Home | Advertise | Submit | Press | Top | Contact | Help | Bookmark
Search downloads:
Home Antivirus & Spyware Cleaners Antivirus RootkitRevealer 1.71

RootkitRevealer 1.71

Details
View: screenshot
Size: 210.00 KB
License: Freeware
OS: Windows NT/2K/XP
Publisher: Sysinternals
Date added: 1/12/2007
Date updated: 1/12/2007
Total Downloads: 344
Downloads - Last Week: 32

Rating: (2 votes)
RootkitRevealer 1.71 Publisher's description

RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

RootkitRevealer can successfully detect all persistent rootkits published at www.rootkit.com, including Vanquish, AFX and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.

Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.

- Download RootkitRevealer 1.71
Antivirus information
Download3K did not scan RootkitRevealer for viruses, adware, spyware or other badware. For your own safety, we recommend that you always have an antivirus, with virus definitions up to date, installed on your computer when downloading and installing programs from the web.

Your email:
Friend email:
Related downloads
 32x32 pixels icon RootkitRevealer 1.71
An advanced root kit detection utility.
344
 32x32 pixels icon Advanced Clipboard Utility (ACU) 1.3.2
Save your time with ACU
273
 32x32 pixels icon Root Cause Analysis Software 1.0
Root Cause Analysis Software (Strategic Analy
75
 32x32 pixels icon Root Cause Analysis Software 1.0
Root Cause Analysis Software (Strategic Analy
192
 32x32 pixels icon Wave Ball Root Revision 1.0
Arkanoid clone of its new 3D series.
156
 32x32 pixels icon Motion Detection 1.04
Creates a movie from anything in motion
403
 32x32 pixels icon WhoCalls Caller ID detection 2.0.5
CallerID detection and display
241
 32x32 pixels icon Motion detection camera 2.6
Easy to use motion detection alarm.
52
 32x32 pixels icon 3 Charts - Drug Detection Periods 1.0
Drug detection time screensaver.
59
 32x32 pixels icon SpyNoMore Anti-Spyware Detection, Remove 2.12
SpyNoMore Anti-Spyware Home Edition: Spyware.
34

Related press releases

Spyware Terminator
Spyware Terminator 32x32 pixels iconFree Spyware Terminator provides effective real-time detection and removal of spyware and incoming threats on your computer. Reliable and user friendly, it's for personal and commercial use. Uses minimal PC resources and performs ultra fast scans.

Spamcontainer
Spamcontainer 32x32 pixels iconSpam Container takes an entirely different approach to spam, allowing you to see only the email you have allowed, banning known bad senders so they are never allowed through and putting all unknown senders into a holding area


Archive: All downloads - Links - Links2

Copyright (c)2005-2008 Download3K.com - All rights reserved - Terms of use - Privacy Policy