Uncover some stealthy malware with Ring3 API Hook Scanner

Uncover some stealthy malware with Ring3 API Hook Scanner

Detecting rootkits and similar stealthy malware is always a challenge, so it can be a good idea to equip your PC with third-party tools which may be able to help.

The latest candidate is the rather geekily-named Ring3 API Hook Scanner, a new NoVirusThanks release which will scan your system for some user mode hook types (inline, IAT, EAT) and report on anything it finds.

As usual with NoVirusThanks tools, the program is well packaged and easy to use. There’s no installation, no hassles with adware or anything else, just unzip the download and launch either the 32 or 64-bit version, according to your needs (either way, there’s no driver required).

Then just click Scan and, if there are any hooks, within a few seconds you’ll see these listed, with details including the hook type, the owning process and module, the API function being hooked, relevant memory addresses, and so on.

Or, if even that’s too much hassle, a command line interface allows you to automate the process. Add a line such as “Ring3Scan.exe /pid:all /log:C:\Ring3Hooks.log” to a script and all you’ll have to do is check the log file occasionally for the latest details.

This is of course still a fairly basic tool, limited in what it can find, and no substitute for a full-strength rootkit detector.

Ring3 API Hook Scanner is also small, simple, easy and convenient to use, though, and that’s why it merits a place in every geek’s portable security toolkit.

This article originally appeared at softwarecrew.co.uk

Source: Copyright Software Crew

See more about:  antivirus  |  api  |  hook  |  novirusthanks  |  rootkit  |  usermode
 
 

Readers of this article also read...

Best Android apps this week 

Best Android apps this week

 
Google to sell “pure” Android Samsung Galaxy S4 

Google to sell “pure” Android Samsung Galaxy S4

 
Toshiba's new 2013 laptops unveiled 

Toshiba's new 2013 laptops unveiled

 
Microsoft faces IE8 zero-day, after US department serves watering hole attack 

Microsoft faces IE8 zero-day, after US department serves watering hole attack

 
How to: Stop online advertisers following you 

How to: Stop online advertisers following you

 

Latest Comments

Latest Poll

Which broadband network do you think is the best choice for Australia?



or View results
The Coalition's.
  19%
 
Labor's.
  63%
 
Screw this I'm going back to smoke signals and string on a can.
  19%
TOTAL VOTES: 1735

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads