|
|
|
|
|
Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system. It utilizes McAfee scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations. It detects more than 40 viruses, trojans and variants. The interface is simple and straightforward, just select the drive or folders to scan and click a button. You can choose an action to perform if a virus is detected (delete, prompt, qurantine or rename) and also configure which types of files to scan.
| Developer | Download | Screenshot | 98/ME/2000/XP | Rating: Excellent |
|
|
|
|
Multi Virus Cleaner is a free a comprehensive stand-alone scanner used to detect and remove major viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users to perform deep scans of their systems to detect and remove all infected files. You can use Multi Virus Cleaner and another antivirus scanner at the same time for the highest level of security. Multi Virus Cleaner is regularly updated and can detect over 2010 common viruses, worms, trojans, and dialers (including all variants of the Sober, MyDoom, and Bagle viruses). The program offers a scanner that requires minimal processing power for repairing a compromised system.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
Sophos Anti-Virus for Win32 Command Line Interface (SAV32CLI) .This is a 32 bit command line scanner. SAV32CLI runs on Windows NT/2000/XP computers only. For command line scanning of Windows 95/98/Me computers you should use SWEEP.EXE from the C:\Program Files\Sophos SWEEP directory. By default, SAV32CLI looks for copies of the following files: SAVI.DLL, OSDP.DLL, VEEX.DLL and VDL.DAT, in the same directory as itself to perform its scan. If one or more files is missing from this directory it will use the scanning engine and virus data of a locally installed version of Sophos Anti-Virus for Windows NT via the Sophos Anti-Virus Interface (SAVI). SAV32CLI.EXE, SAVI.DLL, OSDP.DLL, VEEX.DLL and VDL.DAT are provided on the Sophos Anti-Virus CD in the WIN32\I386\SAV32CLI folder (Intel version) or WIN32\AXP\SAV32CLI (Alpha version). The following archive types are supported: Arj, Cmz, Gzip, Rar, Tar, Zip, etc...To scan all archive types, use -archive. What's New : Virus engine version: 2.31.6; New virus information; Virus data version: 3.98, October 2005; Includes detection for more than 100000 viruses, trojans and worms.
| Developer | Download | ME/NT/2000/XP | Rating : Excellent |
|
|
|
|
Cure your computer suffering from viruses, Trojan horses and other malicious programs with free Dr.Web CureIT! utility. Having downloaded this utility, based on the Dr.Web scanner for Windows, you can quickly scan your computer and, if a virus is found, cure it without installing the Dr.Web anti-virus program. This utility is armed with the most up-to-date add-ons to the virus bases updated two times per hour- no other anti-virus company can offer you such frequently updated add-ons. Created in early 90s in Russia by Igor Daniloff, Dr.Web has always reflected its author’s basic philosophy: security means no compromise. Having appeared as the response to the growing threat of polymorphic viruses, the anti-virus still remains in the lead, always showing 100% results in the Virus Bulletin comparative reviews for this type of the most complicated viruses. No Install Required.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Excellent |
|
|
|
|
Utility for cleaning infection by: I-Worm.BleBla.b, I-Worm.Navidad,I-Worm.Sircam, I-Worm.Goner, I-Worm.Klez.a,e,f,g,h, Win32.Elkern.c, I-Worm.Lentin.a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p, I-Worm.Tanatos.a,b, Worm.Win32.Opasoft.a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p, I-Worm.Avron.a,b,c,d,e, I-Worm.LovGate.a,b,c,d,e,f,g,h,i,j,k,l, I-Worm.Fizzer
I-Worm.Magold.a,b,c,d,e, Worm.Win32.Lovesan, Worm.Win32.Welchia, I-Worm.Sobig.f
I-Worm.Dumaru.a-m, Trojan.Win32.SilentLog.a-b, Backdoor.Small.d, I-Worm.Swen, Backdoor.Afcore.l-ad, I-Worm.Sober.a,c, I-Worm.Mydoom.a-b,e, I-Worm.Torvil.d, I-Worm.NetSky.b-d, TrojanDownloader.Win32.Agent.a-j, I-Worm.Bagle.a-j,n-r,z, Worm.Win32.Sasser.a-d,f, Backdoor.Agent.ac, Trojan.Win32.StartPage.fw.
Command line:
/s[n] - to force scanning of hard drives. Program will scan hard
drives for I-Worm.Klez.a(e,f,g,h) infection in any case.
n - include scanning of mapped network drives.
/y - end program without pressing any key.
/i - show command line info.
/nr - do not reboot system automatically in any case.
/Rpt[ao][=] - create report file
a - add report file
o - report only (do not cure/delete infected files)
Return codes:
0 - nothing to clean
1 - virus was deleted and system restored
2 - to finalize removal of virus you should reboot system
3 - to finalize removal of virus you should reboot system and start
program the second time
4 - program error.
| Developer | Download | Mirror | 98/ME/NT/2000/XP | Rating: Very Good |
|
|
|
|
The F-Secure F-Bot utility disinfects computers infected with all known by March 2005 variants of the following backdoors:
- Wootbot (also known as Backdoor.Win32.Wootbot)
- Agobot (also known as Backdoor.Win32.Agobot)
- Forbot (also known as Backdoor.Win32.Forbot)
- Rbot (also known as Backdoor.Win32.Rbot)
- Spybot (also known as Worm.P2P.Spybot)
- IRCBot (also known as Backdoor.Win32.IRCBot)
- SDBot (also known as Backdoor.Win32.SdBot)
- Poebot (also known as Backdoor.Win32.Poebot)
- Codbot (also known as Backdoor.Win32.Codbot)
The F-Bot utility can also disinfect computers that are infected with new variants of these backdoors, however disinfection will only work if these variants are detected generically by AVP engine.
| Developer | Download | Mirror | 98/ME/NT/2000/XP | Rating: Very Good |
|
|
|
|
ArcaClean is a free tool for removal of popular internet worms (Blaster, Beagle, NetSky, Sober and others). This application scans all computer disks and removes all copies of detected worms as well as reverses the changes in the system configuration caused by worms.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating: Good |
|
|
|
|
Microsoft Windows NT/2000/XP ship with a handy system analysis utility called Task Manager. One of Task Managers many abilities is that it can list all running processes. However, there is a downside - Task Managers "End Process" feature isn't always able to kill a process for you! This isn't just frustrating, it also poses a security problem - what if the process you want to kill is a trojan? DiamondCS TaskMan+ launches Task Manager in a special way as to boost the security privileges of Task Manager, which in turn gives it a real unconditional license to terminate virtually ANY process. TaskMan+ is how Task Manager should be in the first place!
Note: Due to the security privilege modification that TaskMan+ makes, you must be logged in with Administrative privileges to use it.
| Developer | Download | NT/2000/XP | Rating: Very Good |
|
|
|
|
DiamondCS DelLater is a simple program that uses the only method that Microsoft recommend to delete files that are in use. This method is based on documentation from Microsoft that describes a function called MoveFileEx, and DelLater has been carefully designed to be technically accurate to the guidelines set forth in the article. Interestingly, this is the technique used by anti-virus scanners when they're unable to delete a file (such as a trojan) because it's in use. Although the MoveFileEx function isn't supported under Windows 95/98/ME, the article does describe how to implement the same functionality, which DelLater does. Don't worry if you don't understand the Microsoft article as DelLater simplifies everything. DelLater is the ideal program to use when you can't delete a file, no matter how hard you try. This is usually because an active process has an open handle to the file which prevents it from being deleted. Normally if you close down all running programs you'll find that most files will then be free to delete, but that's not always the case, and in some cases it may even be a trojan that's preventing itself from being deleted.
To DelLater A File...
