Ceriwis  

Go Back   Ceriwis > HOBI > Komputer & Teknologi > Shareware & Freeware

Shareware & Freeware Bertukar informasi mengenai Software berbayar ataupun gratis.

Reply
 
Thread Tools
  #1  
Old 24th October 2012
SiJampang1's Avatar
SiJampang1 SiJampang1 is offline
Ceriwiser
 
Join Date: Oct 2012
Posts: 793
Rep Power: 14
SiJampang1 mempunyai hidup yang Normal
Default XueTr :: Anti-Virus (RootKit) Powerfull Yang Terlupakan





� XueTr �




| Home Page |









[/quote]
Quote:





XueTr anti-rootkit is a free and handy toolkit for Windows with various powerful features for kernel structure viewing and manipulation.It offers you the ability with the highest privileges to detect, analyze and restore various kernel modifications and gives you a wide scope of the kernel.With its assistance, you can easily spot and neutralize malwares hidden from normal detectors.



XueTr currently supports the following Windows 32-bit versions:


Quote:





- Windows 2000 SP4

- Windows XP (no SP,SP1, SP2, SP3)

- Windows Server 2003 (no SP,SP1,SP2,R2)

- Windows Vista (no SP,SP1,SP2)

- Windows Server 2008 (no SP,SP1)

- Windows 7 (no SP,SP1)






Currently,the following features are available:




[/spoiler]
Spoiler for open this:
Spoiler for open this:
for fitur:




*Process Manager

View system process and thread basic information.

Detect hidden processes,threads,process modules.

Terminate, suspend and resume processes and threads.

View and manipulate process handles,windows and memory regions.



*Kernel Module Viewer

Display kernel module information including ImageBase,Size,Driver Object,ImagePath,ServiceName and Load Order.

Detect hidden kernel modules.

Unload kernel module(dangerous,never try it on Windows 7).

Dump kernel image memory.

Display and delete system driver service information.



*Hook Detector

View and restore SSDT,Shadow SSDT,sysenter and int2e hooks.

View and restore FSD and keyboard disptach hooks.

View and restore kernel code hooks including kernel inline hooks,patches,IAT and EAT hooks.

View and restore usermode process hooks incluing inline hooks,patches,IAT and EAT hooks.

View and restore message hooks(both global and local).

View and restore kernel ObjectType hooks.

Display Interrupt Descriptor Table(IDT).



*System Callback Viewer

Display and remove Kernel Notifications(Process/Thread/Image/Registry/Lego/Shutdown/Bugcheck/FileSystem/Logon).



*Network Viewer

Display current network connections, including the local and remote addresses and state of TCP connections.

View and delete IE plugins and context menu.

View and restore tcpip dispatch hooks.

Display winsock providers(SPI).

View and edit hosts file.



*Filter Viewer

View and remove filters for common devices including disk,volume,keyboard and network devices.



*Registry Viewer

View and edit system registry.

Detect hidden registry entries using live registry hive analysis.



*File Explorer

Detect hidden files using both disk analysis and driver methods.

View and delete locked files and folders.

View file basic information including NTFS Alternate Data Streams.



*Autorun Manager

Display and delete common autorun entries.



*Service Manager

Display Win32 service information (for Ring0 modules,it is included in Kernel Module Viewer).

Change service status and configuration.



*DPC Timer

Enumerate and delete DPC Timer objects.



*Miscellaneous

View and repair common filetype assosications.

View and repair image hijacks.



*Settings

Option to defense from process creation,thread creation,module load and message hook installation.

Option to defense from file creation,registry key creation.

Option to prevent system suspend,log-off,shutdown and reboot.

Option to prevent locking workstation and switching destop.

option to prevent setting system time.






Quote:
Spoiler for open this:







Spoiler for open this:
Quote:





Update Log



One hand anti-virus tools, support 32-bit, 2000, xp, 2003, vista, 2008 and Win7 operating system.

Download (md5: AF31D243C6C5A18919B363D57832A3A5)



Author QQ microblogging: linxer welcome to listen, after XueTr situation will be released here.



This tool is currently achieve the following functions:



1 processes, threads, process modules, process window, process memory, timer, hotkey information to view, kill the process, kill the thread, unload the module and other functions

(2) kernel driver module view, to support the kernel driver module memory copy

3.SSDT, Shadow SSDT, FSD, KBD, TCPIP, Classpnp, Atapi, Acpi, SCSI, IDT, GDT information view, and can detect and recover ssdt hook and inline hook

4.CreateProcess, CreateThread, LoadImage, CmpCallback, BugCheckCallback, Shutdown, Lego, etc. Notify Routine information view, and supports the removal of these Notify Routine

5 port information view, the current system does not support the 2000

6 See the news hook

7 kernel modules iat, eat, inline hook, patches detection and recovery

8 disk, volume, keyboard, network layer filter driver detection, and supports the deletion of

9 Registry Editor

10 process iat, eat, inline hook, patches detection and recovery

11 file system view, supports basic file operations

12 View (edit) IE plug-in, SPI, startup items, services, Host files, image taking, file associations, system firewall rules, IME

13.ObjectType Hook detection and recovery

14.DPC timer to detect and remove

15.MBR Rootkit detection and repair

16 hijacked kernel object detection

17.WorkerThread enumeration



Disclaimer: This is just a free auxiliary gadget, if you use this tool, giving you direct or indirect losses, damages, and I take no responsibility. From your use of this gadget that moment on, you are deemed to have accepted this disclaimer.






Screenshoot:



Quote:
[spoiler=open this] for ss:




























[quote]





Index of /download









Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


 


All times are GMT +7. The time now is 04:07 AM.


no new posts