+ Reply to Thread
Results 1 to 4 of 4

Thread: Rootkit Unhooker

  1. #1
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,447
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39447

    Rootkit Unhooker

    Rootkit Unhooker LE (RkU) is an advanced rootkit detection/removal utility, designed specially for advanced users and IT professionals. It runs under 32bit Windows 2000, Windows XP, Windows 2003 Server and Windows Vista. If you don't know how to use it, please do not tell that it is not working or found nothing. In the 95% of such incidents users simple don't know how to use this program.

    Features:

    Public version
    SSDT Hooks Detection and Restoring
    Shadow SSDT Hooks Detection and Restoring
    Hidden Processes Detection/Terminating/Dumping
    Hidden Drivers Detection and Dumping
    Hidden Files Detection/Copying/Deleting
    Code hooks Detection and Restoring
    Report generation

    Supported operation systems:
    x86 32 bit Windows 2000 SP4
    x86 32 bit Windows XP +SP1, SP2
    x86 32 bit Windows 2003 +SP1, +SP2
    x86 32 bit Windows Vista

    Note: RkU requires Administrator rights to launch and work.
    DOWNLOAD PAGE

    It's a very good tool to remove hidden rootkits, trojans, and general software that doesn't want to go or installs drivers - you can choose to remove them and the executable from memory, and wipe their .sys and .exe files. It also lets you unhook Windows API functions "taken" by other processes, but be careful with this, since legitimate programs like antivirus/firewall software and the Windows kernel itself may be doing this for good purposes.
    Notes: if you get a BSOD every time when using the "Files" tab's functions, go to Setup -> Settings, tick the "Use Standard DiskIO" checkbox, and press OK.
    And never enable "Extended Mode"! It can lead to blue screens, crashes and system unstability!
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    supergormiti (16.02.10) , shoulder (18.09.08) , hitman (18.09.08)

  3. #2

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    even those that come with packers ?? I mean if you just love to play with Trojans/Shells,does it detect them while your server is on ??
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Retired Seal
    SealLion's Avatar
    Join Date
    03.05.08
    Location
    The Arctic--Believe it!!
    Posts
    2,079
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2079
    Anon: Is this a similiar proggy to 'unhackme'??

    I think that it is. It sounds like it is. I have unhackme installed and it seems to check the computer upon start up and I think that what it does is remove trojans/rootkits upon boot. It runs silently in the background and checks every 15 mins. Its actually quite good I find.

    Unhackme is from 'Partizan'.


    But I think that your proggy seems to do a little bit more than the one that I've got installed here.
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,447
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39447
    @Aurion: I didn't exactly understand what you meant with "even those that come with packers", but I can tell from self-experience that it detects a lot of bad stuff that tries to hide itself (or not), as it can counter possible hooks placed on the Windows API for rootkits and malware to hide themselves (just like APT). It can also see hidden processes and drivers, and depending on how much they've been "buried" inside the system, unload them from memory, or if it isn't possible, wipe it's .sys and attempt to proceed anyway, so that whatever happens, it won't be able to run after a reboot.

    This is its menu:


    @SealLion: just checked UnHackMe (happened to have it in my downloads folder), and it does seem to do a similar job, but also to be more newbie-destined (doesn't prevent it from being very powerful, though), because of it's "wizard" interface.
    This tool is a lot more advanced - you can screw up your system if you don't know what you're roing, really - but also a great trouble-shooter, and definitely an "anti-spyware" suite when combined with APT, Autoruns (possibly also HijackThis), and knowledge of how to use all of them!
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •