RootkitRevealer 1.71

RootkitRevealer 1.71 Screenshot RootkitRevealer is an advanced root kit detection utility.

Developer:   Sysinternals
      software by Sysinternals →
Price:  0.00
License:   Freeware
File size:   0K
Language:   
OS:   Windows XP/Vista (?)
Rating:   0 /5 (0 votes)

RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

RootkitRevealer can successfully detect all persistent rootkits published at www.rootkit.com, including Vanquish, AFX and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.

Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.

tags kernel mode  user mode  file system  mode rootkits  native api  the rootkit  remove the  the windows  the contents  api enumeration  process management  malware process  the native  

RootkitRevealer 1.71 screenshot


Download RootkitRevealer 1.71

 Download RootkitRevealer 1.71


Similar software

RootkitRevealer 1.71 RootkitRevealer 1.71
Sysinternals

RootkitRevealer is an advanced root kit detection utility.

Detection Master 3.1 Detection Master 3.1
GreenSpot Technologies

Detection Master is a powerful forensic utility which is easy to use.

Web CD 1.1 Web CD 1.1
Mike Singer

Web CD is a tool that launches your web site from the root of a CD.

Reverse Chords Finder 1.0 Reverse Chords Finder 1.0
Fast&Soft

Reverse Chords Finder will run a strong algorithm based on an advanced theory of chords.

Stellar Phoenix FAT Data Recovery Software 9.2 Stellar Phoenix FAT Data Recovery Software 9.2
Stellar Information Systems Pr

This Award winning FAT recovery utility which need not be installed prior to a data loss, provides easy recovery after partition table, boot sector and root directory are corrupt and result in data loss.

GetDataBack For FAT 2.31 GetDataBack For FAT 2.31
Runtime Software

GetDataBack for FAT helps you to recover files from drives with FAT12/16/32 file systems.

Remove Red Eye 1.0 Remove Red Eye 1.0
ReaSoft.com

Remove Red Eye is a photo correction tool.

Veeam RootAccess 1.0 Veeam RootAccess 1.0
Veeam Software

By default ESX Server 3 does not allow remote shell access (SSH) for the root account.

winButler 1.1.7 winButler 1.1.7
codesworth

winButler is a Windows productivity utility that can automate repetitive desktop operations into chores and chore lists that can be run via assignable hot keys.

Xtreeme MailXpert Professional Edition 3.0 Xtreeme MailXpert Professional Edition 3.0
Xtreeme GmbH

Xtreeme MailXpert Professional Edition is a processing software for Windows.