Chase and Sam

Welcome to the Home Page of Chase Thompson and Sam Knowles. We're tech journalists, web designers and computer security consultants based in Birmingham Alabama. You can hear us weekly on WAPI 1070 AM in Birmingham (11:00 am) and also see us on TV (Thursday night, 9:55pm) hosting Tech Check on WBRC6 - the local Fox affiliate.

Freeware

Every week, you can find great downloads on this page. We feature freeware, open source software, and any high quality (and malware free) software download we can find. Regular show listeners like Uncle Monster and Tollie often contribute to this page.

Uncle Monster’s Downloads for 06-28-08

[8~{} Uncle Monster
==============================

=======

Cleanmem 1.0

http://www.majorgeeks.com/Cleanmem_d5972.html

By Shane C.,
Cleanmem is a tool I wrote for my customers and
there systems and decided to release it on the net.
The program will install and set it to run every 30
min via the windows task scheduler. Install it and
you’re done! The program doesn’t run in the
background, once it does its job it closes and
doesn’t run again until the task scheduler runs it.
The program is very simple to operate as it will run
and clean the memory out of all processes it can,
without any user input. Some anti viruses and such
protect their processes so of course cleanmem
can’t touch those. This doesn’t work like other
memory cleaners that do nothing but force windows
to free up memory by using up all the avail. memory.
This old trick then causes your system to lag big time!
Cleanmem works in a matter of about 5 sec. It uses
a windows api call that is in Windows 2000,xp,2003,
Vista & 2008 that tells windows to cleanup the
workspace of a processes thus freeing up any memory
the process no longer needs. Other memory
cleaners end up forcing the memory into the page file
slowing down your system. This tool does not.
The API call frees up unused memory from programs,
when a program needs the memory again it can
simply take it
back instead of forcing the memory out of ram and
into the page file. A good example is this, say you
have quickbooks installed and setup for multi user
mode. The quickbooks service takes 37mb of memory
just sitting there! when cleanmem is ran it uses only
600kb and wont grow again until it actually is used.
The same goes for all processes. If a processes needs
more memory it gets it back in a sec, I have it set to
run every 30 min in the windows task sched. You wont
notice any performance hit of any kind even when
pushing your system to the max playing a heavy 3d
game (In my case I tested it playing Age Of Conan)
So basically set it and forget it, memory leaks from
programs will be a thing of the past with this tool.
if you need to run it manually you can simply make
a shortcut to it in the system32 dir, or just open
your run command and type in cleanmem and hit ok!
To see when it works just open the task manager
=======================================

CryptoExpert 2008 Lite 7.6.0

http://www.1stdownload.com/drive-encryption-free/

On the fly drive encryption software for home

CryptoExpert creates encrypted virtual disks and
these disks are visible as usual disks with drive letters
(for example, G:, H:, Z:, i.e. with any drive letter that
is not used by other system devices). The data stored
on a CryptoExpert disk is stored in the container file.
A container is a file, so it is possible to backup a
container, move or copy it to other disk (CD-ROM or
network, for instance) and continue to access your
encrypted data using CryptoExpert. Any free drive
letter (or choosen letter) in the system may be used
to mount and to open an encrypted file-container for
access. When the virtual disk is opened, you can
read and write data as if it were a conventional removable
disk. You can do anything with a CryptoExpert virtual
drive that you can do with a normal hard drive; only that
with CryptoExpert, the encrypted volumes require password
authentication before the files become accessible.

Product Features:
* Using powerful encryption algorithm to encrypt your
data: CAST 128 bit
* Ability to create encrypted containers (files vault)
up to 20 Megabytes in size
* Access to your files on virtual volume on the fly
* Mapping any free drive letter like G:, F:, K: f
or virtual volume
* Requires password authentication before the
files become accessible
* Works with all Windows application - even
DOS applications
* Really Fast
* Looks like normal hard drive
=======================================

AVS DVD Player 2.4.2.125

http://avsmedia.com/DVDPlayer/index.aspx

Play movie DVDs, video & audio files right on your
computer with FREE AVS DVD Player. No spyware
or adware. Safe to install!!! AVS DVD Player  is a
compact and easy-to-use program that has a simple
user-friendly interface allowing you to start watching
DVD movies with no additional software. One more
pleasant thing about it - it is absolutely
FREE SOFTWARE!
Platforms: Windows 2000, XP, 2003, Vista
(no Vista 64-bit/Mac OS/Linux support)

Downloads from Uncle Monster: Allway Sync 8.1.1, Syncback Free, InfoHesive Viewer, OnClick Utilities, Encrypt on Click and more

This week I’m sending links to two software
companies that provide some free versions
of their commercial software. First Allway
Sync free file and folder synchronization
software for Windows. Then 2BrightSparks
that offers ten freeware programs.

[8~{} Uncle Monster
==============================

==

Allway Sync version 8.1.1

http://allwaysync.com/

Allway Sync uses innovative synchronization
algorithms to synchronize your data between
desktop PCs, laptops, USB drives and more.
Allway Sync combines bulletproof reliability
with an extremely easy-to-use interface.
=================================

2BrightSparks’ 100% Freeware

http://www.2brightsparks.com/freeware/freeware-hub.html

SyncBack Freeware V3.2.18.0
SyncBack is our freeware program that helps
you easily backup and synchronize your files
to: the same drive; a different drive or medium
(CDRW, CompactFlash, etc); an FTP server;
a Network; or a Zip archive.

InfoHesive Freeware Viewer V1.3
Read InfoHesive Help Files and eBooks using
the freeware InfoHesive Viewer. With no nag
screens, buy buttons, or upgrade notices, this
is an excellent royalty-free publication medium
with a Print Article or WorkSpace feature and
an onboard Print Designer for added reader
flexibility.

OnClick Utilities
OnClick Utilities is a a suite of powerful software
programs from 2BrightSparks that will transform
your daily computing experience. Four programs
in the suite are available as freeware and featured
below. Enhanced versions of these programs are
also available for those who pay for a license.
Entering a serial number will immediately unlock
all the enhanced versions in the OnClick Utilities
suite.

EncryptOnClick Freeware
EncryptOnClick is a program that lets you securely
encrypt and decrypt files.
EncryptOnClick is like hiring your own highly
experienced data security guard who ensures the
files you want to keep safe and out of view from
others stay that way. The program is very simple
to use and features military grade 256-bit AES
encryption.

DeleteOnClick Freeware
When you delete a file or folder using Windows,
it is usual for the file or folder to be moved to the
Recycle Bin (Trash). When the Recycle Bin is
emptied, the data you have deleted is not actually
removed from your computer. Instead, Windows
makes the space occupied by the file available for
writing. In other words, every file you delete using
Windows is potentially recoverable in the short
term. If you create a new file after deleting using
Windows, or save a changed file, it may write over
the ‘deleted’ file’s space, thus destroying it
permanently. Likewise, defragmenting will possibly
overwrite the deleted files.

HashOnClick Freeware
HashOnClick is a very simple to use file validation
utility for Microsoft Windows 98SE/ME/ 2000/XP/2003
and Vista.
HashOnClick quickly and easily provides information
to compare hash values side by side to establish the
data in one file exactly matches (or not) the data in
another. Ensure that the files you receive haven’t been
tampered with.

PatchOnClick Freeware
PatchOnClick is an easy to use program that
allows you to send and receive updates to large
files without having to send or receive the whole
file each time.
Sending and receiving smaller patch files is less
burdensome on servers, firewalls, and security
programs which scan data as it is sent and received.

Then there are three freeware apps from 2BrightSparks
that are no longer in development. All are on their free-
ware page.

Interesting screen saver, Tray minimizer, Mail Privacy Lite…Downloads from Uncle Monster

This week I’ve included the best screen saver of all
time for messing with someone’s mind. Then two
free programs from a software company that are
pretty cool. One adds extra buttons and extra
functionality to your right click. The other is a
steganography application for hiding your E-mail
messages inside a picture.

[8~{} Uncle Monster
==============================

=======

BlueScreen Screen Saver v3.2

http://technet.microsoft.com/en-us/sysinternals/bb897558.aspx

Introduction

One of the most feared colors in the NT world is blue.
The infamous Blue Screen of Death (BSOD) will pop up
on an NT system whenever something has gone terribly
wrong. Bluescreen is a screen saver that not only
authentically mimics a BSOD, but will simulate startup
screens seen during a system boot.

* On NT 4.0 installations it simulates chkdsk of disk
drives with errors!
* On Win2K and Windows 9x it presents the Win2K
startup splash screen, complete with rotating
progress band and progress control updates!
* On Windows XP and Windows Server 2003 it
present the XP/Server 2003 startup splash screen
with progress bar!

Bluescreen cycles between different Blue Screens and
simulated boots every 15 seconds or so. Virtually all the
information shown on Bluescreen’s BSOD and system
start screen is obtained from your system configuration -
its accuracy will fool even advanced NT developers. For
example, the NT build number, processor revision, loaded
drivers and addresses, disk drive characteristics, and
memory size are all taken from the system Bluescreen
is running on.
Use Bluescreen to amaze your friends and scare your
enemies!

Bluescreen runs on Windows NT 4.0, Windows 2000,
Windows XP, Windows Server 2003 and Windows 9x
(it requires DirectX).

Installation and Use

Note: before you can run Bluescreen on Windows 9x,
you must copy \winnt\system32\ntoskrnl.exe from a
Windows 2000 system to your \Windows directory.
Simply copy Sysinternals BLUESCRN.SCR to your
\system32 directory if on Windows NT/2K, or
\Windows\System directory if on Windows 9x. Right
click on the desktop to bring up the Display settings
dialog and then select the “Screen Saver” tab. Use the
pull down list to find “Sysinternals Bluescreen” and apply
it as your new screen saver. Select the “Settings” button
to enable fake disk activity, which adds an extra touch
of realism!
Note: Some virus scanners flag the Bluescreen screen
saver as a virus. If this is the case with your virus scanner,
you may not be able to use this screen saver.
==========================================

4t Tray Minimizer Free

http://www.4t-niagara.com/tray.html

Minimize Outlook, Internet Explorer, Firefox and any other
applications to the system tray!

4t Tray Minimizer lets you running applications minimized
as System Tray icons, which helps free up space on your
taskbar. Main features:

* various ways to minimize any application to the system tray;
* ability to hide any application without showing tray icon;
* the customized hotkeys for minimizing, restoring, maximizing
and launching applications;
* ability to customize the minimizing behavior of your favorite
application;
* quick hiding/showing the whole system tray.
============================================

4t HIT Mail Privacy LITE 1.01

http://www.4t-niagara.com/hitmail.html

Protect your confidential email in seconds
There is no doubt that even with conventional email protection,
there are unscrupulous people who can and will, intercept and
read emails. 4t HIT Mail Privacy Lite provides a quick and easy
way of protecting your communications by embedding your
text into an image, combined with a particularly strong encryption
method, you can be assured your mail is safe.
Use any image on your PC, from a pleasant lanscape image to
your latest birthday photo, HIT Mail supports a wide variety of
image formats and is extremely easy to use.

Uncle Monster’s Weekly downloads

This week I’m getting really geeky with a
drive partitioning and cloning tool written
with an alternative operating system.
OTW Other Than Windows. It was made
with Visopsys (VISual OPerating SYStem).
Here is a link to the ISO and floppy image
for the tool and a link to the OS it came
from. Now if you really want impress and
confuse your fellow geeks, I’m including
links to a few other alternative and some-
what obscure operating systems. You can
load them up on a PC, leave it running and
freak out that special arrogant geek who
irritates you.

[8~{} Uncle Monster
==============================

===

Partition Logic ver 0.69

http://partitionlogic.org.uk/index.html

ABOUT PARTITION LOGIC

Partition Logic is a free hard disk partitioning and data management
tool.  It can create, delete, erase, format, defragment, resize, copy,
and move partitions and modify their attributes.  It can copy entire
hard disks from one to another.

Partition Logic is free software, available under the terms of the GNU
General Public License.  It is based on the Visopsys operating system.
It boots from a CD or floppy disk and runs as a standalone system,
independent of your regular operating system.

Partition Logic is intended to become a free alternative to such
commercial programs as Partition Magic, Drive Image, and Norton Ghost.

SYSTEM REQUIREMENTS

Partition Logic supports most basic PC hardware without any additional
work or configuration.  It has very modest (by today’s standards)
requirements:

* Pentium-class or better x86 processor.  Supports all modern
Intel x86 and AMD processors.
* 32 megabytes RAM memory (16 megabytes if operating in text mode).
* IDE (ATA) hard disks for partitioning.
* IDE (ATAPI) CD-ROM drive, if booting from the CD version.
* Standard PC floppy disk, if booting from the floppy disk version.
* For graphics mode, a VESA 2-compatible graphics card with linear
framebuffer support.
* USB or PS/2-syle keyboard.
* USB or PS/2-style mouse, if operating in graphics mode.

LIMITATIONS

Partition logic has the following limitations:

* Does not work with some SATA hard disks
* No hardware support for non-USB SCSI hard disks
* Supports only DOS/Windows-style MBR partition tables (used on
nearly all IBM PC-compatibles).  No support for Sun or BSD disk
labels, or EFI/GPT tables used on Itanium and Intel Mac platforms.
* Cannot format partitions as NTFS or EXT3.  Can format as FAT
(12/16/32), EXT2, and Linux swap.
* Cannot resize FAT or EXT filesystems.  Can resize NTFS (Windows
XP) and Linux swap.
* No hardware support for serial mice
* No hardware support for PCMCIA

These limitations are intended to be fixed in future releases.
================================

Visopsys 0.69

http://visopsys.org/index.html

Visopsys (VISual OPerating SYStem) is an alternative operating system
for PC-compatible computers, written “from scratch”, and developed
primarily by a single hobbyist programmer since late 1997.

Visopsys is free software and the source code is available under the
terms of the GNU General Public License.  The libraries and header
files are licensed under the terms of the GNU Lesser General Public
License.

The bulk of Visopsys is a fully multitasking, 100% protected mode,
virtual-memory, massively-monolithic-style kernel.  Added to this is a
bare-bones C library and a minimal suite of applications — together
comprising a small but reasonably functional operating system which
can operate natively in either graphical or text modes.  Though it’s
been in continuous development for a number of years, realistically
the target audience remains limited to operating system enthusiasts,
students, and assorted other sensation seekers.  The ISO and floppy
images available from the download page can install the system, or
operate in ‘live demo’ mode.
=================================

SkyOS build 6915

http://www.skyos.org/?q=node

The Sky Operating System, or SkyOS, is an operating system written for
x86-based personal computers. SkyOS was created in 1996 by Robert
Szeleney as a small bootloader. In the past 8 years, SkyOS has evolved
into a full-featured, modern operating system, with a goal to be the
easiest to use desktop operating system available for the average
computer user. The development staff has also increased to include
business, software, and graphics developers.
=================================

Syllable 0.6.5

http://web.syllable.org/pages/index.html

So what exactly is Syllable and what can it do for you? We are
producing two operating systems: Syllable Desktop and Syllable Server.
They are meant for different roles, but they share the goals of being
as easy to use as possible while still being very powerful. Syllable
Desktop is meant to run on personal computers. It is fully graphical,
so it is easy to operate for people who don’t care about diving into
technical details. At the same time, it also offers a traditional
command prompt environment that is well-known to technical-minded
people as an extra, so nobody loses out. Syllable Server is meant to
run on server computers - the ones that quietly do their work in
backrooms and that you can connect to over the network with your
personal computer. Thus, Syllable Server and Syllable Desktop are made
to work together. You can happily use them on their own and with many
different systems, but used together they will provide extra
advantages. For example, if you want to set up a network of machines,
it is easier if both desktop and server computers are alike, at least
in their software. There will be less you will need to learn and
remember to accomplish your tasks

Protect your privacy…

This week I’m sending a link to a neat site
that has some very interesting software for
protecting your privacy. If you’re familiar with
the XP Antispy software that turned off a lot
of the phone home features of  XP, you may
be interested in this site which offers a similar
application for XP and another app that turns
off ET in Vista. There are also several nice
free tools offered too. One thing about the
privacy apps is that tend to trigger false virus
alerts. Read the FAQ.

