Antispy : Free But Powerful Anti Virus & Rootkits Toolkit
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
Development
IDE: Visual Studio 2008
Userspace: MFC
WDK: WDK7600
Third-party Library: Codejock toolkit pro
Features
Currently,the following features are available(including but not limited to):
Process Manager
Display system process and thread basic informations.
Detect hidden processes,threads,process modules.
Terminate, suspend and resume processes and threads.
View and manipulate process handles,windows and memory regions.
View and manipulate process hotkeys,privileges,and timers.
Detect and restore process hooks incluing inline hooks,patches,iat and eat hooks.
Inject dll,dump process memory.
Create debug dump,include mini dump and full dump.
Kernel Module Viewer
Display kernel module basic information,include image base,size,driver object,and so on.
Detect hidden kernel modules.
Unload kernel modules.
Dump kernel image memory.
Display and delete system driver service information.