Rootkit Revealer
for Windows

RootkitRevealer is an advanced rootkit detection utility.

  • Total Downloads
    18
  • Downloads Last Week
    0
  • User Rating
    0
  • My Rating

Rootkit Revealer Description

RootkitRevealer is an advanced rootkit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

RootkitRevealer successfully detects many persistent rootkits including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).

Since persistent rootkits work by changing API results so that a system view using APIs differs from the actual view in storage, RootkitRevealer compares the results of a system scan at the highest level with that at the lowest level. The highest level is the Windows API and the lowest level is the raw contents of a file system volume or Registry hive (a hive file is the Registry's on-disk storage format).

Thus, rootkits, whether user mode or kernel mode, that manipulate the Windows API or native API to remove their presence from a directory listing, for example, will be seen by RootkitRevealer as a discrepancy between the information returned by the Windows API and that seen in the raw scan of a FAT or NTFS volume's file system structures.

Rootkit Revealer Screenshots

Screenshots are not available currently.

What's New in Rootkit Revealer 1.71

Release notes are not available currently.

Rootkit Revealer Requirements

Operating Systems:

Windows 2000 / XP / 2003 / Vista / Windows7

System Requirements:

No additional system requirements.

Quick Specifications

See Full Specifications

More From Microsoft SysInternals

  • Process Explorer
    Process Explorer shows you handles and DLLs processes have opened or loaded.
See More

Essential Downloads in Anti Spyware

  • Rootkit Revealer
    RootkitRevealer is an advanced rootkit detection utility.
  • Spyware Terminator
    Free real-time protection against spyware and adware.
  • Windows Defender
    Windows Defender protect your files and personal settings, and protect password.
  • SuperAntiSpyware Free Edition
    Detect and remove spyware, malware, rootkits, trojans, hijackers, and other malicious threats.
  • Scan Spyware
    ScanSpyware removes spyware, adware and other malicious programs safely.
  • HijackThis
    Scan your computer to find Spywares or malwares or other unwanted programs.
See More