开发工具:
文件大小: 6mb
下载次数: 0
上传时间: 2014-04-13
详细说明: PCHunter anti-rootkit is a free and handy toolkit for Windows with various powerful features for kernel structure viewing and manipulation.It offers you the ability with the highest privileges to detect, analyze and restore various kernel modifications and gives you a wide scope of the kernel.With its assistance, you can easily spot and neutralize malwares hidden from normal detectors. PCHunter currently supports the following Windows versions: Windows 2000 SP4 (32-bit only) Windows XP (32-bit only) Windows Server 2003 (32-bit only) Windows Vista (32-bit only) Windows Server 2008 (32-bit only) Windows 7 (32/64) Windows 8 (32/64) Windows 8.1 (32/64) Currently,the following features are available: *Process Manager View system process and thread basic information. Detect hidden processes,threads,process modules. Terminate, suspend and resume processes and threads. View and manipulate process handles,windows and memory regions. *Kernel Module Viewer Display kernel module information including ImageBase,Size,Driver Object,ImagePath,ServiceName and Load Order. Detect hidden kernel modules. Unload kernel module(dangerous). Dump kernel image memory. Display and delete system driver service information. *Hook Detector View and restore SSDT,Shadow SSDT,sysenter and int2e hooks. View and restore FSD and keyboard disptach hooks. View and restore kernel code hooks including kernel inline hooks,patches,IAT and EAT hooks. View and restore usermode process hooks incluing inline hooks,patches,IAT and EAT hooks. View and restore message hooks(both global and local). View and restore kernel ObjectType hooks. Display Interrupt Descriptor Table(IDT). *System Callback Viewer Display and remove Kernel Notifications(Process/Thread/Image/Registry/Lego/Shutdown/Bugcheck/FileSystem/Logon). *Network Viewer Display current network connections, including the local and remote addresses and state of TCP connections. View and delete IE plugins and context menu. View and restore tcpip dispatch hooks. Display winsock providers(SPI). View and edit hosts file. *Filter Viewer View and remove filters for common devices including disk,volume,keyboard and network devices. *Registry Viewer View and edit system registry. Detect hidden registry entries using live registry hive analysis. *File Explorer Detect hidden files using both disk analysis and driver methods. View and delete locked files and folders. View file basic information including NTFS Alternate Data Streams. *Autorun Manager Display and delete common autorun entries. *Service Manager Display Win32 service information (for Ring0 modules,it is included in Kernel Module Viewer). Change service status and configuration. *DPC Timer Enumerate and delete DPC Timer objects. *Miscellaneous View and repair common filetype assosications. View and repair image hijacks. *Settings Option to defense from process creation,thread creation,module load and message hook installation. Option to defense from file creation,registry key creation. Option to prevent system suspend,log-off,shutdown and reboot. Option to prevent locking workstation and switching destop. option to prevent setting system time. Warning:Use it at your own risk.This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY. 2013-10-06 V1.3: *Support Win8.1 2013-03-22 V1.2: *Added ClassInitData enumeration feature *Fixed several bugs. 2013-02-28 V1.1: *Added Sfilter enumeration feature *Added FltMgr Filter enumeration feature *Fixed several bugs. 2013-01-22 V1.0: *Finish the first version. ...展开收缩
(系统自动生成,下载前可以参看下载内容)
下载文件列表
相关说明
- 本站资源为会员上传分享交流与学习,如有侵犯您的权益,请联系我们删除.
- 本站是交换下载平台,提供交流渠道,下载内容来自于网络,除下载问题外,其它问题请自行百度。
- 本站已设置防盗链,请勿用迅雷、QQ旋风等多线程下载软件下载资源,下载后用WinRAR最新版进行解压.
- 如果您发现内容无法下载,请稍后再次尝试;或者到消费记录里找到下载记录反馈给我们.
- 下载后发现下载的内容跟说明不相乎,请到消费记录里找到下载记录反馈给我们,经确认后退回积分.
- 如下载前有疑问,可以通过点击"提供者"的名字,查看对方的联系方式,联系对方咨询.