SanityCheck

November 23rd, 2010

Description:
Advanced rootkit and malware detector

Size:

760 KB 

Date Added:

November 23rd, 2010 

Version:

2.01 

OS Support:

Windows 2000 / 2003 / 2008 / Xp / Vista / 7 

License/Program Type:

Freeware 

Price:

0.00 

Downloads:

42 
Editor's Opinion
SanityCheck is a versatile application designed to scan your system for rootkits and malware. It provides a comprehensive report containing all irregularities found. Free to use!
Editor's Description
SanityCheck is an advanced rootkit and malware detection tool for Windows which thoroughly scans the system for threats and irregularities which indicate malware or rootkit behavior. By making use of special deep inventory techniques, this program detects hidden and spoofed processes, hidden threads, hidden drivers and a large number of hooks and hacks which are typically the work of rootkits and malware. It offers a comprehensible report which gives a detailed explanation of any irregularities found and offers suggestions on how to solve or further investigate any situation.

Main Features of SanityCheck:

- Runs on almost all Windows versions - SanityCheck runs on most recent Windows versions including Windows XP, Windows Vista, Windows 2003 and 2008 Server. Unlike most other anti-rootkit software it also supports x64 editions of Windows. For an exact overview of the Windows versions supported by SanityCheck and the service packs required click here.

- Makes use of special deep inventory techniques - SanityCheck makes use of a special Windows feature (a GlobalFlag setting) which allows it to create a deep inventory of drivers, devices, processes, threads and a lot of other information about your system. By making use of this feature in combination with other techniques it is able to create a very thorough scan of irregularities on your system.

- Detect hidden processes - SanityCheck goes to incredible lengths to detect processes which hide themselves from the Windows taskmanager and programming interfaces. It uses seven unmentioned safe techniques to reveal hidden processes in both usermode and kernelmode.

- Detect obfuscated processes - Sanity Check detects processes which do efforts to obfuscate their names. This is a typical activity associated with malware.

- Detect processes attempting to appear as common system processes - Sanity Check detects for processes which appear as a standard Windows process.

- Detect processes with obviously deceptive names - Malicious processes which are received as email attachements often try to appear as an innocent document types. An example of such a process name is:
"foo.txt .exe"

- Detect processes without product, company or description information - Although not necessarily evil, SanityCheck checks for processes without a product, company or description resource information.

- Verify signatures and checksums of processes and kernel modules - Sanitycheck verifies digital signatures on processes and kernel modules and checks them for validity. It also verifies the validity of checksums.

- Detect SSDT hooks - SanityCheck detects kernel modules which hook the system service descriptor table. Although not necessarily the work of malware, SanityCheck will do every effort to detect the modules responsbile for these acts and generate a comprehensible report.

- Detect Import Address Table hooks - The program detects kernel modules which hook the entry points of exported kernel routines.

- Detect kernel object callout hooks - Although rarely used, kernel object callout hooks are incredibly powerful and have the potential to instrument the complete working of the Windows kernel. Currently we do not know of any security product which detects these hooks.

- Detect hidden drivers - SanityCheck detects various forms of kernel modules which are attempting to hide.

- Detect hijacked driver entry points - Hijacked dispatch entry points in drivers can be used by rootkits and malware for a wide variety of purposes. SanityCheck detects both drivers which have their entry points hooked as well as the modules reponsible for these actions.

- Find the culprit - Note that it is not always possible to make a clear distinction between malware and legitimate products. This is because certain products resort to aggressive controversial techniques as anti-piracy measures, to avoid debugging or even for anti-competitive purposes. Anitivirus or other security software that is installed on your system may be making use of rootkit-like techniques such as a hidden process in an effort to hide itself from malware. Such products may be involved in a controversial race along the lines of "defeat evil with its own weapons". For this reason SanityCheck does everything possible to pinpoint the modules and processes which are responsbile for these actions while remaining careful in drawing any conclusions.

- Comprehensible report - We do not believe in aggressively "fixing" malware with a single click of a button. This is because there is no such thing as a clear distinction line between malware and legitimate products which make of controversial techniques. "Fixing" hooks in the kernel is a very unsafe and despicable act which is only very likely to make your system crash or worse. Instead Sanitycheck leaves your system in an unaltered state while offering comprehensible suggestions on how to proceed in any situation.

- Optional expert mode - Optionally you can switch SanityCheck into expert mode. It will then display a wealth of information on drivers, devices, processes, threads, kernel objects and system routines which can be very useful for further analysis. A lot of the information available in expert mode cannot be obtained by any other existing utility other than a kernel debugger. Because the amount of information can be overwhelming and may be difficult to understand for novice users, it is turned off by default and only a comprehensible report is displayed.
SanityCheck VIDEO TRAILER
For more information, please watch the movie that contains installation and complete features demo
SanityCheck Award
SanityCheck Antivirus Scan Report done by Softoxi.com

SanityCheck Award
SanityCheck Video Tutorial done by Softoxi.com
SanityCheck Scan reports
avast! 4.8 Scan Report:

*
* avast! Report
* This file is generated automatically
*
* Task 'Simple user interface' used
* Started on 23 noiembrie 2010 16:05:35
* VPS: 101123-0, 23.11.2010
*

C:\Softoxi\Scan\sanitySetup.exe\inno.hdr [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\InfoAfter.txt [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\setup.exe\[Embedded_R#HELPER_EXE_AMD64] [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\setup.exe\[Embedded_R#HELPER_EXE_IA64] [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\setup.exe\[Embedded_R#REGDLL_EXE] [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\setup.exe\[Embedded_R#SHFOLDERDLL] [+] is OK
C:\Softoxi\Scan\sanitySetup.exe\{embedded}\setup.exe [E] Unknown packer version. (42051)
C:\Softoxi\Scan\sanitySetup.exe [+] is OK
C:\Softoxi\Scan\sanitySetup.exe:Zone.Identifier [+] is OK
Infected files: 0
Total files: 9
Total folders: 1
Total size: 1,5 MB

*
* Task stopped: 23 noiembrie 2010 16:05:35
* Run-time was 0 second(s)
*




Kaspersky Anti-Virus 2010 Scan Report:

Virus Scan: completed <1 minute ago (events: 25, objects: 22, time: 00:00:03)
23.11.2010 16:05:21 Task started
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe:Zone.Identifier
23.11.2010 16:05:21 Archive: Inno C:\Softoxi\Scan\sanitySetup.exe
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/exe/data0032.res
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/exe/data0033.res
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/exe/data0034.res
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/exe/data0035.res
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/exe
23.11.2010 16:05:21 OK C:\Softoxi\Scan\sanitySetup.exe/script
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0000
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0001
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0002
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0003
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0004
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0005
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/data0006
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#/data0032.res
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#/data0033.res
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#/data0034.res
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#/data0035.res
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe/#
23.11.2010 16:05:24 OK C:\Softoxi\Scan\sanitySetup.exe
23.11.2010 16:05:24 Task completed

Related software

MalAware

[MalAware] -> [Mal]ware [Aware]ness

Date updated: May 25th, 2012 | Downloads: 54 | Licence: Freeware

Spyware Doctor

Spyware Doctor defends your computer against malware attacks.

Date updated: May 25th, 2012 | Downloads: 111 | Licence: Shareware

Kaspersky Virus Removal Tool

Kaspersky Virus Removal Tool is a utility designed to remove all types of infections from your computer.

Date updated: May 25th, 2012 | Downloads: 279 | Licence: Freeware
Top Downloads
TuneUp Utilities

With more than 30 easy-to-use tools you get the maximum out of your PC....

Secure Folder

Secure Folder is a tiny, easy-to-use folder security software that lets you hide, loc...

D7

D7 is a tool for PC technicians to aid in many tasks and provide a uniform procedure ...

WinRAR

The powerful compression tool with many integrated additional functions to help you m...

Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and mo...

Dropbox

Dropbox is a reliable, secure software that syncs your files online and across your c...

Latest Video Trailers
Screenshot Captor Video Trailer

Screenshot Captor is a program for taking screenshots on your computer. It's differen...

MalAware Video Trailer

[MalAware] -> [Mal]ware [Aware]ness ...

Temp File Cleaner Video Trailer

This program only has one thing in mind, and that is deleting temporary files. All of...

Drives Monitor Video Trailer

Monitor hard drive activity with this handy gadget....

WExplorer Video Trailer

WExplorer is a small alternative to Windows Explorer....

Vanga Rengi Mangaro Video Trailer

Patch for Windows to use Filesystem Dialogs instead of default file dialogs....