1. Run dellater.exe
2. Reboot (whenever you like).
That's all that's required. After rebooting and logging in you'll be able to see that the file you specified is no longer there.
| Developer | Download | 95/98/ME/NT/2000/XP | Rating: Very Good |
|
|
|
|
This free tool from Panda Anti-Virus automatically repairs infections of "popular" worms and viruses and restores original system and registry configuration. Panda Quick Remover can currently detect and remove the following infections: Bugbear, Palyh, Parite, Fizzer, Nicehello, Lovgate, Redlof, Lirva, Datom, Bride, Opaserv, Frethem, Dadinu, Lentin, Stator, Reeezak, Updater, Goner, Happy, Qaz, Msinit, Badtrans, Klez, Vote, Nimda, Sircam, Funlove, Anna Kournikova, Cool Notepad, Help, I Love You, Kak Worm, Matrix, Navidad, Pretty Park, Shell, Scrap e Verona....
| Developer | Download | Mirror | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
This is NOT a virus scanner. It does NOT protect you. It is a Malware Analyser which is be able to deal with new, unknown malware. This means you can scan your PC and it will "collect" suspicious files into one Folder called "MALWARE" (Subfolder of your Installation Folder).It is very very fast and detects a lot of brand new malware and even polymorphic viruses / worms. It can even create signatures (for some types of malware) full automaticaly. You can scan single files via Drag'n'Drop or whole Drives / Folders via the "Collector Mode". This program does NOT delete any files. The Collector does only copy a suspicious file into the MALWARE FOLDER. And... it stills under development. There is not a daily update because it works completely without signatures.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Good |
|
|
|
|
Anti macro virus program. It can treat the most of macrovirus. To use it you must open ill htm-, asp-, htt-, etc. file, find virus, find unique signature inside, find first and last strings of virus. After starting you fill corresponding fields and run the process. It makes virus search in file types that you defined over the all disks of your computer. When the program finds signature inside the current file it removes all virus lines from begin to end. File can include some copes of virus. It will remove all of them.. Good advise: do not use this product if you are not advanced user and cannot understand what it does. It is not easy to use and so on. Default values of fields are preset for remove macro virus "I am sorry". VC++ v.6.0 sources are published. Free for use and modification. Please read help file and an article on brigsoft.com for more information.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Good |
|
|
|
|
The program is the whole complement to your virus scanner. The great advantage is, that WinHKI Anti-Virus checks the background of Windows whether there are suspicious modifications. It works completely on system check in this case. If there is a virus or worm, which have overlooked from your virus scanner or haven't recognized, WinHKI Anti-Virus will join in. It examines files, which nest in the system or files, which change their size suddenly. For that are mostly Win32-PE-viruses responsible. The program only requires 0,2 MB of place on the hard disk.
Advantages:
-> finds with the system check new still unknown viruses, worms and trojans
-> you don't need a virus database
-> it checks the complete system for suspicious modifications
-> whole complement to your virus scanner
-> extremely fast, you only need about 0,2 MB on the hard disk
-> works completely selfcontinuously in the background and announces suspicious files
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
Backwork recognizes many different trojan horse types (apart from BackOrifice). BackWork is an Anti-Back Orifice tool. Back Orifice is a trojan horse that infects Windows 95 - 98 personal computers (in some cases also Windows NT). After a computer is infected by this trojan, people can gain full access and control over the infected computer. The attacker uses the Internet to connect to your computer. Then the attacker can browse your hard drive, read your e-mail, can intercept your passwords, run programs, delete files, etc. Backwork is a resident program which constantly scans your system for the trojan horse. If it finds it, it will remove it. Unlike other programs, Backwork works. (Out of 10 anti-Back Orifice tools, 2 where infected with the trojan horse themselves..., and several didn`t find all possible variants of the virus, this one is clean, and working on all variants of Back Orifice) .
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
Most of the worms, in particular the most famous, use known vulnerabilities in Windows services which are enabled by default and that often can't be disabled via the OS's configuration. Even with these services patched with Microsoft security fixes, they are still exposed to the Internet at large ready to be exploited by the next exploit. Server side services are not covered by windows worms doors cleaner which aims only home users computers, who themselves shouldn't run any webservers.
These webservers should be patched and can't really be disabled without removing the service offered to the Internet (like the website).
These ports/services on client side are :
* DCOM RPC (listen on port 135) MS03-026
* RPC Locator (port 445) MS03-001, MS04-011
* NetBIOS (ports 137/138/139) MS03-049
* UPNP (port 5000) MS01-059
* Messenger service (uses RPC/NetBIOS ports) MS03-043
Windows Worms Doors Cleaner allows you to close these services the worms rely on.
| Developer | Download | Screenshot | 2000/XP | Rating : Very Good |
|
|
|
|
The purpose of this program is early detection of infection from boot viruses and to provide a daily check of system critical files. When computer starts, it reads informations stored into first sectors of the hard disk, a necessary procedure for a correct system startup. Many viruses, adding themselves to boot code, take advantage of this mechanism in order to gain control of the machine and replicate themselves to infect as many computers as possible. Every times Startest 3.5 is run, a comparison is made between current MBR\boot sectors and the configuration detected during initial setup process, alerting for changes. In case of changes, the program extracts the added or changed code in hexadecimal format, offering the possibility of notification to the free services of anti-virus software houses. Moreover, the program checks every time is run some essential Windows Dinamic Link Libraries, helping in early detection of unknown viruses attack to the system. Some new viruses infact, ( i.e. Hybris virus ), take control of the system communication DLLs to gain access to the Internet, having the best possibility of spreading through e-mail services. This version of the program checks a larger number of critical Windows files, improving overall safety of the system. The program is a DOS-based application and it has been tested and works under Windows 95\98 and Me. This version does NOT work properly under Windows XP, 2000, NT. More detailed instructions about the program will be found in the accompanying readme files. Please read them carefully before using the program.
| Developer | Download | 95/98/ME | Rating: Good |
|
|
|
|
A multipurpose utility for removal of I-Worm/Bagle, I-Worm/Bugbear, I-Worm/Netsky, I-Worm/Sasser, PSW.Bispy, I-Worm/Atack...Download the remover vcleaner.exe. Restart your computer in Safe mode and run the remover on the infected computer. Note: Some viruses can stop the action during the removing process. In this case rename the vcleaner.exe to some different exe file (e.g. something.exe). Restart your computer in Safe mode (recommended) and run the remover on the infected computer.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating: Very Good |
|
|
|
|
It's now possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. In the past, pages that offer seemingly attractive downloads which contain such malware required you to click to start any download to your computer. Now it's become automatic, using features in the Windows operating system known as scripting. These scripts can load programs without you knowing, and then they run immediately. All you have to do is visit the site, without doing anything besides viewing the page. HTAstop acts as a brickwall against these scripts, disabling them so the download doesn't occur. HTAstop protects you against one variety of script, our IEClean covers all twenty seven.
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
The "DSO Exploit" (Data Source Object) was first reported by GreyMagic Software of Israel on February 27, 2002 and a "workaround" for Microsoft's defective code was provided by Axel Pettinger and Garland Hopkins on March 3, 2002. Their fix requires the user to manually edit the registry. Many computer users are extremely nervous (and justifiably so) about doing this, owing to years of warnings and advisories not to. This FREE utility will safely do it for those who do not feel confident running and editing "Regedit."
| Developer | Download | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|
|
|
Trend Micro System Cleaner is a stand-alone virus removal utility using the latest virus definition file from Trend Micro used to detect and remove major viruses. This self-extracting archive is a stand-alone fix package that incorporates the Damage Cleanup Engine and Template. It replaces the traditional fix tool by addressing a wide variety of system infections rather than a specific malware infection. This tool supports the following features: Terminate all malware instances in memory Remove malware registry entries Remove malware entries from system files Scan for and delete all malware copies in all local hard drives. This program is not to be used as a permanent anti-virus solution. You can use this tool to clean up an infected system or as a second opinion for your current anti-virus scanner. Version 2.905 October 20, 2005 can detect [107] new viruses by the virus definition file.
| Developer | Download | Screenshot | 95/98/ME/NT/2000/XP | Rating: Excellent |
|
|
|
|
Simple tool to detect and deactivate the Flux Trojan in the memory. Also included in a² Free .
| Developer | Download | Mirror | Screenshot | 2000/95/98/ME/NT/XP | Rating : Very Good |
|
|
|
|
This freeware utility allows you to capture a sample of almost any resident virus, should one be infecting your system. Unlike conventional anti-virus software, this program won't detect specific viruses, nor will it remove them. But 9 times out of 10, if a virus is alive on your system, Virus Trap will bottle a sample of the virus, ready for submission to anti-virus companies to determine what virus it is.
| Developer | Download | 95/98/Me/NT/XP/2000 | Rating : Very Good |
|
|
|
|
This free utility is designed to provide the most basic virus-protection solution to workstations. It scans and removes (optional) virus infected files and any illicit content. The free virus scanner contains all files (including virus tables) needed to execute the On-Demand scanner. It is updated once a month.
| Developer | Download | Screenshot | 98/ME/2000/XP | Rating: Good |
|
|
|
|
The McAfee CleanBoot product is a new recovery utility that can be used to scan and clean infected computers.CleanBoot is intended for use where serious infection is suspected. CleanBoot provides an in-depth scan of the boot sector and all the files on the supported disk partitions.!This is BETA software!, please use caution when installing it on your system!
Features :
CleanBoot Disk
Bootable options
Disk Scanning
File Repair
Scanning Options
Generate log files
WARNING :
McAfee CleanBoot is an unsupported emergency recovery utility, that should only be used when standard methods of cleaning an infected computer have proved ineffective.In rare circumstances it could cause additional damage to that caused by the virus.
| Developer | Download | Mirror | Screenshot | 98/Me/NT/XP/2000 | Rating : Very Good |
|
|
|
|
DiamondCS JPEGScan is a free, small, fast and easy-to-use scanner that has detection and repair capabilities for JPEG files infected with the MS04-028 exploit. It can detect all known variants of the exploit, and accomplishes this not by string searching or anti-viral signature scanning but rather by properly walking through all blocks in the JPEG searching for the undersized boundaries in comment sections that indicates the presence of MS04-028 infection. Repairing renders the file harmless by readjusting undersized boundaries to their proper size, and if the file was based on a real JPEG then it should also become viewable. If you simply want infected files deleted rather than repaired, JPEGScan can handle that also. JPEGScan also allows for one-click integration into Explorer's context menu, allowing you to easily right-click on any file, directory or drive and start scanning immediately for infected JPEG images. Although all users will find this tool useful, network administrators in particular will enjoy being able to sweep entire networks for infected images. For reasons of speed, optimization and accuracy, the main scan routines were written in assembly language, making JPEGScan basically as fast as it possibly can be.
| Developer | Download | 98/ME/NT/2000/XP | Rating: Very Good |
|
|
|
|
avast! Virus Cleaner is available free for every user. This tool will help you remove selected virus & worm infections from your computer. If, despite all the security measures you take, your computer gets infected by a virus or worm, it is necessary to disinfect your system somehow. While for some viruses the only 100% realiable method of disinfection is restoring your system from backups, for many common infections this is not really necessary and the virus/worm can be removed quite easily. So, in order to properly remove the worm from your computer, it is often necessary to make additional fixes in your system registry, delete the links from your Startup Folder etc. Here the avast! Virus Cleaner comes - it will find and remove selected worms from your computer, as well as fix the registry and startup items to make sure your system will work correctly after the disinfection.
| Developer | Download | Mirror | Screenshot | 98/ME/NT/2000/XP | Rating : Very Good |
|
|