[8~{} Uncle Monster
==============================

=======

The main site for all of the software is:

http://xpy.whyeye.org/

xpy 0.10.2

Small tool which disables the default threats of a Windows XP
installation. Besides disabling Windows and some of its components to
communicate with Microsoft servers, xpy improves privacy settings and
your system’s security.

Features:
- Disable Windows communicating with Microsoft
- Disable questionable services
- Tweak Internet Explorer and Windows Media Player
- Remove Windows Messenger
- Improve privacy and security
- Improve performance

Though xpy is smaller than 60 kilobytes, it can close serious threats
(i.e. DCOM) on long distance, where large service-packs can only
protect you until a new security hole has been found.

Make sure you carefully choose the settings you want to apply, to
avoid problems. If you experience trouble, refer to the Frequently
Asked Questions or report a bug on SourceForge.

xpy is currently available in two versions, Redistributable and
Monolingual. The Redistributable build includes all available
languages and is intended for distribution on offline-media (i.e.
CD-ROM) or Intranet, while the Monolingual builds try to save
bandwidth for fastest possible download speed.
=====================================

Vispa 0.2.2.1

Vispa is a small software, securing your Windows Vista installation
and protecting your privacy. In addition to so-called Antispy
features, it disables common security threats and increases your
Windows performance.
There are many reasons why you wouldn’t want your operating system
connect to Microsoft’s server, be it for practical reasons, be it
suspicion or simply idealism. Based on the source-code of the
award-winning xpy (version 0.9.8), Vispa allows you to easily tweak
your Windows Vista for better privacy and security, even system
performance. Do a few clicks rather than finding the write registry
keys or program settings.

The only recommendation I can give is not applying settings without
vague knowledge of what you’re doing. Not every setting is desired in
every environment. Vispa is no tool for beginners, just a more
convenient way of tweaking your operating system.

Important: Some antivirus software might report Vispa as Spyware or a
Trojan. Vispa is an executable written and compiled using NSIS,
false-positives are unfortunately quite common among NSIS compiled
programs. The NSIS development team is aware of this situation and
constantly works with software companies to solve such issues.
=====================================

Tools

RunWithParameters
Tiny tool, which allows running any application with a parameter.
Instead of going to the Command Prompt, users can simply right-click
an application and enter the parameters in the pop-up window.

ClickFont
Tired of the installation procedure of TrueType fonts on Windows?
ClickFont allows easy installation of TrueType fonts with just two
mouse clicks, from anywhere in the system. All it takes is a
right-click on a font.

FileQuery
A Windows shell extension that lets its user query the internet for
unknown file types, media files or any other files. Just right-click
on any file to get information from it.

AV Scans, Hard Drive Monitor, and FREE Clip Art…

This week brings some interesting free software.
One application enables you to run multiple anti-
virus scans of your computer. Another is an on
screen hard drive activity indicator if you can’t see
your hard drive activity light. There is also a link to
a huge collection of ### FREE ### clip art.

[8~{} Uncle Monster
==============================

======

MultiAV v6.00

Information:
http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with-multiple-anti-virus-for-free/

Download:
http://www.pctipp.ch/ds/28400/28470/Multi_AV.exe

Most of the time one Anti-Virus software can’t completely protect your
computer from virus.

When you’re infected by persistent virus like Brontok, you’d be
frustrated if the installed Anti-Virus program on your computer is
unable to clean it. So how to scan computer using more than 1 type of
antivirus? Is the only solution to uninstall the current antivirus
program and then install another one? Fortunately not, here’s how you
can scan your computer with 4 types of Anti Virus program without
installing them.

Multi AV Scanning Tool by David H. Lipman is a malware removal utility
incorporating multiple command line scanners including McAfee, Sophos,
Kaspersky and Trend engines.

FREE Multiple anti virus program

To perform a scan using these vendor’s scanners choose the number on
the menu corresponding to the Anti Virus scanner you wish to run. The
scripts will automatically obtain the Anti Virus vendor’s files for
you. You don’t need to have them already resident on your computer.
After the files have been downloaded to your computer and have been
made ready to use, you will get a prompt if you want to run the
scanner or not. If you do want to perform a scan then click on “Yes”,
if you do not want to perform a scan (maybe you want to perform the
scan in SAFE MODE) choose “No”. If you choose No or ignore the prompt
it will return you back to the main menu. An example prompt for the
Sophos scanner is shown below.

