查看: 1760|回复: 9
收起左侧

[分享] SpyDLLRemover v2 小巧的防间谍软件

[复制链接]
binbinges
发表于 2009-11-20 21:44:18 | 显示全部楼层 |阅读模式
SpyDLLRemover v2




主页地址
http://www.rootkitanalytics.com/
               
TOP                SpyDLLRemoveris the standalone tool to effectively detect and delete spywares fromthe system. It comes with advanced spyware scanner which quicklydiscovers hidden Rootkit processes as well suspcious/injected DLLswithin all running processes. It not only performs sophisticated autoanalysis on process DLLs but also displays them with variousthreatlevels, which greatly helps in quick identification of maliciousDLLs. The DLL search feature helps in finding DLL within all runningprocesses using just partial or full name. Then user can choose toremove the dll from single process or from all loaded processes withjust one click.

One of the unique feature of SpyDLLRemover isits capability to free the DLL from remote process using advanced DLLinjection method which can defeat any existing Rootkit tricks. It alsouses sophisticated low level anti-rootkit techniques to uncover hiddenuserland Rootkit processes as well as to terminate them.

Newer version comes with other cool features such as HTML based reportgeneration, sorting the process/dll list for quick analysis, enhanceduser interface etc.

Features of SpyDLLRemover v2               
TOP                 Here are some of the prominent and unique features of SpyDLLRemover which set it apart from any other tool of its kind.                        
                        
  • Advanced Spyware Scanner which efficiently discovers hidden Rootkitprocesses as well as suspicious/injected DLLs within all runningprocesses in the system.
  • Detection and removal of hidden userland Rootkit processes using sophisticated techniques such as
                                    - Direct NT System Call Implementation
                                - Process ID Bruteforce Method (PIDB) as first used by BlackLight
                                    - CSRSS Process Handle Enumeration Method
  • State of art technique for completely freeing the injected DLL fromremote process based on advanced DLL injection method using low levelimplementation which defeats any blocking attempts by Rootkits. This isone of those unique features found only in SpyDLLRemover.
  • Sophisticated DLL auto analysis which helps in seperating out thelegitimate modules/DLLs from the malicious ones. Such DLLs aredisplayed using different colors representing various threat levels forquicker and easier identification.
  • Integratedonline verification mechanism through ProcessLibrary.com to validateany suspcious DLLs. This makes it easy to differentiate between thespyware & legitimate DLLs.
  • DLL Tracerfeature to search for dll within the running processes using partial orfull name. Then user can choose to remove the dll from single processor from all loaded processes with just one click.
  • Sort the process/DLL in the list based on various parameters for easier and quicker analysis.
  • Detailed report generation of Spyware scanning result as well asprocess/DLL list in standard HTML format for offline investigation.
  • View the process/DLL properties for more information by just double clicking on the process/DLL entry in the list.
  • Feature to show all running processes in the system which has loadedthe selected DLL. Also user can click on "Remove DLL from ALL' buttonto quickly remove any such malicious DLL from all loaded processes.
  • Termination of suspicious or hidden process based on low levelimplementation which makes it very effective against any Rootkittechniques.
  • Displays detailed information about all running processes on the system
                                     - Process name
                                     - Process Id
                                     - Company Name
                                     - Process Description
                                     - Memory Utilization
                                     - Process Binary Path
                                     - Process File Size
                                     - File Install Date
  • Shows detailed information about each loaded DLLs within process to make it easier for manual analysis.
                                     - DLL Name
                                     - Company Name
                                     - Description
                                     - Comment about type of DLL (System, Hidden, Suspicious)
                                     - Load/reference count of DLL
                                     - Loading Type (static/dynamic)
                                     - DLL File Size
                                     - File Install Date
                                     - Base Address of DLL
                                     - Entry point of DLL
                                     - Full DLL File Path
  • It is standalone tool which does not require any installation and can be executed directly.
  • Enriched user interface along with more user friendly options makes it the cool tool.

Awards 获奖情况
               
TOP                                                                                                                               

Download SpyDLLRemover 下载
               
TOP                Platform:
                Windows XP, 2003, Vista, Longhorn (32 bit)
                On 64 bit platform, only 32 bit processes are supported.

                Hashes For SpyDLLRemover_v2_5.zip :
                MD5 Hash:  b0ae305f8e5231e811c42c8e2e1dfb4d
                SHA1:  c9a594cfeab84052c192688031675ace653d4fce
               
Click Here: VirusTotal Report on SpyDLLRemover v2.5 - zip

                        Click the following to download:
               
                               




[ 本帖最后由 binbinges 于 2009-11-20 21:54 编辑 ]

评分

参与人数 1经验 +5 收起 理由
一凡 + 5 感谢提供分享

查看全部评分

bukkake
发表于 2009-11-20 21:45:19 | 显示全部楼层
谢谢分享
我爱猫小咪
发表于 2009-11-20 21:50:52 | 显示全部楼层
貌似不错
binbinges
 楼主| 发表于 2009-11-20 21:51:20 | 显示全部楼层
同时,该公司还出产3种ROOKIT 工具

                                tools
KernelLand anti-rootkit

UserLand anti-rootkit                                The following are UserLand rootkit analytics tools:                       
                       
yyjcs
发表于 2009-11-20 23:10:27 | 显示全部楼层
谢谢,下来了解一下。
beike8256
发表于 2009-11-21 00:19:25 | 显示全部楼层
都没听说过,楼主真厉害,也不知道怎么找到的,呵呵!
田藏锋
发表于 2009-11-21 01:51:13 | 显示全部楼层
关键是是否免费。
bbs2811125
发表于 2009-11-21 02:16:42 | 显示全部楼层
感谢分享
qoo1919
发表于 2009-11-22 10:12:23 | 显示全部楼层
SpyDLLRemover 有誤報.小心使用...
智造中国
发表于 2009-11-22 10:30:54 | 显示全部楼层
用过的朋友说下效果。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-1 06:07 , Processed in 0.121446 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表