Supported systems:
? 32-bit 2000, XP, 2003, Vista, 2008, Win7, Win8, Win8. 1 operating system.
? 64-bit Win7, Win8 and Win8. 1 operating system.
At present, the software has achieved the following functions:
Process, thread, process module, process window, process memory information viewing, process killing, thread killing, module unloading and other functions.
The kernel driver module view supports the memory copy of the kernel driver module.
SSDT, shadow SSDT, FSD, KBD, TCPIP, Nsiproxy, Tdx, Classpnp, Atapi, Acpi, SCSI, IDT and GDT, and can detect and recover ssdt hooks and inline hooks.
You can view more than 20 notification routines such as CreateProcess, CreateThread, LoadImage, CmpCallback, BugCheckCallback, Shutdown, Lego, etc., and support deleting these notification routines.
Port information view, currently does not support 2000 system.
View message hook
Detection and recovery of iat, eat, inline hook and patch of kernel module
Disk, volume, keyboard, network layer, etc. filter driver detection and support deletion.
Registry editing
Detect and restore processes iat, eat, inline hooks and patches.
File system view, supporting basic file operations.
View (edit) IE plug-ins, SPI, startup items, services, host files, image hijacking, file association, system firewall rules, IME.
Detection and recovery of object type hook
Detection and deletion of DPC timer
MBR Rootkit detection and repair
Kernel object hijacking detection
Worker thread enumeration
Enumeration of some callback information in Ndis
Hardware debugging register and debugging related API detection
Enumerates the callbacks of SFilter/Flgmgr.
System user name detection