    Default UnHackMe

    UnHackMe is a specialized Trojan removal tool that can detect and remove so called rootkits like Hacker Defender and clones. The program offers a simple interface and an option to exclude specific files from the scan.

    A rootkit is a program that a hacker uses to mask intrusion and obtain administrator-level access to a computer or computer network. The intruder installs a rootkit on a computer using a user action or by exploiting a known vulnerability or cracking a password. The rootkit installs a backdoor giving the hacker a full control of the computer. It hides their files, registry keys, and process names, and network connections from your eyes.

    Your antivirus could not detect such programs because they use compression and encryption of its files. The sample software is Hacker Defender rootkit.

    UnHackMe allows you to detect and remove Rootkits.

    Benefits to use UnHackMe:
    The main difference between UnHackMe and other antirootkit software
    is the detection method.
    UnHackMe tries to detect the hidden rookits by watching the computer from early study of the boot process till the normal Windows mode.
    UnHackMe is a first bootwatch antirootkit.
    Most modern antirookit programs try to detect the rookits when the rookit is already active. They use the very complex methods for detecting hooked system functions. But the rookit authors creates the new tricks and this war will not have the end.

    1. Unique detection method.
    Antirootkits tries to detect rootkits in the Normal Windows mode. But
    if a rootkit uses DKOM technology antirootkits will have a lot of problems
    in detection. UnHackMe uses the rootkit's weakness. The rootkits need a way to auto start after computer reboot.
    UnHackMe watches the Windows boot process from early stage till the normal mode.
    UnHackMe detects rootkits and other dangerous programs as well.
    Take a look at the list of removed rootkits here.

    2. Safety.
    Other antirookits software often cause the Windows blue-screen-of-death during rootkit detection.
    Antirookit use the kernel mode software and each error or incompatibility with hidden
    rootkit will cause immediate BSOD (blues screen of death).
    Also your antirootkit can conflict with installed legitimate device drivers on the user computer. There are a lot of computer configurations and the software authors could not test all of them for compatibility with their software.
    UnHackMe uses the kernel drivers only for making snapshots of the system state and UnHackMe is very stable.

    3. Detection speed.
    Antirootkits need a lot of time to check all hard drives, memory and the registry. A user needs to start the programs manually. UnHackMe automatically detects for rootkits every Windows boot. It takes about 5-7 seconds only.

    4. Compatibility.
    Antirootkits are often conflicts between each other. UnHackMe is fully compatible with antiviral and antirootkit software.
    A user can use UnHackMe and other antiviral/antirootkit software at
    the same time.

    5. Not only rootkit remover.

    Antirootkits could not protect against Trojans and malware. UnHackMe removes Trojans/adware/spyware as well as rootkits.

    UnHackMe= UnHackMe4+Partizan+Reanimator
    * UnHackMe4 detects hidden services registry keys, processes, services, drivers.
    * It uses UnHackMedrv.sys kernel driver.
    * Partizan watches the Windows boot process.
    * Reanimator detects and remove Trojans/Spyware/Adware using signature database .

    Looking to the progress of rootkit development since last year we have the opinion that the rootkit detection on the working computer is not real. We can not get you the 100% guarantee free of rootkits on the working computer connected to network.
    Partizan is a boot watch anti-rootkit.
    Rootkits authors like to play games.
    "We hide rootkit files/drivers/registry keys and after that try to find us they said.
    We didn't play the games.
    Our strategy is different:
    You hide yourself while we're watching how you do it.
    Each rootkit need a way to automatically start after computer reboot.
    We can detect it and remove a rootkit from auto start.

    What are the user benefits
    * Detecting kernel rootkits without a lot of BSOD.
    * Partizan checks the computer automatically during every Windows boot.
    * Partizan uses small number of computer resources.
    * Partizan takes only a couple seconds for checking. Compare it with full disk scan.
    * Partizan is a powerful. It can detect a remove any kernel/usermode rootkit, Trojan/Spyware/Adware components.
    * You can use other anti-rootkit software in addition to Partizan as well.

    How does the Partizan work
    Partizan activates several agents for monitoring the Windows boot process.
    * Anti-Bootkit. Used against Bootkit rootkits located in the boot sectors (in development).
    * Partizan boot driver. Used against Rustock clone rootkits. It can trace registry services and delete a service. Partizan driver starts on the early stage of the Windows boot process. Partizan driver has additional "safe" mode allows to skip processing of the Winlogon and similar registry keys by Windows operation system to avoid infection and for easy removing infection.
    * Partizan Native application. It is started from the BootExecute registry key. Partizan deletes files/streams and service keys.
    * Secure Start. It starts before Windows shell starts using RunOnceEx key.
    * Secure Start executes UnHackMe application for rootkits testing using information from the Partizan boot driver. Secure Start can remove Trojans/usermode rootkits/spyware/adware using RegRun Reanimator with Application Database.

