RootkitRevealer: a new way to discover intruders

SysInternals, famous for all its good tools for Windows systems (Process Explorer is one of my favourite) today is out with a new free security tool called RootkitRevealer.

RootkitRevealer is an advanced root kit detection utility that runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit (a "rootkit" is a technique used by malware, including viruses, spyware, and trojans, to hide their presence from spyware blockers, antivirus, and system management utilities).

This tools has a GUI version (really useful) and a command-line version, and you can download it from HERE. Great work SysInternals (as usual)!

Print | posted on Wednesday, February 23, 2005 2:20 PM

Comments on this post

# re: RootkitRevealer: a new way to discover intruders

Requesting Gravatar...
yah ive used this before. Its good but not that good. I can make things not show up here just like a/v doesnt detect it and basically unless it mass distributed you will never know

Left by xer0 on Feb 23, 2005 6:11 PM

Your comment:

 (will show your gravatar)
 
Please add 8 and 2 and type the answer here: