<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
<channel>
	<title>Last 10 Submissions RSS Feed</title>
	<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&req=search&code=last_ten]]></link>
	<pubDate>Fri, 20 Nov 2009 19:32:20 -0600</pubDate>
	<ttl>1800</ttl>
	<description>This is the RSS feed of the last ten file submissions accepted into our database.  This RSS feed is always up to date as it is dynamically updated.</description>
	<item>
		<title>Kernel Detective</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=201]]></link>
		<description><![CDATA[Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result ... BSoD !<br /><br />Supported NT versions :<br />XP/Vista<br /><br /><br />Kernel Detective gives you the ability to :<br />1- Detect Hidden Processes.<br />3- Detect Hidden Threads.<br />2- Detect Hidden DLLs.<br />3- Detect Hidden Handles.<br />4- Detect Hidden Driver.<br />5- Detect Hooked SSDT.<br />6- Detect Hooked Shadow SSDT.<br />7- Detect Hooked IDT.<br />8- Detect Kernel-mode code modifications and hooks.<br />9- Disassemble (Read/Write) Kernel-mode/User-mode memory.<br />10- Monitor debug output on your system.<br /><br />And other interesting features !<br /><br /><br />Enumerate running processes and print important values like Process Id, Parent Process Id, ImageBase, EntryPoint, VirtualSize, PEB block address and EPROCESS block address. Special undocumented detection algorithms were implemented to detect hidden processes.<br /><br />Detect hidden and suspicious threads in system and allow user to forcely terminate them .<br /><br />Enumerate a specific running process Dynamic-Link Libraries and show every Dll ImageBase, EntryPoint, Size and Path. You can also inject or free specific module.<br /><br />Enumerate a specific running process opened handles, show every handle's object name and address and give you the ability to close the handle.<br /><br />Enumerate loaded kernel-mode drivers and show every driver ImageBase, EntryPoint, Size, Name and Path. Undocumented detection algorithms were implemented to detect hidden drivers.<br /><br />Scan the system service table (SSDT) and show every service function address and the real function address, detection algorithm improved to bypass KeServiceDescriptorTable EAT/IAT hooks.You can restore single service function address or restore the whole table.<br /><br />Scan the shadow system service table (Shadow SSDT) and show every shadow service function address and the real function address. You can restore single shadow service function address or restore the whole table<br /><br />Scan the interrupts table (IDT) and show every interrupt handler offset, selector, type, Attributes and real handler offset. This is applied to every processor in a multi-processors machines.<br /><br />Scan the important system kernel modules, detect the modifications in it's body and analyze it. For now it can detect and restore inline code modifications, EAT and IAT hooks. I'm looking for more other types of hooks next releases of Kernel Detective.<br /><br />A nice disassembler rely on OllyDbg disasm engine, thanks Oleh Yuschuk for publishing your nice disasm engine .With it you can disassemble, assemble and hex edit virtual memory of a specific process or even the kernel space memory. Kernel Detective use it's own Read/Write routines from kernel-mode and doesn't rely on any windows API. That make Kernel Detective able to R/W processes VM even if NtReadProcessMemory/NtWriteProcessMemory is hooked, also bypass the hooks on other kernel-mode important routines like KeStackAttachProcess and KeAttachProcess.<br /><br />Show the messages sent by drivers to the kernel debugger just like Dbgview by Mark Russinovich. It's doing this by hooking interrupt 0x2d wich is responsible for outputing debug messages. Hooking interrupts may cause problems on some machines so DebugView is turned off by default, to turn it on you must run Kernel Detective with "-debugv" parameter.]]></description>
		<pubDate>Thu, 16 Jul 2009 12:37:18 -0500</pubDate>
		<guid isPermaLink="false">201</guid>
	</item>
	<item>
		<title>Combofix</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=197]]></link>
		<description><![CDATA[Combofix by sUBs.<br /><br />*Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.<br /><br />Note: Geeks to Go no longer hosts a mirror of Combofix, but you can download it from one of the mirrors below, or click the <b><a href="http://www.geekstogo.com/forum/downloads.html&req=download&code=confirm_download&id=197" target="_blank">Download File</a></b> button to be connected to one of the mirrors automatically.<br /><br /><a href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" target="_blank">mirror 1</a><br /><a href="http://www.forospyware.com/sUBs/ComboFix.exe" target="_blank">mirror 2</a><br /><br />Please visit <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank">this webpage </a>for instructions on running the tool.]]></description>
