Jump to content

RootkitRevealer

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by FleetCommand (talk | contribs) at 07:53, 1 November 2009 (Minor improvements). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Sysinternals RootkitRevealer
Developer(s)Bryce Cogswell and Mark Russinovich
Stable release
1.7 / 1 November 2006
Written inMicrosoft C++
Operating systemMicrosoft Windows XP and Server 2003
PlatformMicrosoft Windows
Size0.231
Available inEnglish
TypeComputer security software
LicenseSysinternals EULA (Closed-source freeware)
Website[1]

RootkitRevealer is a proprietary tool for rootkit detection on Microsoft Windows by Mark Russinovich at Sysinternals. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. It does not support 64-bit Windows systems. It was the tool that first detected Sony's XCP rootkit.