MOD 00/06 · BOOT
PRE-FLIGHT CHECK // T-MINUS
--:--:-- UTC
MALWAREPROOF
000
INITIALIZING DEFENSE LINK
CLICK TO SKIP
--:--:-- UTC
SHIELD OK
OFFLINE-FIRST C++ EDR · PERSISTENCE HUNTER — NO CLOUD

Nothing hides. Not in the registry.

MalwareProof is a 100% local, offline-first C++ EDR and persistence hunter. It digs out WMI event consumers, scheduled tasks, registry Run/RunOnce keys, hijacked services, COM objects and process hollowing — with exact paths, keys and PIDs. Zero cloud. Zero telemetry. Instant execution.

THREAT LOCK
SCAN 0:000 · PID 4712 · PERSISTENCE HOOKS FOUND · DPR ≤ 2.0
TIERFREE · $29 · $99
TARGETSWINDOWS + LINUX
STATUSSHIELD ACTIVE
Scroll
MODULE 01 — DEFENSE
01 Defense // why malwareproof

It hunts what keeps malware alive

Most scanners check files and miss the real question: how does the malware start again after reboot? MalwareProof hunts persistence — the hooks that re-launch a threat every boot.

A native C++ engine walks every persistence surface — WMI event subscriptions, scheduled tasks, registry Run/RunOnce keys, hijacked services, COM class registrations — and maps process memory for injection techniques like process hollowing. Everything runs locally, with zero network access.

ScanWMI · Tasks · Registry · Services
TracePersistence → Process → PID
ReportExact Paths · Keys · PIDs
PurgeOne-Click Clean · Autorun Shield
0
Persistence surfaces scanned
0
Platforms · one engine
0
Cloud requests · ever
0%
Local C++ execution
Server room
THREAT RADAR · SIGNAL CLEAN

No threat can hide — not even in memory

MODULE 02 — ARSENAL
02 Arsenal // six weapons, one engine

A persistence hunting kit — from audit to forensics

01

WMI Event Hunt

Enumerates permanent event consumers, filters and bindings — the silent persistence used by living-off-the-land malware.

wmi_consumersevent_filtersbinding
02

Scheduled Tasks & Autorun

Walks every scheduled task and autorun registry key — Run, RunOnce, Startup folder, services — and maps each to its binary.

scheduled_tasksrun_keysautorun
03

Hijacked Services & COM

Detects service image-path swaps and COM class overrides — attackers re-point legit entries to their own payloads.

service_hijackcom_objectsimage_path
04

Process Hollowing

Scans memory for hollowed processes — a legit binary running attacker code in its own address space.

process_hollowingmemory_injectionvad
05

One-Click Purge

Paid tier. Removes every confirmed hook safely — task, key, service or consumer — and rolls back the entry point.

auto_purgecleanuplicenced
06

Forensic Export

Pro licence. JSON/HTML evidence reports for analysts — full chain of persistence → process → PID with timestamps.

forensicsjson_htmlcli_mode
MODULE 03 — SESSION
03 Comm session // live run

One session — one hunt

A real scenario: a dropper registers a hidden scheduled task and a WMI consumer, then hollows a system process. MalwareProof walks each persistence surface, traces the hooks to a PID, and reports the exact registry keys and paths — all locally, in under a minute.

SCAN TIME — 00:47
SURFACES WALKED — 6
HOOKS FOUND — 2 + 1 injection
VERDICT — PERSISTENCE MAPPED
HUNT LINK — local · offline LIVE
MODULE 04 — OPERATIONS
04 Flight operations // scenarios

Six standard missions

OP·01Keyboard
Silent autostart

WMI Event Hunt

Permanent event consumers, filters and bindings — the persistence layer attackers prefer because AV never looks there. Each consumer is traced to its owning process.

wmi_consumersevent_filtersbinding
OP·02Code on screen
Scheduled & autorun

Task & Run-Key Walker

Every scheduled task and registry autorun point — Run, RunOnce, Startup — resolved to its binary path. New and modified entries light up instantly.

scheduled_tasksrun_keysautorun
OP·03Servers
Backdoor ride-along

Service & COM Hijack

Detects service image-path swaps and COM class overrides that re-point legitimate entries to attacker payloads — the classic privilege-persistence trick.

service_hijackcom_objectsimage_path
OP·04Circuit board
Ghost process

Process Hollowing

Scans memory regions for hollowed processes — a trusted binary whose image was unmapped and replaced by attacker code in its own address space.

process_hollowingmemory_injectionvad
OP·05Security lock
Clean sweep

One-Click Auto-Purge

Licenced tier. Every confirmed hook — task, key, service or consumer — is removed safely and its entry point rolled back. No residue, no reboot roulette.

auto_purgecleanuplicenced
OP·06Globe network
Evidence chain

Forensic Export

Pro licence. Full persistence→process→PID chain in JSON/HTML — analyst-ready evidence with timestamps. CLI mode and portable USB builds included.

forensicsjson_htmlcli_mode
01 / 06
Nebula
CHANNEL 0:000 · NO INTERFERENCE

Radio silence means the threat is dead

MODULE 05 — FLIGHT RULES
05 Flight rules // five phases

Every defense session follows flight rules

T-5

Install

Deploy in seconds on Windows or Linux. Runs fully offline — no account, no cloud, no telemetry.

T-4

Scan

Walk every persistence surface: WMI consumers, scheduled tasks, Run/RunOnce, services, COM and memory.

T-3

Trace

Resolve each hook to its binary path and owning PID. Nothing is deleted without your consent.

T-2

Purge

Licenced tier. One click removes every confirmed hook safely and rolls back the entry point.

T-1

Export

Pro licence. Analyst-ready JSON/HTML evidence of the full persistence→process→PID chain.

Free — AuditFull local scan · exact paths, registry keys, PIDs · no auto-deletion$0
StandardOne-Click Auto-Purge · rollback · quarantine · Autorun Shield detection$9 · 30 DAYS
ProShield controls — exclusions & notifications · priority updates$29 · 90 DAYS
BusinessPortable USB · CLI mode · Forensic JSON/HTML export$99 · 365 DAYS
PlatformWindows 10+ · Linux 5.10+2 OS
EngineNative C++ · persistence + memory injectionLOCAL
Analysis100% On-device · offline-firstZERO CLOUD
TelemetryNone · ever0%
DeploymentNative installer · portable buildC++
COUNTDOWN COMPLETE

Hunt done. Nothing left to hide.

Run the free audit and see every persistence hook hiding on your machine — paths, keys and PIDs. Then unlock One-Click Auto-Purge with the Standard tier ($9/30d), live shielding with Pro ($29/90d), or CLI and forensics with Business ($99/365d). Subscription, zero cloud. Claim your licence key on the confirmation page — it's not emailed.

$ malwareproof scan --persistence --offline