# mohuihui/antispy

AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.

Repository: https://github.com/mohuihui/antispy
Canonical: https://ross.abutalabs.com/products/antispy
Language: C
License: NOASSERTION
License Family: other
Last push: 2021-04-22T03:04:43+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2489, "days_push": 1959, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1109, forks 426 (observed 2026-08-28T04:03:37.231919+00:00)

## What it is
AntiSpy is a free Windows anti-rootkit and antivirus toolkit that detects, analyzes, and restores kernel modifications and hooks with the highest privileges. It includes a userspace MFC GUI paired with a kernel driver to expose hidden processes, modules, and hooks that evade normal detectors.

## Use cases
- detect hidden processes and kernel modules on windows
- find and restore ssdt and inline kernel hooks
- analyze suspected rootkit infections
- dump process and kernel memory for malware analysis
- inspect and clean registry and file system anomalies
- view kernel notifications, filters, and system timers

## When to choose
- you need deep kernel-level inspection of a Windows system
- malware is hiding from conventional antivirus tools
- you want a free GUI-based rootkit detector with restore capabilities

## When to avoid
- you need a cross-platform or modern actively maintained tool
- you are on a non-Windows operating system
- you require official vendor support or recent Windows 10/11 kernel compatibility guarantees

## Facets
- artifact type: application
- maturity: maintenance
- function: security, reverse-engineering, developer-tools
- domain: security, windows, developer-tools
- platform: windows, cpp, c
- tags: anti-rootkit, kernel-hooks, malware-analysis, system-internals, mfc

## Member repositories
- mohuihui/antispy (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:37.231919+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:43:36.736635+00:00, confidence not recorded.
  - readme: https://github.com/mohuihui/antispy (fetched 2026-08-28T04:03:37.231919+00:00, sha 9d35941448fc)
- Data as of 2026-08-30T08:39:29.467469+00:00.
