Quad Master
RootKit Revealer
Hi Guys
Read about this software in Tracer's Post , felt that looks like an intresting
software so did a bit of googling and posting info here.
RootkitRevealer is an advanced patent-pending root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys). If you use it to identify the presence of a rootkit please let us know!
The reason that there is no longer a command-line version is that malware authors have started targetting RootkitRevealer's scan by using its executable name. We've therefore updated RootkitRevealer to execute its scan from a randomly named copy of itself that runs as a Windows service. This type of execution is not conducive to a command-line interface. Note that you can use command-line options to execute an automatic scan with results logged to a file, which is the equivalent of the command-line version's behavior.
Some more of ur questions will be answered here
Main Link:- http://www.sysinternals.com/Utilities/RootkitRevealer.html
1.> What is a Rootkit?
2.> Types of Rootkit
Persistent Rootkits , Memory-Based Rootkits , User-mode Rootkits , Kernel-mode Rootkits
3.> How RootkitRevealer Works
4.> Can a Rootkit hide from RootkitRevealer?
5.> Is there a sure-fire way to know of a rootkit's presence?
And more.......
Some More Intresting Articles
1.> Rootkit battle: Rootkit Revealer vs. Hacker Defender
2.> How Not 2 Run Rootkit Revealer - Forum Discussion
3.> Sony, Rootkits and Digital Rights Management Gone Too Far
Link:- http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html
4.> Unearthing Rootkits
Link:- http://www.windowsitpro.com/Windows/Article/ArticleID/46266/46266.html
5.> This site contains sample code for a number of user-mode and kernel-mode rootkits as well as ongoing discussions on how to develop rootkits.
Link:- http://www.rootkit.com/
6.> Microsoft Research rootkit home page where Microsoft publishes papers and information on its efforts to combat rootkits.
Link:- http://research.microsoft.com/rootkit/