		<pubDate>Sun, 12 Jul 2009 14:08:20 -0500</pubDate>
		<guid isPermaLink="false">197</guid>
	</item>
	<item>
		<title>TFC - Temp File Cleaner by OldTimer</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=187]]></link>
		<description><![CDATA[TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%&#092;temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files. <br /><br /><br />TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. <b>Be sure to save any unsaved work before running TFC.</b>]]></description>
		<pubDate>Thu, 28 May 2009 12:25:27 -0500</pubDate>
		<guid isPermaLink="false">187</guid>
	</item>
	<item>
		<title>SysRestorePoint</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=170]]></link>
		<description><![CDATA[Single Click System Restore Point by Doug Knox.<br /><br />Usage: Download SysRestorePoit.exe and save this file to your hard drive. Double click to run, it will leave a dialog telling you whether or not the Restore Point was successfully created.<br /><br />NOTE: If you get an error because you don't have .NET Framework, you can get it free from Microsoft here: <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5&displaylang=en" target="_blank">http://www.microsoft.com/downloads/details...;displaylang=en</a>]]></description>
		<pubDate>Fri, 10 Apr 2009 17:15:03 -0500</pubDate>
		<guid isPermaLink="false">170</guid>
	</item>
	<item>
		<title>Comodo Internet Security 3.8</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=165]]></link>
		<description><![CDATA[Comodo Internet Security, Comodo’s award-winning free security suite, offers prevention-based, default deny protection (DDP) technology to prevent malware in your PC. Conventional security suites ignore prevention, focusing only on the eventual detection of viruses. Basically, this means that it will allow all applications to access your PC resources by default as long as the application is not on your security software’s blacklist of already known malware. Comodo Internet Security includes an extensive white-list of safe executables called the 'Comodo Safe-List Database'. This database checks the integrity of every file and application asking for access to your PC. CIS will alert you of potentially damaging applications before they are installed. This is a ground-breaking method of protecting your PC. Traditionally firewalls only detect harmful applications from a blacklist of known malware - often-missing new forms of malware that are being created and launched daily. Comodo Internet Security is continually updated and currently almost 3,000,000 applications are in Comodo Safe list, representing virtually one of the largest safe lists within the security industry. Put simply, the good stuff gets in, and the bad stuff gets nowhere near your PC’s insides. Best of all, Comodo Internet Security is free for life.<br /><br /><b>Application Info URL </b><br /><a href="http://personalfirewall.comodo.com/index.html" target="_blank">http://personalfirewall.comodo.com/index.html</a><br /><br /><b>Download URL</b><br /><a href="http://download.comodo.com/cis/download/setups/CIS_Setup_3.8.65951.477_XP_Vista_x32.exe" target="_blank">http://download.comodo.com/cis/download/se...P_Vista_x32.exe</a>]]></description>
		<pubDate>Mon, 23 Mar 2009 13:50:06 -0500</pubDate>
		<guid isPermaLink="false">165</guid>
	</item>
	<item>
		<title>Driver Sweeper by guru3d</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=151]]></link>
		<description><![CDATA[My Description<br /><br />This program is good for successfully removing unwanted video card drivers / files if you recently updated your video card drivers or you are switching from ATI to NVIDIA or vice versa.  It will clean up the unwanted files that might give you errors from the information listed above.<br /><br />------------------------------------------------------------------------------------------------------------<br /><br />Guru3D's Description - Driver Sweeper is a fast tool to remove driver leftovers from your system. It's very important to remove your drivers on a proper way, because driver leftovers can cause problems like stability and startup problems. You can use it if you want to update/remove drivers from your system.]]></description>
		<pubDate>Fri, 02 Jan 2009 13:16:22 -0600</pubDate>
		<guid isPermaLink="false">151</guid>
	</item>
	<item>
		<title>WinAudit</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=144]]></link>
		<description><![CDATA[WinAudit is a tool for auditing a system. This can give you a full summary of your computer and is ideal for troubleshooting.<br /><br />WinAudit was made by Parmavex Services. Uploaded with permission of Parmavex Services.]]></description>
