CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

GMER 1.0.14 Beta

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Wed Nov 14, 2007 5:57 pm    Post subject: GMER 1.0.14 Beta
Reply with quote

GMER 1.0.14 beta download plus screenshots of Gmer detecting Trojan.Srizbi rookit here:
http://www2.gmer.net/beta/

This version has incorporated new registry and file system browser/editor functions!

This version runs on 32 bit Vista - launch by right-clicking gmer.exe and choosing "Run as Administrator."

Please note that this is beta software and should be used only for evaluation at this time. As with all beta software, system crashes or errors may occur. If they do - please describe any problems encountered and what triggered the event. Explanatory screenshots are welcome. Use at own risk!

I have found it to be quite stable thus far and the new features offer new and welcome functionality. I am only having a problem with Autostart function on 32 bit Vista (no system crashes though - just "the program needs to close"). If any one wants test/confirm this, please do so.

Quote:
List of changes in GMER 1.0.14:
# Improved files scanning
# Improved registry scanning
# Added disk browser
# Added registry browser and editor
# Added registry exports
# Added "Kill file" and "Disable service" options to help remove stubborn malware
# Added new option "gmer.exe -nodriver"
# Added new option "gmer.exe -killfile"
  • gmer.exe -killfile C:\WINDOWS\system32\drivers\runtime2.sys
  • gmer.exe -killfile C:\WINDOWS\system32:pe386.sys

# Simplified displaying of device hooks

Few comments about new version:

The Registry editor has some limitations:

1) because it's based on direct disk writes - you can change only
REG_DWORD + all REG_SZ value/data but the size of new string should to be smaller or equal to the old value.

2) WINDOWS only sees changes made after the next reboot

Here is movie which shows new version:
http://www2.gmer.net/kav7test.wmv


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Wed Nov 14, 2007 7:53 pm    Post subject:
Reply with quote

Gmer (author) has successfully corrected the Vista autostart scan bug, but it may not be reflected in the downloadable version yet.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sat Dec 15, 2007 8:22 pm    Post subject: Re: GMER 1.0.14 Beta
Reply with quote

[quote="negster22"]GMER 1.0.14 beta download plus screenshots of Gmer detecting Trojan.Srizbi rookit here:
http://www2.gmer.net/beta/

This version has incorporated new registry and file system browser/editor functions!
[/color]

Nice.

Some guy also posted about this in the wiki.

http://www.online-solutions.ru/en/osam_autorun_manager.php

"Functional capabilities:

* support of virtually all known methods of automatic loading using the system registry or special folders;
* automatic detection of the peculiarities of settings on specific user systems;
* validation of digital file signatures;
* color marking of file statuses for better comprehension;
* filtering by statuses of detected objects;
* search by masks using any parameter in any display mode;
* output of additional information for any object type;
* output of detailed file information, validation of file existence and accessibility;
* temporary disablement of registry objects or files without creating additional keys or subfolders;
* generation of two types of report files (text and HTML*) with all autoload information.

Unique capabilities:

* protection against rootkits by detecting hidden registry keys and records using the method of direct registry data analysis (without using OS functions);
* comprehensive support of LSP (Layered Service Providers) filters deletion and recovery with rearrangement of the providers chain;
* support of namespace providers (NSP) with rearrangement of the providers chain*."

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer