1. Introduction
This is a company-supported Antirootkit, and the proven monitoring recording feature makes it a tool for manual analysis of samples. Optional components as Edelweiss (kill soft) are provided to the user.
1 Version of System support
NT 32bit/64bit
2 official website
http://www.huorong.cn/
2 When do I need it?
- You want to determine whether a program is a malicious program. Please run all this in the virtual machine. Internet cafes are also OK ...
You can export the logs to users to help you solve the problem.
- You want to know the security of your computer.
3 usage
Most of the operations are known by name.
Notable points:
- Use the C arrow to turn on monitoring .
- If you find that there is basically no log generated after you turn on monitoring , it is probably because you accidentally set the filter condition . Set in the location shown in a.
- If you want to see the action of the current target program immediately, click the button shown in arrow B. It is at the far right of the interface. If you want to stop your mind and monitor it, click it again.
4 Expand Learning
Easy to understand Anti-rootkit
5 note
Some of the bugs that are known may affect your use of:
- Log export error. When more than 300 logs are generated, there is no guarantee that subsequent logs can be exported.
- X of Death-if you accidentally point x in the Edelweiss Sword, your work will be destroyed, whether or not you are monitoring the status. The program does not exit with any hints.
Feedback has been given to the official.
Copyright NOTICE: This article is a blogger original article, in the case of the author and the source of the circumstances can be freely reproduced.
Anti-virus Tool-Edelweiss Sword