An complex rootkit recognition tool is called Rootkitrevealer. It runs on Windows Nt 4 and higher, and its performance lists anomalies between the registry and submit system Apis that could be caused by a user-mode or rootkit in the seed way.
Most lasting rootkits, such as Afx, Vanquish, and Hackerdefender, are successfully detected by Rootkitrevealer. However, it is not intended to identify file – or registry-key-protected roots like Fu.
Rootkitrevealer compares the outcomes of a system test at the highest and lowest levels because lasting rootkits operate by altering Api gains, causing system views using Apis to differ from actual safe-keeping views. The basic material of a file system quantity, or Registry colony file( the Registry’s’s on-disk storage format ), are at the highest level and lowest level, respectively.
Advertisement
Therefore, Rootkitrevealer will notice a discrepancy between the information returned by the Windows Api and that seen in the raw test of an Fat or Ntfs volume’s’s file system structures when using rootkits, whether in users way or essence setting, to eliminate their presence from directory listings.
Advertisement
Technical
- Title:
- Windows version of Rootkitrevealer 1.71
- Requirements:
- Nt Windows,
- Windows of Windows,
- Windows 2000.
- Language:
- English
- License:
- Free
- most recent change:
- 30th July 2023, a Friday
- Author:
- Microsoft Internals