IT2009. 8. 17. 20:54


GMER is an application that detects and removes rootkits.

GMER scans for :

· hidden processes
· hidden threads
· hidden modules
· hidden services
· hidden files
· hidden Alternate Data Streams
· hidden registry keys
· drivers hooking SSDT
· drivers hooking IDT
· drivers hooking IRP calls
· inline hooks

GMER also allows to monitor the following system functions :

· processes creating
· drivers loading
· libraries loading
· file functions
· registry entries
· TCP/IP connections

GMER runs on Windows NT/W2K/XP/VISTA.

What's New in GMER 1.0.15 :

· Improved files scanning
· Improved registry scanning
· Improved "delete file" function
· Added disk browser
· Added registry browser and editor
· Added registry exports
· Added "Kill file" and "Disable service" options to help remove stubborn malware
· Added new option "gmer.exe -nodriver"
· Added new option "gmer.exe -killfile"
gmer.exe -killfile C:\WINDOWS\system32\drivers\runtime2.sys
gmer.exe -killfile C:\WINDOWS\system32:pe386.sys
· Simplified displaying of device hooks
· Added detection and removal of MBR rootkit

Posted by 고진감래 [苦盡甘來]