FREE Sophos antivirus

If you choose to perform a scan then you will be prompted to see if
you want to perform the scan of a particular folder or location. An
example prompt for the Sophos scanner is shown below.

Sophos directory to scan

If you choose “No” then the AV scanner will proceed to perform a scan
of all hard disks on the computer. If you choose “Yes” then you will
be prompted to type in the path of the folder or the drive to be
scanned. The scanner will then proceed to perform the scan of that
location and all folders below it. If the drive or folder does not
exist (for example a syntax error is made in typing the folder
location) you will again be prompted to type in the path of the folder
or the drive to be scanned.

Sophos, McAfee and Kaspersky uses the same method above to ask you
which location you’d like to scan but for Trend, it will automatically
obtain the Trend Micro Sysclean utility and the latest Trend Pattern
File. After the files have been downloaded to your computer and they
have been made ready to use, you will see the following GUI utility.

FREE Trend Anti virus

By clicking on the “Advanced” button you can choose to scan a
specified folder or drive. If it is not chosen then Sysclean will scan
all hard disks.

Here is how to run Multi AV Scanning tool in your computer.
1. Download Multi_AV.exe from the link at the end of this article.

2. Run Multi_AV.exe (You must use the default folder C:\AV-CLS)

3. Run StartMenu.BAT or double-click on ‘Start Menu’ shortcut from
C:\AV-CLS folder.

There are two modes of operation: Remove/Delete and Detect Only. The
software defaults to the Remove/Delete mode which means that any files
that are deemed to be infected will be automatically removed from the
system and can which can not be cleaned. If you desire to use the
Multi AV Scanning Tool just to detect and not delete malware, you can
hit the letter “D” and place the software in a Detect Only mode of
operation. Those files found to be infected by malware will be logged
but not cleaned nor deleted from the system. These two modes of
operation are only for the McAfee, Sophos and Kaspersky modules since
the Trend Micro Sysclean utility has a GUI selection for detection
with or without file deletion.

Included in the C:\AV-CLS folder is a file called killproc.txt and is
used to shutdown or kill running processes prior to scanning the
platform. There are two processes already in the text file.
iexplore.exe (Internet Explorer) and firefox.exe (FireFox).
insert file name to kill task
You can add more file names in the text file making sure the last line
is a blank line. You can also bring up the killproc.txt text file by
hitting the “E” key in Multi-AV menu.

Note: The directory C:\AV-CLS is hard coded and should not be changed.
Multi AV should be used to remove an infection from your computer.
They are not a replacement for realtime antivirus protection but they
are an effective tool to remove malware (viruses etc.) from an
infected machine where antivirus software is disabled, out-of-date or
even if it is not installed at all.
=============================================

DKHardDrive-Light 1.2.2

http://www.dkpcode.com/html/downloads.html#DKHardDrive-Light

Product:  DKHardDrive-Light - Desktop (on screen) hard drive light.
Version: 1.2.2
Platform: Windows 2000/XP/Vista

DKHardDrive-Light monitors the computer’s hard drive and Notifies you
of activity by blinking a Red Light on the desktop.
Uses:
Monitor hard drive activity right from your desktop. This is helpful
when the computer’s hard drive light is not within view.
Have you ever wanted to know if the computer has locked up or is it
just busy? DKHardDrive-Light gives you a better understanding of what
the hard drive is doing.
Options:
- Single Drive mode (user selectable drive).
- Multiple Drive mode (all drives).
- Show or Hide file activity for Single and Multi drive modes (while
in Multi drive mode, “Hide activity” creates a light bar showing just
the drive lights).
Functionality:
- Stays on Top of all open application and operating system windows.
This keeps it always in view on your desktop, no matter what you are
working on.
- Monitors hard drive activity.
- Displays file access (created/deleted and changed) in a list as
activity occurs.
Requirements:
Microsoft .Net Framework Redistributable 2.0 available as a separate
download below.
How to check if you have .Net Framework already installed: click
Start, Control Panel, Add/Remove Programs. Then look for a line that
shows: Microsoft .NET Framework 2.0
If it is already installed then you do not need to download and
install .Net Framework Redistributable 2.0.
======================================

WPClipart 5.3

Home Page:
http://www.wpclipart.com/index.html

Download:
http://www.download.com/WPClipart/3000-2189_4-10777321.html?part=dl-10777321&subj=dl&tag=button

Description
This is a clean and safe site for children and others to find
good-quality, printable images.

