StreamArmor is the sophisticated tool for discovering hidden alternate data streams (ADS) as well as clean them completely from the system. It's advanced auto analysis coupled with online threat verification mechanism makes it the best tool available in the market for eradicating the evil streams. StreamArmor comes with fast multi threaded ADS scanner which can recursively scan over entire system and quickly uncover all hidden streams. All such discovered streams are represented using specific color patten based on threat level which makes it easy for human eye to distinguish between suspicious and normal streams.
StreamArmor has built-in advanced file type detection mechanism which examines the content of file to accurately detect the file type of stream. This makes it great tool in forensic analysis in uncovering hidden documents/images/audio/video/database/archive files within the alternate data streams. StreamArmor is the standalone, portable application which does not require any installation. It can be copied to any place in the system and executed directly.
Alternate Data Stream (ADS) is the lesser known feature of Windows NTFS file system which provides the ability to put data into existing files and folders without affecting their functionality and size. Any such stream associated with file/folder is not visible when viewed through conventional utilities such as Windows Explorer or DIR command or any other file browser tools. It is used legitimately by Windows and other applications to store additional information (for example summary information) for the file. Even 'Internet Explorer' adds the stream named 'Zone.Identifier' to every file downloaded from the internet.
Due to this hidden nature of ADS, hackers have been exploiting this method to secretly store their Rootkit components on the compromised system without being detected. For example, the infamous Rootkit named 'Mailbot.AZ' aka 'Backdoor.Rustock.A' used to hide its driver file into system32 folder (C:\Windows\system32) as a stream '18467'.
In short, ADS provides easy way to store the malicious content covertly as well as execute it directly without making even a bit of noise. Only sophisticated tools such as StreamArmor has the ability to discover and destroy these hidden malicious streams. For complete details on 'Alternate Data Streams' please refer to below article: 'Exploring Alternate Data Streams'.
Here are the highlights of prominent and unique features of StreamArmor which makes it stand apart from other existing tools in the market.
Here are the screenshots of StreamArmor showcasing its unique and unparalleled features...
Screenshot 1: StreamArmor detecting Rootkits such as HackerDefender, Agent.X, Vanquish etc in addition to other hidden streams.

*To zoom in - click the image*
Screenshot 2: StreamArmor showing all the discovered streams using specific color pattern based on their respective threat levels.

*To zoom in - click the image*
Screenshot 3: StreamArmor displaying the snapshot view of the selected Rootkit stream file which clearly shows that its a executable file (starting with "MZ").

*To zoom in - click the image*
Screenshot 4: Online threat verification of uncovered 'HackerDefender' Rootkit stream file using VirusTotal.com.

*To zoom in - click the image*
Screenshot 5: Online threat verification of uncovered 'HackerDefender' Rootkit stream file using ThreatExpert.com.

*To zoom in - click the image*
Screenshot 6: 'Scan Settings' of StreamArmor showing the default configuration.

*To zoom in - click the image*
Screenshot 7: General configuration dialog of StreamArmor that allows user to fine tune various options as per the needs.

*To zoom in - click the image*
Screenshot 8: Exported stream scan report in HTML format by Stream Armor showing scan summary along with detailed threat report.

*To zoom in - click the image*
Forensics:
PCI DSS 10.2, 12.9, A.1.4*,
SOX DS7, HIPAA 164.308(a)(1) and (a)(6),
FISMA IR-7, ISO 27001/27002 13.2.1, 13.2.3
*Shared Hosting Providers Only
Source : Security-Database
License:
Freeware.
Platform:
Windows XP, 2K3, Vista, Longhorn and Windows 7 (both 32 & 64 bit versions)
On 64 bit platform, only 32 bit processes are supported.
Hashes For StreamArmor_v1.zip :
MD5 Hash : d283e449332dd738f96bc60344688341
SHA1 Hash: 3bfdd9732efae250ed008f0b679bca45e148840b
Click the following to download:
ToolsCount
~~~~~~~~~~~~~~~~~~~
Spy DLL Remover61314
Stream Armor8531
Elfstat1680
KsiD1127
dwtf1033
SHC862
NOTE: Our tools are listed in many sites and torrents, which makes it hard for us to track all downloads. Hence, we are listing only the total installations from our website.