Uncover some stealthy malware with Ring3 API Hook Scanner

August 9, 2012 – 06:51 by in News Print Share No Comment

Detecting rootkits and similar stealthy malware is always a challenge, so it can be a good idea to equip your PC with third-party tools which may be able to help.

And the latest candidate is the rather geekily-named Ring3 API Hook Scanner, a new NoVirusThanks release which will scan your system for some user mode hook types (inline, IAT, EAT) and report on anything it finds.

As usual with NoVirusThanks tools, the program is well packaged and easy to use. There’s no installation, no hassles with adware or anything else, just unzip the download and launch either the 32 or 64-bit version, according to your needs (either way, there’s no driver required).

You'll get all the necessary low-level details on any hooks the program finds

Then just click Scan and, if there are any hooks, within a few seconds you’ll see these listed, with details including the hook type, the owning process and module, the API function being hooked, relevant memory addresses, and so on.

Or, if even that’s too much hassle, a command line interface allows you to automate the process. Add a line such as “Ring3Scan.exe /pid:all /log:C:\Ring3Hooks.log” to a script and all you’ll have to do is check the log file occasionally for the latest details.

This is of course still a fairly basic tool, limited in what it can find, and no substitute for a full-strength rootkit detector.

Ring3 API Hook Scanner is also small, simple, easy and convenient to use, though, and that’s why it merits a place in every geek’s portable security toolkit.

Related Posts Plugin for WordPress, Blogger...

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.