Thursday, July 12, 2007

Mount And Blade 1.003 Hile

About Adobe Flash Player Unhooker and Sophos Anti-Rootkit

In recent days, new versions of our favorite anti-rootkit software appeared:

(I do not know exactly how long it Sophos Anti-Rootkit is 3.1, I've only noticed it just now.)


1:22 IceSword English version
important innovation: The Advanced Scan (see picture). Unhooker rootkit is there but somehow meaningful.

Update: I take the back. Looks like by the Advanced feature of the IceSword tcpip.sys manipulations of Rustock.B (RKU what is already doing more). The hidden driver is not found still.


In the context menu of Process is now Find Modules. There you can search the loaded modules known as DLLs.



Update: In View-> Hide signed items, there is now an option signed to hide files (as with the programs from Sysinternals). Unfortunately, the function a little primitive and I do not think IceSword validate the signatures.

also part of the Registry has a new search function (right mouse button). Explorer of the file will now find alternative data streams (ADS). The ADS implementation looks pretty good.

Update: IceSword refers to the new search function of the hidden ADS Unreal.A rootkits.

The new version can now restore a changed SSDT (a la rootkit Unhooker). Unwanted BHOs can be deleted immediately.

Note: Because this Chinese servers are somehow more difficult to reach, I have the program again uploaded to speedyshare.


rootkit Unhooker LE 3.7.300.501
important innovation: RKU now supports Windows Vista 32 bit.
Displays a Shadow SSDT at (no idea what exactly that is ...).


A new "About" box.



Sophos Anti-Rootkit 3.1
should have improved detection and cleanup functions.
The color of the icon has been changed slightly.


Links

0 comments:

Post a Comment