Gmer is primary a free rootkit scanner which offers additional functionality such as offering an Intrusion Prevention System and a Firewall. The interface looks very user friendly but the settings, options and the results require at last basic knowledge of rootkits and other means of harming the system to apply and interpretate them in the correct way. Gmer does notify the user if it spots something suspicious and displays those results in red in the main window. The two screenshots below show two typical scan results after performing a scan of your computer with Gmer.


As I said earlier, running Gmer is really easy. Just start the application and click on the scan button. Gmer does scan the system automatically and displays the results in the main window. If you spot red entries you should try and search the Internet for clues about them. It is possible to kill processes, service and files by right-clicking an entry in the main window.
Next to scanning for Rootkits you can also scan for Autostart entries, check running processes, services and modules and activate the Intrusion Prevention System and the Firewall. Take a look at this nice Gmer tutorial which walks you through a basic process.
Read Related Posts
2 Responses to “Check a system for rootkits with Gmer”
Trackbacks/Pingbacks
-
[...] is a viable alternative to already available rootkit detection programs like Gmer or AVG Anti-Rootkit. It is probably be best used in conjunction with these [...]

How to check your system for rootkits
Wallwatcher firewall and router analyzer
Automatically Identify Running Processes
Batch Kill Processes with Kill Process
Hello.
One can see all services on the computer (disabled, automatic, manual) using gmer as we can do it with services.msc, but, GMER also shows you boot and system services and lets you to modify them.
I tried to disable klif.sys (from kaspersky, having that software not running on memory and having it’s service disabled too) but gmer doesn’t seem to work, even in safe mode.
A popup menu appears when clicking on klif.sys line and I choose disable but it doesn’t change anything.
Does anybody know how to disable system and boot services?
I know I could remove some lines from regedit but I’d prefer something reversible.
I don’t mind to use any other software but usual ones don’t even show you that services.