system98 发表于 2011-1-19 13:41

Tuluka is a new powerful AntiRootkit

反rootkit工具.

http://www.tuluka.org/pic/scr/tdl3/tdl3_dev.png

http://www.tuluka.org/pic/scr/tdl3/tdl3_drv.png
Tuluka is a new powerful AntiRootkit, which has the following features:

-Detects hidden processes, drivers and devices
-Detects IRP hooks
-Identifies the substitution of certain fields in DRIVER_OBJECT structure
-Checks driver signatures
-Detects and restores SSDT hooks
-Detects suspicious descriptors in GDT
-IDT hook detection
-SYSENTER hook detection
-Displays list of system threads and allows you to suspend them
-IAT and Inline hook detection
-Shows the actual values of the debug registers, even if reading these registers is controlled by someone
-Allows you to find the system module by the address within this module
-Allows you to display contents of kernel memory and save it to disk
-Allows you to dump kernel drivers and main modules of all processes
-Allows you to terminate any process
-Is able to dissasemble interrupt and IRP handlers, system services, start routines of system threads and many more
-Allows to build the stack for selected device
-Much more..




Tuluka is tested on the following operating systems(32-bit):

[*]Windows XP SP0 SP1 SP2 SP3
[*]Windows Server 2003 SP0 SP1 SP2 R2
[*]Windows Vista SP0 SP1 SP2
[*]Windows Server 2008 SP0 SP1 SP2
[*]Windows 7 SP0 SP1
Work on other versions of the operating system is not guaranteed.
You use this software at your own risk. The author makes no warranty.

Tuluka v1.0.394.77MD5: 7ba2c1a8c6eac22a8f0d78409c8d485eSHA-1: 17905ad4af09e5f27d14616f66e806544a3591e2http://www.tuluka.org/any/download.gif

紫色 发表于 2011-1-19 13:57

呵呵 汉化就好了 现在只英语和其他一种外语

tcwjw 发表于 2011-1-19 14:03

                               不汉化,好多英语看不懂                                       

Hmily 发表于 2011-2-7 14:12

这个ARK没见过,看起来不错啊,收藏一份.

zhuwg 发表于 2011-2-7 18:08

下载下来看看行的ark

bbqq8 发表于 2011-2-9 23:58

谢谢楼主了!

ahyanglf 发表于 2011-2-10 08:49

偶也收藏下吧
页: [1]
查看完整版本: Tuluka is a new powerful AntiRootkit