Skip to content
 

Rootkit Revealer

RootkitRevealer is an advanced rootkit detection utility.

Version: 1.71
Size:    226 KB
License: Freeware
OS: Windows 2000/XP/
2003/Vista/Windows7
Publisher Homepage

RootkitRevealer is an advanced rootkit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

RootkitRevealer successfully detects many persistent rootkits including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don’t attempt to hide their files or registry keys).

Since persistent rootkits work by changing API results so that a system view using APIs differs from the actual view in storage, RootkitRevealer compares the results of a system scan at the highest level with that at the lowest level.

The highest level is the Windows API and the lowest level is the raw contents of a file system volume or Registry hive (a hive file is the Registry’s on-disk storage format).

Thus, rootkits, whether user mode or kernel mode, that manipulate the Windows API or native API to remove their presence from a directory listing, for example, will be seen by RootkitRevealer as a discrepancy between the information returned by the Windows API and that seen in the raw scan of a FAT or NTFS volume’s file system structures.

Click for more screenshots...

VN:F [1.8.1_1037]
Rating: 5.0/5 (1 vote cast)
VN:F [1.8.1_1037]
Rating: +1 (from 1 vote)
Rootkit Revealer5.051

Popularity: 1%

  • Share/Bookmark

Related Softwares:

  1. Little Registry Cleaner
  2. Ashampoo Anti-Malware
  3. CCleaner
  4. Ashampoo® UnInstaller 4
  5. Spyware Detector
  6. System Cleaner

Leave a Reply