Security
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  just4fun
RegRun Security Suite
Not an antivirus. A powerful tool kit against Trojans, viruses, spyware, adware and rootkits
Features
Benefits

Startup Monitor...

Bootlog Analyser...

Advanced MSConfig...

Know more?
Screenshots

FAQ

On-line manual

Print PDF

One-click purchase
RegRun NIVA Platinum

NIVA+CD-ROM

Download trial
RegRun NIVA Platinum
Forums
Greatis Forum

NI Forum

Mickey Forum

Thank you!

International
Download Russian

Download Ukrainian

Join our localization team

Home Download Order Support   Newsletter Your shopping cart ?
RegRun against Trojans and Viruses

Trojan programs. What are they?

"A program that neither replicates or copies itself, but does damage or compromises the security of the computer. Typically it relies on someone emailing it to you, it does not email itself, it may arrive in the form of a joke program or software of some sort."
(Symantec Security Response - Glossary)

As you can see a trojan program need to be started automatically to begin its work. Prevent from starting this program and it will be not more dangerous than a dust on the road.

RegRun against Trojans

RegRun Watch Dog provides silent monitoring of the startup programs during your Windows working session. If RegRun WatchDog has detected changes to your registry or startup files, you will see a window similar to this:

You may quickly decline changes and restore your working startup.

What the startup holes are monitored by WatchDog?

Windows 95/98/ME

Files:

  • AUTOEXEC.BAT
  • CONFIG.SYS
  • WINSTART.BAT
Startup entries:
  • load, run in the WIN.INI
  • shell in the SYSTEM.INI

Registry keys:

  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunEx
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
  • HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKLM\Software\Microsoft\Active Setup\Installed Components
Any registry keys added to the trace list using Registry Tracer feature
(for example: Internet Explorer home page.)
Note! RegRun automatically adds to monitoring list:
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppInit
  • HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Start Page
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
  • HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute

File Extensions (may be expanded by user): pif, bat, com, exe.

VXD and Device drivers.

Finally: STARTUP and COMMON STARTUP folders.

Windows NT4/2000/XP:

Files:

  • %SYSTEMROOT%\SYSTEM32\config.nt
  • %SYSTEMROOT%\SYSTEM32\autoexec.nt
Startup entries:
  • load, run in the mapped to the registry WIN.INI
  • shell in the the mapped to the registry SYSTEM.INI

Registry keys:

  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunEx
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
  • HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKLM\Software\Microsoft\Active Setup\Installed Components
In addition to the registry keys above:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls
(by Registry Tracer)

File Extensions(may be expanded by user): pif, bat, com, exe.

Device drivers.

Services.

Another way to auto run trojan is substitution of the execution files and DLLs used in the startup. Most of known e-mail trojans substitute WinSock DLL.

RegRun has two features to prevent substitution.

Anti Replacement

RegRun automatically detects files that will be replaced with the next restarting of Windows. Windows needs to use special technology to replace opened files a like system DLL or executable files.

  • Windows 9X and Windows ME uses "wininit.ini" file located in Windows folder.
  • Windows NT/2000 uses registry value -
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations".
File Protection RegRun File Protection copies the original files to the special "storage" folder. RegRun File Protection supports full file comparison or signature checking. If you check the box "Use Signature Checking" RegRun makes an MD5 signature of the source file and saves it. While comparing, it compares the original signature with a calculated signature. File Protection allows to protect any files and to quickly restore them.

RegRun is the effective tool against trojans. The main advantage of the RegRun is its possibility to fight agains unknown trojans!

RegRun is the advanced trojan detector!

Viruses: "A program or code that replicates, that is infects another program, boot sector, partition sector or document that supports macros by inserting itself or attaching itself to that medium. Most viruses just replicate, a lot also do damage."
(Symantec Security Response - Glossary)

RegRun doesn't replace antiviral software.
It has the Infection Detector feature.

RegRun uses special technology to search for viruses unknown to antiviral software. This is not signature scanning, but rather "infection scanning". During a session, RegRun opens and monitors a number of "bait" program and macro files which are vulnerable to infection by any active virus. If any of these files change, RegRun will advise you, and facilitate your communication with your antivirus supplier by providing you before and after samples.

RegRun uses advanced technology to detect UNKNOWN viruses!

Buy Now! Purchase RegRun

Read more information...


Would you like to add your opinion?

Your Name (Not Required):

Your E-mail to contact (Not Required):


Description:

What's new?

March 7 2008
Partizan.exe is not a worm. Partizan.exe is a part of RegRun Suite, UnHackMe antirootkit. Updated. Symantec fixed false positive.

February 19 2008
RegRun Platinum Ukrainian 5.70

February 14 2008
Happy Valentine's day!
RegRun 5.7 released

February 11 2008
Spyware Doctor false positive. Partizan.sys wrong detection.

What is spXX.sys?

January 28 2007
Removing Medichi Rootkit

October 26 2007
Removal of Noskrnl.exe and Noskrnl.sys Rootkit (Spooldr clone)

July 25 2007
Removal Baidu rootkit (cnprov.sys)

July 24 2007
Removal Spooldr(ecard.exe) rootkit

June 25 2007
Fixing BSOD
in Winlogon Process

June 4 2007
Removal Areses Trojan

May 25 2007
Virus Feebs rootkit removal story

RegRun 5.5 beta updated

Release RegRun Reanimator 5.5.5.900

April 5 2007
What's this? Rthdcpl.exe - Illegal System DLL Relocation...

March 1 2007
Warning! Rootkit Unhooker

February 9 2007
Read our article about Unreal rootkit...

December 28 2006
Released free Rustock Rootkit(lzx32.sys) removal tool

November 29 2006
A#######.sys is a rootkit?

September 8 2006
Rootkit Removal instructions: ntsystem.exe

April 24 2006
What is BDGuard.sys?

April 17 2006
Virus or not? SPTD####.sys

March 31 2006
What is mc21.tmp, mc22.tmp, mc23.tmp?

January 19 2006
ICQCHK.exe, MSX.DLL free remover...
Educational discount...

Services
Ask Computer Guys

Windows startup programs

Articles
Using Registry Tracer...

RegRun against Trojans and Viruses

Specify an order for startup programs

RunGuard prevents a launch...

Using Bootlog Analyser...

They say
The Washinton Post suggests: "Consult the Greatis...

Wilders.ORG. Security advisors recommend...

Testimonials
You guys are awesome!!!!
Traci www.pentagonattack911.com

Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | just4fun

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2008 Greatis Software