Nothing hides. Not in the registry.
MalwareProof is a 100% local, offline-first C++ EDR and persistence hunter. It digs out WMI event consumers, scheduled tasks, registry Run/RunOnce keys, hijacked services, COM objects and process hollowing — with exact paths, keys and PIDs. Zero cloud. Zero telemetry. Instant execution.
It hunts what keeps malware alive
Most scanners check files and miss the real question: how does the malware start again after reboot? MalwareProof hunts persistence — the hooks that re-launch a threat every boot.
A native C++ engine walks every persistence surface — WMI event subscriptions, scheduled tasks, registry Run/RunOnce keys, hijacked services, COM class registrations — and maps process memory for injection techniques like process hollowing. Everything runs locally, with zero network access.
No threat can hide — not even in memory
A persistence hunting kit — from audit to forensics
WMI Event Hunt
Enumerates permanent event consumers, filters and bindings — the silent persistence used by living-off-the-land malware.
Scheduled Tasks & Autorun
Walks every scheduled task and autorun registry key — Run, RunOnce, Startup folder, services — and maps each to its binary.
Hijacked Services & COM
Detects service image-path swaps and COM class overrides — attackers re-point legit entries to their own payloads.
Process Hollowing
Scans memory for hollowed processes — a legit binary running attacker code in its own address space.
One-Click Purge
Paid tier. Removes every confirmed hook safely — task, key, service or consumer — and rolls back the entry point.
Forensic Export
Pro licence. JSON/HTML evidence reports for analysts — full chain of persistence → process → PID with timestamps.
One session — one hunt
A real scenario: a dropper registers a hidden scheduled task and a WMI consumer, then hollows a system process. MalwareProof walks each persistence surface, traces the hooks to a PID, and reports the exact registry keys and paths — all locally, in under a minute.
SURFACES WALKED — 6
HOOKS FOUND — 2 + 1 injection
VERDICT — PERSISTENCE MAPPED
Six standard missions
Radio silence means the threat is dead
Every defense session follows flight rules
Install
Deploy in seconds on Windows or Linux. Runs fully offline — no account, no cloud, no telemetry.
Scan
Walk every persistence surface: WMI consumers, scheduled tasks, Run/RunOnce, services, COM and memory.
Trace
Resolve each hook to its binary path and owning PID. Nothing is deleted without your consent.
Purge
Licenced tier. One click removes every confirmed hook safely and rolls back the entry point.
Export
Pro licence. Analyst-ready JSON/HTML evidence of the full persistence→process→PID chain.
Hunt done. Nothing left to hide.
Run the free audit and see every persistence hook hiding on your machine — paths, keys and PIDs. Then unlock One-Click Auto-Purge with the Standard tier ($9/30d), live shielding with Pro ($29/90d), or CLI and forensics with Business ($99/365d). Subscription, zero cloud. Claim your licence key on the confirmation page — it's not emailed.