ghacks Technology News

Check a system for rootkits with Gmer


Gmer is primary a free rootkit scanner which offers additional functionality such as offering an Intrusion Prevention System and a Firewall. The interface looks very user friendly but the settings, options and the results require at last basic knowledge of rootkits and other means of harming the system to apply and interpretate them in the correct way. Gmer does notify the user if it spots something suspicious and displays those results in red in the main window. The two screenshots below show two typical scan results after performing a scan of your computer with Gmer.

gmer rootkit scanner rootkit scanner

As I said earlier, running Gmer is really easy. Just start the application and click on the scan button. Gmer does scan the system automatically and displays the results in the main window. If you spot red entries you should try and search the Internet for clues about them. It is possible to kill processes, service and files by right-clicking an entry in the main window.

Next to scanning for Rootkits you can also scan for Autostart entries, check running processes, services and modules and activate the Intrusion Prevention System and the Firewall. Take a look at this nice Gmer tutorial which walks you through a basic process.




Tags: , ,
Categories: Operating Systems, Security, Tools, Windows


Read Related Posts


2 Responses to “Check a system for rootkits with Gmer”

  1. skan says:

    Hello.
    One can see all services on the computer (disabled, automatic, manual) using gmer as we can do it with services.msc, but, GMER also shows you boot and system services and lets you to modify them.
    I tried to disable klif.sys (from kaspersky, having that software not running on memory and having it’s service disabled too) but gmer doesn’t seem to work, even in safe mode.
    A popup menu appears when clicking on klif.sys line and I choose disable but it doesn’t change anything.

    Does anybody know how to disable system and boot services?
    I know I could remove some lines from regedit but I’d prefer something reversible.
    I don’t mind to use any other software but usual ones don’t even show you that services.

Trackbacks/Pingbacks

  1. [...] is a viable alternative to already available rootkit detection programs like Gmer or AVG Anti-Rootkit. It is probably be best used in conjunction with these [...]

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

© 2005-2009 Ghacks.net. All Rights Reserved. Privacy Policy - About Us