Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - What about a nice warm cup of Geek?

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. Rufus
7. McAfee Removal Tool (MCPR)
8. MusicBee
9. Sergei Strelec's WinPE
10. K-Lite Mega Codec Pack
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » Antivirus & Malware » Specific (Stubborn) Removal Tools » Phrozen RunPE Detector 2.0 » Download Now

Phrozen RunPE Detector 2.0


Author: Phrozen S.A.S.U.
Date: 06/22/2017
Size: 2.57 MB
License: Freeware
Requires: Win 10 / 8 / 7 / Vista / XP
Downloads: 14261 times

tip TIP: Click Here to Repair or
Restore Missing Windows Files
Download Phrozen RunPE Detector
Download@Authors Site
Download@MajorGeeks
Download@MajorGeeks

Rate This Software:
5 (4 votes)



MajorGeeks: Setting the standard for editor-tested, trusted, and secure downloads since 2001.


Download Avast Free Avast Free Antivirus Worried about finance scams?
Get free antivirus with AI-powered online scam detection Download Free!

-= advertisement =-
Phrozen RunPE Detector is designed to detect and defeat some suspicious processes using a generic method.

The RunPE is a very simple and efficient method, most commercial anti-virus heuristic scans detect this trick, but not everybody thinks a good commercial anti-virus solution is money well spent. When you understand the RunPE injection method, you can easily imagine a way to get rid of most of the possible versions by using a Memory PE Headers Scan of each process and comparing the Memory PE Headers to the Process Image Path PE Header version.

Since the Malware PE Header that has hijacked a legitimate process is very different from the legitimate process Image Path PE Header, we could detect the presence of a hijacked process.

RunPE is a technique that is used in several malicious ways. The two most common are:

  • FWB (Firewall Bypass): As its name suggests, this technique is implemented to bypass or disable the Application Firewall or the Firewall rules. Since most malware needs to connect to a Remote Command-and-Control (C&C) Server, it needs to connect to the Internet via the Firewall.
    Since most users are connected to the Internet at home, normally the installed Firewall would prevent the malware from connecting to the Internet. Using the RunPE technique to hijack a legitimate process that is authorized to reach the Internet, any malware could subsequently connect to the C&C without being detected by the Firewall.
  • Malware Packer or Crypter: script kiddies – immature hackers - use a well-known type of malware that is already detected by most anti-virus programs. They then try the obfuscate this malware to evade detection. To achieve this, they need to buy programs such as a Packer or a Crypter. The price depends on its ability to evade anti-virus programs, update intervals, the number of extra functions, etc.

    A Crypter will simply obfuscate or conceal the malicious code, and an anti-virus program will fail to detect it. A Packer will add an extra compression step to make the malware smaller. It is then easier to transfer, or it can be virtually invisibly added to a legitimate process. Therefore, it will be harder to detect when it is downloaded to the victim's computer. Here, RunPE is used to unencrypt the malware in memory and to place it into a legitimate process without being written on the disc.
    More advanced techniques exist for Crypting and Packing malware, but since most creators of Crypters and Packers developed from typical script kiddies that visited the same forums to get a basic knowledge, they all have learned to use the RunPE method.


  • Version History for Phrozen RunPE Detector:
    https://www.phrozen.io/changelog/3


    Screen Shots Screenshot for Phrozen RunPE Detector
    Official Download Mirror for Phrozen RunPE Detector Official Download Mirror for Phrozen RunPE Detector Official Download Mirror for Phrozen RunPE Detector


    Top Downloads In Specific (Stubborn) Removal Tools

    McAfee Removal Tool (MCPR) 10.5.374.0 [ 2024-11-14 09:24:54 | 12 MB | Freeware | 11|10|8|7 | 5 ]
    McAfee Consumer Product Removal Tool is designed for the complete removal of McAfee Security products in order to reinstall or install a different antivirus.

    Trellix Stinger (formerly McAfee Stinger) 13.0.0.372 [ 2025-06-09 08:56:46 | 47 MB | Freeware | 11|10|8|7 | 5 ]
    Trellix Stinger (formerly McAfee Stinger) detects and removes specific viruses. Video tutorial and portable version available.

    Kaspersky Virus Removal Tool 20.0.12.0 (09/13/2024) [ 2024-09-13 01:00:01 | 107 MB | Freeware | 11|10|8|7 | 5 ]
    Kaspersky Virus Removal Tool is a portable app designed to scan and disinfect an infected computer from viruses and other malicious programs.

    ZHPCleaner 2025.6.2.11 [ 2025-06-01 11:55:27 | 4 MB | Freeware | 11|10|8|7 | 3 ]
    ZHPCleaner is a freeware app designed to scan for and remove adware, hijackers, toolbars, and PUPs that may be included with your browser for free.

    Dr.Web Live Disk 9.0.1 (06/11/2025) [ 2025-06-11 01:00:00 | 860 MB | Freeware | 11|10|8|7 | 3 ]
    Dr.Web Live Disk will clean your computer of infected and suspicious files.

    « Orbot: Proxy with Tor for Android 17.3.2 · Phrozen RunPE Detector 2.0 · Who Stalks My Cam 3.0 »


    other news Tactical Briefings






    Comment Rules & Etiquette - We welcome all comments from our readers, but any comment section requires some moderation. Some posts are auto-moderated to reduce spam, including links and swear words. When you make a post, and it does not appear, it went into moderation. We are emailed when posts are marked as spam and respond ASAP. Some posts might be deleted to reduce clutter. Examples include religion, politics, and comments about listing errors (after we fix the problem and upvote your comment). Finally, be nice. Thank you for choosing MajorGeeks.
    © 2000-2025 MajorGeeks.com
    Powered by Contentteller® Business Edition