Main > Security & Privacy > AntiSpyware >

Rootkit Revealer 1.71



 

Rootkit Revealer 1.71

Sponsored Links

Rootkit Revealer 1.71 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 225.96 KB
Platform: Windows 2000 / XP / 2003 / Vista / Windows7
License: Freeware
Price:
Downloads: 75
Date added: 2011-11-17

Rootkit Revealer 1.71 description

Rootkit Revealer 1.71 is described as a convenient as well as helpful rootkit detection utility. It runs on Windows XP (32-bit) and Windows Server 2003 (32-bit), and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects many persistent rootkits including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

The reason that there is no longer a command-line version is that malware authors have started targetting RootkitRevealer's scan by using its executable name. They've therefore updated RootkitRevealer to execute its scan from a randomly named copy of itself that runs as a Windows service. This type of execution is not conducive to a command-line interface. Note that you can use command-line options to execute an automatic scan with results logged to a file, which is the equivalent of the command-line version's behavior. 

The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode. 

Persistent Rootkits
  • A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention. 
Memory-Based Rootkits
  • Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.
User-mode Rootkits
  • There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries. 
  • The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.
Kernel-mode Rootkits
  • Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.
Requirements:
  • Windows 2000 / XP / 2003 / Vista / Windows7

Rootkit Revealer 1.71 Screenshot

Rootkit Revealer 1.71 Keywords

Bookmark Rootkit Revealer 1.71

Hyperlink code:
Link for forum:

Rootkit Revealer 1.71 Copyright

WareSeeker.com do not provide cracks, serial numbers etc for Rootkit Revealer 1.71. Any sharing links from rapidshare.com, yousendit.com or megaupload.com are also prohibited.

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
PowerPoint Slide Show Converter turns a presentation created with Microsoft PowerPoint into a self-running slide show application (executable file) that can be run on Windows computers without requiri Free Download
Agent Reader is an Advanced Personal Assistant with keyboard and mouse Macro Recorder, Pop-up Killer, Text-to-Speech and more than 20 additional productivy functions not provided by Windows. Free Download
MakeSurvey is a powerful and interactive survey management system, enabling to organize, run and manage various types of surveys. MakeSurvey can process internet and email surveys. Free Download
This easy to use program that clearly reports where and what the differences are. Features: - Differences in HTML Analysis report and Visualization reports are hyperlinked, - Can be used as part of an Free Download
Advanced Office Repair(AOFR) is a Microsoft Office data recovery suite. It includes recovery tools for corrupt or damaged MS Access databases, MS Excel worksheets, MS Word documents, MS Outlook data f Free Download
ClassRoom GradeBook 8 (Windows 9x/XP and Vista) is a sophisticated freeware grading and record keeping program to help classroom teachers from elementary thru grad school easily keep track of their cl Free Download
Resides in the System Tray for easy access to Spell Checking.You can spell check words, sentences and paragraphs.Easy Spell Checking, Auto Correct, Batch Spell Checking,Custom Dictionaries, System Tra Free Download
WorkManager Pro lets you automate working with multiple tasks on a PC. With this handy tool you can arrange as many tasks (programs, documents, URLs and system commands) as you need into one Work. Thi Free Download