		<pubDate>Thu, 04 Dec 2008 05:03:19 -0600</pubDate>
		<guid isPermaLink="false">144</guid>
	</item>
	<item>
		<title>ERUNT - The Emergency Recovery Utility</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=113]]></link>
		<description><![CDATA[ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.<br /><br />Backing up the registry with ERUNT<br />----------------------------------<br /><br />Note: To ensure proper operation of ERUNT, you should be logged in as a system administrator.<br /><br />Start ERUNT, confirm the Welcome message.<br /><br />Type in the name of a restore folder where the backed up registry files should be saved, or click "..." to browse your computer's drives and select a folder. You can also simply leave the default, which is afolder named ERDNT inside your Windows folder, the advantage being that you have access to this folder from the Windows Recovery Console in case Windows does not boot anymore.<br /><br />Note that in the folder edit field, ERUNT by default appends a folder named the current date to the restore folder, which allows you to keep as many registry backups as you wish in the same restore folder, separated into the different creation dates. This feature, as well as the appearance of the date string, can be configured via the ERUNT.INI file, described later in this document. If you want the registry backup to be created directly in the folder you select, you can also simply remove the date from the folder edit field before clicking "OK".<br /><br />Next, select the backup options:<br /><br />- System registry: The current system registry, usually consisting of the files DEFAULT, SAM, SECURITY, SOFTWARE, and SYSTEM.<br /><br />- Current user registy: The registry files for the currently logged-on user, usually NTUSER.DAT and USRCLASS.DAT.<br /><br />- Other open user registries: Sometimes Windows has a few other user registries in memory. Examples for this are "generic" registries,  e.g. for user "EVERYONE", or registries of other users if you use Fast Task Switching in Windows XP. Check this option to backup all these additional user registries (if found) as well.<br /><br />Click "OK" and wait until the backup process is complete. (Note that depending on your system configuration this may take some time, and<br />that the first bar is NOT a progress bar, just an indicator that the program is still running.) The ERDNT program for later restoration of the registry is automatically copied to the restore folder.]]></description>
		<pubDate>Tue, 19 Aug 2008 22:48:39 -0500</pubDate>
		<guid isPermaLink="false">113</guid>
	</item>
	<item>
		<title>VundoFix</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=100]]></link>
		<description><![CDATA[VundoFix is a freeware removal tool for many of the known variants of Trojan.Vundo, Trojan.Conhook and other similar infections.<br /><br />Normal Usage for Removal:<br /><br />"Download VundoFix" to your desktop.<br /><br />    * Double-click VundoFix.exe to run it.<br />    * When VundoFix opens, click the Scan for Vundo button.<br />    * Once it's done scanning, click the Remove Vundo button.<br />    * You will receive a prompt asking if you want to remove the files, click YES<br />    * Once you click yes, your desktop will go blank as it starts removing Vundo.<br />    * When completed, it will prompt that it will reboot your computer, click OK.<br /><br />*****Note: It is possible that VundoFix encountered a file it could not remove.*****<br />In this case, VundoFix will attempt run on reboot, simply follow the above instructions starting from "Click<br />the Scan for Vundo button." when VundoFix appears at reboot.<br /><br />If you encounter a variant of Vundo that VundoFix does not detect or cannot remove please let us know on our forum located at <a href="http://www.atribune.org/forums/" target="_blank">http://www.atribune.org/forums/</a> in the HijackThis and Malware Removal section. The forum staff is always happy to help with removal of Vundo and other malware as well.]]></description>
		<pubDate>Thu, 29 May 2008 11:26:16 -0500</pubDate>
		<guid isPermaLink="false">100</guid>
	</item>
	<item>
		<title>FixIEDef</title>
		<link><![CDATA[http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=98]]></link>
		<description><![CDATA[This tool removes AntiSpyPro, Files Secure, IE AntiVirus, IEDefender, and Malware Bell. Eliminates the "Fake Alerts" generated by Trojan-Downloader.Win32.Delf. Removes Trojan-Downloader.Win32.Delf from the system.<br /><br />Warning: This is an Unicode compiled script and will not run on Win9x/ME.]]></description>
		<pubDate>Thu, 29 May 2008 11:03:51 -0500</pubDate>
		<guid isPermaLink="false">98</guid>
	</item>
</channel>
</rss>