WINDOWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>

WEEKLY HIGHLIGHTS

DVD Cloner45
Spyware Doctor40
1Click DVD Copy40
Apollo DVD Copy40
ABC Amber BlackBer...45
Protected Music Co...40

7-DAY TOP DOWNLOAD

#
Program
Avira AntiVir
Personal - Free
Antivirus 9.0.0.407

197,527
Windows Live
Messenger 2009
14.0.8089.726

191,571
Avira Antivir Virus
Definition File
Update November 6,
2009

183,902
Nexus Radio 4.1.1
132,855
Windows Live
Messenger
8.5.1302.1018

114,274
FreeZ Online TV 1.30
94,065
Microsoft Office
2007

83,055
Y! Multi Messenger
8.x and 9.x

80,995
DVD Shrink 3.2.0.15
60,078
AVG Free Edition 9.0
Build 698a1730

56,394

WEEK'S BEST

  • Internet Explorer ...
  • Online Armor ++ 4....
  • cFosSpeed 5.01 Bui...
  • SONY Vegas Pro 9.0...
  • Firefox 3.6 Beta 1...
  • Nokia Photos 1.6.434
  • Windows Server 200...
  • Skype Portable 4.1...
  • Google Chrome Port...
  • PCMark Vantage Bas...
  • Kaspersky Anti-Vir...
  • Microsoft Virtual ...
  • Messenger Plus! Li...
  • WinX DVD Author [F...
  • SoftPerfect Networ...
  • System Mechanic Pr...
  • Ad Muncher 4.8 Bui...
  • Windows 7 Upgrade ...
  • Pidgin 2.6.3
  • OpenOffice.org 3.2...
  • VirtualDub 1.9.7 B...
  • Maxthon [Softpedia...
  • Spyware Doctor 7.0...
  • SUPERAntiSpyware 4...
  • Adobe Acrobat Prof...
  • Camfrog Video Chat...
  • Adobe Reader 9.2.0...
  • Foxit PDF Reader 3...
  • Microsoft Maliciou...
  • AVG Identity Prote...
  • Home / Windows / Antivirus
     Report spyware

    RootkitRevealer 1.71

    Softpedia Pick Award
    Download button

    Downloads: 43,854  Add to download basket  Tell us about an update
    User Rating:
    Rated by:
    Good (3.6/5)
    62 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:
    Sysinternals | More programs
    Freeware / FREE
    225 KB / Windows NT / 2K / XP
    November 11th, 2006, 08:19 GMT
    C: \ Antivirus

     Read user reviews (2)  Add a review  Refer to a friend  Subscribe

     

    RootkitRevealer description

     

    An advanced root kit detection utility

    RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

    RootkitRevealer can successfully detect all persistent rootkits published at www.rootkit.com, including Vanquish, AFX and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

    The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.

    Persistent Rootkits
    A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.

    Memory-Based Rootkits
    Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.

    User-mode Rootkits
    There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.

    The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.

    Kernel-mode Rootkits
    Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.

     Softpedia guarantees that RootkitRevealer 1.71 is 100% FREE, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    rootkit cleaner | rootkit detector | rootkit scanner | rootkit | cleaner | scanner



    HTML code for linking to this page:


    Go to top

    Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM