 |
|
Who's Online
|
There are currently 290 people and 0 DV-member(s) online.
|
|
|
|
|
RSS
|
|
|
|
|
|  |
SysProt AntiRootkit 1.0.0.5 Beta
|
Posted on Monday, September 24 2007 @ 00:05:20 CEST by Thomas De Maesschalck |
SysProt AntiRootkit v1.0.05 is out! This new version contains IRP Hooks detection feature and also various other improvements, bug fixes etc. IRP Hooks detection may come handy as some of the new Rootkits are utilizing this technique. One such example is Win32/Cutwail trojan, which hooks IRP_MJ_DEVICE_CONTROL of Tcpip.sys driver.
Here's an overview of SysProt AntiRootkit v1.0.0.5 features:
Hidden process detection and removal
Hidden drivers detection
SSDT Hooks detection and removal
Kernel Inline hooks detection and removal
IRP hooks detection
Sysenter Hook detection
TCP/UDP Ports Info
File System browser
Hidden Services Registry keys detection and removal
|
Program Information
Category:
Tools and Utilities
Type:
Free
Version: 1.0.0.5 Beta
Size: 0.2MB
Works on: Windows
Product page: here
|
|
Download: SysProt AntiRootkit 1.0.0.5 Beta
|
|
|