RootkitRevealer 1.71

RootkitRevealer 1.71 Screenshot RootkitRevealer is an advanced root kit detection utility.

Developer:   Sysinternals
      software by Sysinternals →
Price:  0.00
License:   Freeware
File size:   0K
Language:   
OS:   Windows XP/Vista (?)
Rating:   0 /5 (0 votes)

RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

RootkitRevealer can successfully detect all persistent rootkits published at www.rootkit.com, including Vanquish, AFX and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.

Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.

tags kernel mode  user mode  file system  mode rootkits  native api  the rootkit  remove the  the windows  the contents  api enumeration  process management  malware process  the native  

RootkitRevealer 1.71 screenshot


Download RootkitRevealer 1.71

 Download RootkitRevealer 1.71


Authors software

TCPView 2.4 TCPView 2.4
Sysinternals

TCPView is a little application that displays full details of all TCP and UDP endpoints on your system, including the remote address and state of TCP connections.

Regmon 7.04 Regmon 7.04
Sysinternals

Regmon is a Registry monitoring tool that will show you which applications are accessing your Registry, which keys they are accessing, and the Registry data that they are reading and writing - all in real-time.

Filemon 7.03 Filemon 7.03
Sysinternals

Filemon will monitor and display file system activity on a system in real-time.

Process Explorer 10.21 Process Explorer 10.21
Sysinternals

Process Explorer will show you information about which handles and DLLs processes have opened or loaded.

BGInfo 4.07 BGInfo 4.07
Sysinternals

BGInfo automatically generates desktop backgrounds that include important information about the system including IP addresses, computer name, network adapters, and more.

Similar software

RootkitRevealer 1.71 RootkitRevealer 1.71
Sysinternals

RootkitRevealer is an advanced root kit detection utility.

PcWedge 1.0 PcWedge 1.0
A+ Software

PCWedge is a useful utility to interfase RS232 serial Bar-Code Reader output and convert the data to keystrokes in any Windows application program as if it were being typed directly in the keyboard.

Find Compressed 1.0.1.2 Find Compressed 1.0.1.2
Exodus Development

The built-in command line utility compact.

Rootkit Unhooker 3.00.88.344 RC4 Rootkit Unhooker 3.00.88.344 RC4
UG North EP_X0FF (EvilPhantasy

Rootkit Unhooker - an advanced rootkit detection/removal utility Here are some key features of "Rootkit Unhooker": Service Descriptor Table hooks detection · Includes Service Descriptor Table hooks removing (unhooking) SYSENTER/Int 2e hooks detection · Detection of hooking sysenter instruction handler and system interrupt (IDT) hook SYSENTER/Int 2e hooks removing (unhooking) · Restoring original instruction (interrupt) handler Hidden processes detection · Detection of processes hidden from Windows API · Most powerful in the world at current time · Detection of processes with full path and name (unique) Hidden processes terminating · Including force-kill powered by PVASE · (c) PVASE Process Virtual Address Space Erasing Hidden processes dumping · With ability to rebuild file for analysis Hidden drivers detection · Detection of drivers hidden from Windows API · combines four different methods of detection and including special five (c) Stealth Walker technology · and six (c) KMSE - Kernel Memory Scanning Engine Hidden drivers dumping · Unique feature that gives you ability to make dump of selected driver IRP hooks detection · Look for "References" column on the Hidden Drivers Detector page Detection of API-based hooks (Code Hooks Detection) · Includes most powerful at this time inline (splicing) hooks detection in drivers and libraries.

Microsoft Process Monitor 1.12 Microsoft Process Monitor 1.12
Microsoft Inc

Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity.

GOCR Windows Frontend 1.0 GOCR Windows Frontend 1.0
About280.com

GOCR is an open source Optical Character Recognition (OCR) program that runs on Windows, Linux and MacOSX.

ProcView32 2.01 ProcView32 2.01
Blumentals Software

ProcView32 is a windows 32-bit process viewer.

Web CD 1.1 Web CD 1.1
Mike Singer

Web CD is a tool that launches your web site from the root of a CD.

Securepoint Intrusion Detection System 1.0 Beta Securepoint Intrusion Detection System 1.0 Beta
Securepoint GmbH

The Securepoint Intrusion Detection System (SIDS) allows to analyse your network for intrusion detections.

SynchronEX Backup & FTP 2.14 SynchronEX Backup & FTP 2.14
Xellsoft

SynchronEX is a versatile tool for synchronization, backup and FTP of files and directories - optimized for one-click automation and supporting shell usage.

Other software in this category




CleanCIH 1.6 CleanCIH 1.6
Proland

Clean your PC from the Win95.

Klez Removal Tool 1.0.11 Klez Removal Tool 1.0.11
Symantec Corporation

W32.

WinImp 1.21 WinImp 1.21
Technelysium

WinImp is a new file archiver which not only recognises common archive formats, but also introduces a new, high performance archive format.

Softpit PC Search Light 1.3 Softpit PC Search Light 1.3
Goldmarc Technology AS

The softpit PC search light is a useful utility for people who need to find critical information fast and precisely on their own computer.