Rootkit Detector: Version 2
I recently decided to rework a piece of code I wrote earlier this year, and decided to expand upon it.
My intent is to eventually have something resembling a fully fledged rootkit-detector, but I think thats still a while off.
I did however add a few new functions that my previous version didnt have. Rootkit Detector is thus able to detect both SSDT pointer and detour (trampoline) hooks. Included is also the ability to detect processes hidden by various methods, this function does occasionally spit out process detritus.
I also had some fun and reworked the GUI and came up with a cool way of doing so. I thought it came out looking pretty stylish (as you can see in the screenshot below :P).
Note: wont work on pre XP-sp2 systems. Nor do I think it will work on Vista.