RootkitRevealer is an advanced patent-pending root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.
The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.
Since persistent rootkits work by changing API results so that a system view using APIs differs from the actual view in storage, RootkitRevealer compares the results of a system scan at the highest level with that at the lowest level. The highest level is the Windows API and the lowest level is the raw contents of a file system volume or Registry hive (a hive file is the Registry's on-disk storage format).
Thus, rootkits, whether user mode or kernel mode, that manipulate the Windows API or native API to remove their presence from a directory listing, for example, will be seen by RootkitRevealer as a discrepancy between the information returned by the Windows API and that seen in the raw scan of a FAT or NTFS volume's file system structures.
Related downloads:
· GMER: is an application that detects and removes rootkits.
Rating: None (0 votes) Comments:
write comment all comments
Virus Definitions
- Kaspersky Update
- Norton Definitions
- Trend Micro Pattern File
- AVG Anti-Virus Updates
- McAfee SuperDAT
- Ad-aware Reference File
- F-Secure Definitions
- Trojan Remover Update
Top Downloads
- McAfee SuperDAT
- NOD32 3.0
- Kaspersky Anti-Virus
- Kaspersky Update
- Norton AntiVirus 2008
- Norton Definitions
- AVG Free Ed. 8.0
- Trojan Remover 6.7.0
- McAfee AVERT Stinger
- Buddy Spy 2.2.18
Hot Free Stuff
- Pocket KillBox
- xp-AntiSpy
- AntiVir Personal Edition
- SpywareBlaster
- FreeUndelete
- Windows Defender
- CCleaner
- SPAMfighter
- Unlocker
- Spybot-S&D
- Buddy Spy
- ZoneAlarm Free
- nCleaner
- CWShredder
- McAfee Avert Stinger
Friends
Copyright © 2008 ScanWith.com
Categories