Advertisement

RootkitRevealer

RootkitRevealer is an advanced root kit detection utility
Download.hr
5
Users
5.0
1 votes
Your vote
  • Currently 5.00/5
Listed version:
1.71
License:
Freeware
/ Free / Free download
Price:
Free
Operating system:
Windows NT/2K/XP
File size:
229.53 kB
Downloads:
3,402
Last updated:
17.10.2007 | Updated
Publisher:
Category:
Security / Anti-Virus
trusted
DOWNLOAD


RootkitRevealer is listed in Anti-Virus category and made available by Sysinternals for Windows NT/2K/XP. Unfortunately, we have not yet reviewed RootkitRevealer. If you would like to submit a review of this software, we encourage you to submit us something!
RootkitRevealer review by publisher Sysinternals:

What is RootkitRevealer software from Sysinternals, what is it used for and how to use it?

RootkitRevealer is an advanced root kit detection utility

Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.

Download and install RootkitRevealer safely and without concerns.

RootkitRevealer is a software product developed by Sysinternals and it is listed in Security category under Anti-Virus. RootkitRevealer is a free software product and it is fully functional for an unlimited time although there may be other versions of this software product. You can run RootkitRevealer on Windows NT/2K/XP operating systems. RootkitRevealer was last time updated on 17.10.2007 and it has 3,402 downloads on Download.hr portal. Download and install RootkitRevealer safely and without concerns.
RootkitRevealer awards
RootkitRevealer awards
RootkitRevealer awards
Focusky 3-months Pro Plan
Time limited giveaway
$24.75  FREE

in Windows giveaways Expires on March 30, 2017

Focusky 3-months Pro Plan
FREE: Nuclear Dawn
Lantern good software buddy
Dr.Web CureIt! super
Windows Credentials Viewer Simplicity rules!
What is your favorite system...
Do you use a 32-bit OS or 64-bit...
What is your favorite video player?
What is your favorite graphics...
What Was The Last Movie You Saw?
Some Tips On Intelligent...
WinX MediaTrans Giveaway Version
Focusky 3-months Pro Plan giveaway
DVDFab Passkey 9.1.1.3 Updated!
Aiseesoft FoneCopy 1.2.28