disappear.
    • The Java console appears in your task bar when you hadn't run any Java software recently.
    • Virus Symptoms

    • Unusual messages or displays on your monitor
    • Unusual sounds or music played at random times
    • Your system has less available memory than it should
    • A disk or volume name has been changed
    • Programs or files are suddenly missing
    • Unknown programs or files have been created
    • Some of your files become corrupted or suddenly don't work properly
    • More details here

      Trojan Symptoms

    • Your computer screen flips upside down or inverts
    • Your wall paper or background settings change by themselves
    • Documents or messages print on your printer by themselves
    • Your windows color settings change by themselves
    • Your screen saver settings change by themselves
    • Your right and left mouse buttons reverse their functions
    • Your mouse pointer disappears
    • Your mouse moves by itself
    • Your mouse starts leaving trails
    • Your Windows Start button disappears
    • Your computer starts reading the contents of your computer clipboard
    • Your Task bar disappears
    • Your computer shuts down and powers off by itself
    • More details here

      How to cure Part1 Part2 Part3

      Useful Links here here here

      Online Scanners:Trend Micro Housecall Kaspersky Online Scanner Virustotal Jotti Online Malware Scan Avast Online Scanner BitDefender Online Scanner Symantec Online Scan

      Free virus removal tools:McAfee AVERT Stinger AntiVir Personal Edition AVG Panda Antikak BitDefender Free Tools Symantec Free Tools McAfee Free Tools TrendMicro Tools Kaspersky Tools Avast

      Read more...

      Sunday, December 16, 2007

      0

      Rootkit & Removers

    • Sunday, December 16, 2007
    • Runtrailblog
    •  A rootkit, like a cloak of invisibility, is a program that surreptitiously allows an attacker to gain administrator-level access to a computer or network. Installing itself silently, it stays concealed by hiding processes, files, network traffic and other observable information about itself from the computer user. Rootkits typically hide utilities that make it easy for attackers to return to a compromised system in the future. Rootkits aren't easily detected and since no single vendor reliably detects all rootkits, it can be beneficial to work with more than one rootkit-detection tool. Fortunately, there are a number of useful no-cost tools available.

      · Sophos Anti-Rootkit is a sophisticated free rootkit detection and removal tool for Windows NT, 2000, XP and 2003. Before scanning, it's strongly recommended that the user close down all non-essential applications. A rootkit scan can take several minutes on a desktop computer or significantly longer on a server. The scan searches for hidden files, processes, registry keys and values. When the scan finishes, a pop-up screen appears confirming the status and results of the scan. Click on the suspicious file to display more information about it. The information displayed includes whether the item is recommended for removal. If a suspicious file is recognized, it can be safely removed; if the scanner isn't sure what it is, but considers it suspicious, it can still be removed. Download here

      · Panda AntiRootkit, like Sophos, has a GUI and allows for command-line options. Also like Sophos, it identifies known rootkits and suspicious rootkit behaviors indicative of unknown rootkits, and provides the option of removing them along with their associated registry entries, processes and files. Panda AntiRootkit looks for hidden files, registry entries, drivers, processes, execution hooks and does an excellent job of ferreting out possible rootkits, removing dangerous rootkits even when it can't fully identify them. It runs on Windows 2000, XP and 2003. Download here

      If one of the rootkit scanners mentioned above doesn't do it for you, you can also run additional rootkit detection and removal tools such as:

      • McAfee Rootkit Detective: This is a program designed to detect and clean rootkits and works on XP, 2000 and 2003. However, McAfee strongly recommends its software only be used by knowledgeable individuals with direction from and the support of a representative from McAfee Avert Labs or McAfee Technical Support. Download here Rapidshare: here
      • AVG Anti-Rootkit Free: This tool -- in its free basic-level version -- provides for rootkit detection and removal and works on Windows 2000 and XP. Download here
      • Microsoft® Windows® Malicious Software Removal Tool :This tool checks your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps to remove the infection if it is found. Microsoft will release an updated version of this tool on the second Tuesday of each month.
      • F-Secure BlackLight :F-Secure BlackLight can detect and eliminate active rootkits from the computer. Traditional antivirus scanners can't detect active rootkits.

           (Rapidshare :here, Addon,pasword :www.thegreatforum.org Serials:GDQx-LEMB-L3F7-KE32-x7VA,
            0RUV-xE2U-PQRD-CRM6-F0QJ ,AxPV-U00B-BQ7C-LKED-92E7)

      • RootKit Hook Analyzer:RootKit Hook Analyzer is a security tool which will check if there are any rootkits installed on your computer which hook the kernel system services. Kernel RootKit Hooks are installed modules which intercept the principal system services that all programs and the operating system rely on. If any of these system services are intercepted and modified it means that there is a possibility that the safety of your system is at risk and that spyware, viruses or malware are active.

      • ARIES Rootkit Remover:The ARIES Rootkit Remover v1.0 is designed to locate and permanently remove the rootkit that was developed by First4Internet and used by Sony BMG to hide their digital rights management (DRM) software. Unlike Sony's own rootkit remover that has been known to cause blue screens, Lavasoft's ARIES Rootkit Remover is a reliable, stand-alone tool.Rapidshare:here

      Read more...

      Your Links

      .

      Subscribe