Jump to content

RootkitRevealer

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 220.244.170.133 (talk) at 07:32, 31 December 2008. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

RootkitRevealer is a proprietary tool for rootkit detection on Microsoft Windows by Mark Russinovich at Sysinternals. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. It was the tool that first detected Sony's XCP rootkit.