GMER - detect and remove rootkits

Submit portable freeware that you find here. It helps if you include information like description, extraction instruction, Unicode support, whether it writes to the registry, and so on.
Post Reply
Message
Author
JimDriskill
Posts: 4
Joined: Tue Mar 27, 2007 3:26 pm
Location: Earth for the most part

GMER - detect and remove rootkits

#1 Post by JimDriskill »

GMER detects rootkits and more, check the homepage for details:
http://www.gmer.net/index.php
There is no install, just unzip to the location of your choice and run.

theboydanny
Posts: 18
Joined: Sat Mar 24, 2007 5:52 am
Location: Utrecht, Netherlands

#2 Post by theboydanny »

Not entirely portable imho, considering it creates gmer.exe, gmer.dll, gmer.ini and gmer_uninstall.cmd in C:\WINDOWS... And a quick scan of my registry shows that it installs a service, gmer.sys...
So after running GMER you'd have to UNINSTALL it. There's more info here http://www.gmer.net/faq.php.
Nevertheless I have used this app before and it's a good one, along with sysinternals RootKitRevealer (which is portable!). I have a zipped copy of gmer on my pendrive in case of emergencies. Besides, you won't run it on a daily basis...

User avatar
Midas
Posts: 6725
Joined: Mon Dec 07, 2009 7:09 am
Location: Sol3

Re: GMER

#3 Post by Midas »

GMER version v2.1.19357 released (changelog at http://www.gmer.net/#files).
Apparently GMER has been endorsed by AVAST: There's an article at PCWorld explaining how to use GMER:

TP109
Posts: 571
Joined: Sat Apr 08, 2006 7:12 pm
Location: Midwestern US

Re: GMER

#4 Post by TP109 »

Be aware that the "how-to instructions" are vague don't provide any details on how to use this tool besides performing a scan - this is also the case on the gmer home page and on many other sites. I've been aware of this app for some time and have used it, but finding out how to interpret the results is difficult. This site provides the reason for all the "mystery":
Discussions pertaining to how GMER works, what it can or cannot do, what the log results mean, etc is not available to the public in order to safeguard and protect the integrity of the tool from malware writers. As such, our discussion in public areas is limited and sometimes may appear vague or not fully address a specific question .....
Many sites just recommend sending the results to the developer for interpretation.

User avatar
Midas
Posts: 6725
Joined: Mon Dec 07, 2009 7:09 am
Location: Sol3

Re: TDSSKiller

#5 Post by Midas »

Security through obscurity it seems, then... not my favorite. :(

An easier alternative I found mentioned in the PCW article's comments would be Kaspersky's TDSSKiller, freely available from http://support.kaspersky.com/viruses/disinfection/5350.

I haven't really tested for portability, but TDSSKiller does appear to consist of a single executable with no settings, so the odds are good...

User avatar
webfork
Posts: 10821
Joined: Wed Apr 11, 2007 8:06 pm
Location: US, Texas
Contact:

Re: TDSSKiller

#6 Post by webfork »

Midas wrote:Security through obscurity it seems, then... not my favorite. :(
Agreed. I prefer my security tools open or at least more open than this. When someone says "how does it work?" and the answer is "trust us," that is to me a meaningless answer. Who is working on it? Why are they doing anti-rootkit work in the first place? Do they have a reputation to protect (like SysInternals)?

That's not to say this isn't a great tool created by some real badasses who want to stay behind a shield of anonymity, but I don't know how to evaluate that.

Edit: here we go: https://en.wikipedia.org/wiki/GMER

User avatar
Midas
Posts: 6725
Joined: Mon Dec 07, 2009 7:09 am
Location: Sol3

Re: TDSSKiller

#7 Post by Midas »

webfork wrote:Edit: here we go: https://en.wikipedia.org/wiki/GMER
  • It still doesn't enlighten me or the general public about the inner workings of the tool. In view of its public record, I'm more than willing to trust GMER -- but I'd like to at least know where I'm threading...

User avatar
Wolfghost
Posts: 253
Joined: Fri Jul 02, 2010 6:14 am
Location: Norway

Re: GMER - detect and remove rootkits

#8 Post by Wolfghost »

Updated GMER 2.2.19882

Windows XP/Vista/7/8/10
32-Bit and 64-Bit

GMER 2.2 Change Log:

Added support for Windows 10
Improved files & disk scanning

Download: http://www.bleepingcomputer.com/download/gmer/

Post Reply