Detect hidden userland rootkit processes using multiple techniques such as:
· Direct NT System Call Implementation
· Process ID Bruteforce Method (PIDB) as first used by BlackLight
· CSRSS Process Handle Enumeration Method
Displays detailed information about all running processes on the system:
· Process name
· Process Id
· Company Name
· Process Description
· Memory Utilization
· Process Binary Path
· Process File Size
· File Install Date
Shows detailed information about each loaded DLLs within process to make it easier for manual analysis:
· DLL Name
· Company Name
· Description
· Comment about type of DLL (System, Hidden, Suspicious)
· Load/reference count of DLL
· Loading Type (static/dynamic)
· DLL File Size
· File Install Date
· Base Address of DLL
· Entry point of DLL
· Full DLL File Path
Size (RAR): 14.2 Mb
2% recovery record
Download SpyDLLRemover 3.2 Portable