Downloads from Uncle Monster: Freeware anti-rootkit programs.

GMER 1.0.14.14205

http://www.gmer.net/index.php

GMER is an application that detects and removes  rootkits.
It scans for:
# hidden processes
# hidden threads
# hidden modules
# hidden services
# hidden files
# hidden Alternate Data Streams
# hidden registry keys
# drivers hooking SSDT
# drivers hooking IDT
# drivers hooking IRP calls
# inline hooks
GMER also allows to monitor the following system functions:
# processes creating
# drivers loading
# libraries loading
# file functions
# registry entries
# TCP/IP connections
GMER runs on Windows NT/W2K/XP/VISTA
==============================

================

DarkSpy Anti-Rootkit V1.0.2 Test Version(Freeware)

http://www.rootkit.com/newsread.php?newsid=474

DarkSpy Introduction:
DarkSpy is a new rootkit detection tool from China.
It’s coded by two guys : CardMagic & wowocock,and support
some new features that can make the detection more effective.
DarkSpy is consisted of five parts:
1.Process:
Detect hidden process(even hide with FUTo…)
Force kill process(even Icesword)
2.Kernel Module:
Detect hidden kernel module(even hide with FUTo…)
3.File:
Detect hidden files
Force copy file
Force delete file
4.Registry function is not provided in test version.
5.Port:
Detect hidden ports
(Notice: DarkSpy don’t allow any kernel debugger to run!)
Environment supported by test version:
32bit Windows 2000(SP4 and later)
32bit Windows XP
32bit WIndows 2003
Single CPU without hyperthread
===========================================

Rootkit Buster v2.2.1014

http://www.trendmicro.com/download/rbuster.asp

Trend Micro RootkitBuster is a rootkit scanner that scans hidden
files, registry entries,

processes, drivers, and Master Boot Record (MBR) rootkits. In
addition, RootkitBuster can also

clean hidden files and registry entries. For more information, please
view readme.
=============================================

McAfee Rootkit Detective Beta v1.0

http://vil.nai.com/vil/stinger/rkstinger.aspx

McAfee Rootkit Detective Beta is a program designed and developed by
McAfee Avert Labs to

proactively detect and clean rootkits that are running on the system.

McAfee Rootkit Detective should only be used by knowledgeable
individuals at the direction of,

and with the support of, a representative from McAfee Avert Labs or
McAfee Technical Support.

Improper usage of this tool could result in damage to your
applications or operating system.
Download it

The Rootkit Detective Beta can be downloaded here.
Features

Following are the features of this program that are designed to
proactively detect and clean

rootkits from the system. This program is not dependent on any
signatures and can proactively

detect most of the existing and upcoming rootkits and allow the user
to clean them.

* Designed to proactively detect the system objects like
processes, files and registry that are

hidden to the user.
* Provides information about all running processes in the system.
* Provides information about various system hooks like SSDT(System
Service Descriptor

Table) hooks, user/kernel IAT/EAT(Import/Export Address Table) hooks.
* Allows the user to clean/remove the malicious objects from the
system by renaming/deleting

the hidden files/registry.
* Allows the user to terminate the malicious processes.
* Users can submit samples using the submission feature present in the tool.
* Users can also collect the samples manually after renaming them
and submit to

stinger@avertlabs.com for further analysis.

Rootkit Detective log file contains details of the hidden files. The
files once renamed after reboot

will have a .REN extension. User can search for the same on the system
and can submit these

files for further analysis with your comments to
stinger@avertlabs.com. Zip the files and password

protect with “infected” and mention “Rootkit Detective” in the subject
line when you send the mail.
Supported Operating Systems

* Windows XP Home Edition with SP2
* Windows XP Professional Edition with SP2
* Windows 2000 with SP4
* Windows 2000 Server
* Windows 2003 Server SP