A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #17581  by quark
 Fri Jan 04, 2013 10:30 am
Hello all.

new version gmer 2.0.18327 GMER - Rootkit Detector and Remover

2.0

- Added support for Windows 8
- Added full support for Windows x64
- Added Trace I/O function
- Added disk "Quick scan" function
 #17584  by B-boy/StyLe/
 Fri Jan 04, 2013 10:54 am
What a nice update we received today, LOL finally!!! :)

Thank you for sharing this. I am wondering why it took him so long since the developer already created a few x64 tools like aswMBR and aswar.

Anyway - GMER + MBAR + aswMBR + TDSSKiller + FRST are very promising combination. I hope that sUBs can gets CF ready for Windows 8 in the near future as well. :)



Regards,
Georgi
 #17648  by KeWss
 Tue Jan 08, 2013 12:53 am
Tested on Windows 7 + SP1 ( x64 ):
Code: Select all
nt!KeSetEvent+0x1e3:
fffff800`02ce1715 488b00          mov     rax,qword ptr [rax] ds:69f0:00000000`00000000=????????????????
-
IRQL_NOT_LESS_OR_EQUAL
Arg1: 0000000000000000, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
	bit 0 : value 0
	bit 3 : value 0
Arg4: fffff80002ce1715
also, it crashes during analysis:
Image