RootkitRevealer
Appearance
Developer(s) | Bryce Cogswell and Mark Russinovich |
---|---|
Stable release | 1.7
/ 1 November 2006 |
Written in | Microsoft C++ |
Operating system | Microsoft Windows XP and Server 2003 |
Platform | Microsoft Windows |
Size | 0.231 |
Available in | English |
Type | Computer security software |
License | Sysinternals EULA (Closed-source freeware) |
Website | [1] |
RootkitRevealer is a proprietary tool for rootkit detection on Microsoft Windows by Mark Russinovich at Sysinternals. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. It does not support 64-bit Windows systems. It was the tool that first detected Sony's XCP rootkit.