PDA

View Full Version : UnHackMe 3.1 Beta


dbarrow
04-14-2006, 11:52 AM
http://fileforum.betanews.com/detail/UnHackMe/1103207240/1
http://greatis.com/unhackme/downloadbeta.htm

Publisher's Description:

UnHackMe allows you to detect and remove a new generation of Trojan programs - invisible Trojans. They are called "rootkits". A rootkit is a collection of programs that a hacker uses to mask intrusion and obtain administrator-level access to a computer or computer network. The intruder installs a rootkit on a computer using a user action or by exploiting a known vulnerability or cracking a password. The rootkit installs a backdoor giving the hacker a full control of the computer. It hides their files, registry keys, and process names, and network connections from your eyes. Your antivirus could not detect such programs because they use compression and encryption of its files.

*reviews appear positive
I downloaded it but have not tried it out yet.

dbarrow
04-14-2006, 12:36 PM
Ran it... very simple program that does not appear to do much.
It appears to be checking System\Current Control Set\Services
As most rootkits run as a "service" this is not something difficult to do manually.

#1: Know what Services and the total number (at idle) you should have running and what they each belong to
You can see these in your Administrative Controls\Services
and third party apps like AdWatch.
Process Explorer will do something similar and goes even deeper listing what is running under generics like svchost
(usually 4 instances)

#2: Investigate any NEW services!
If you normally have 36 Services running and suddenly find 37, you want to find out what it is and what it belongs to. Trace them down with Process Explorer and see what owns them.

dbarrow
02-09-2007, 02:13 PM
http://fileforum.betanews.com/detail/UnHackMe/1103207240/1
UnHackMe 4.1 Beta 1 beta

*Seems to get fair ratings as a trojan detector.
Well designed and runs fast.
Causes no damage.
Worthy of the "toolbox"