E-Mail:

Sysinternals’ RootkitRevealer 1.4

In my February 21, 2005 article “Kernel Rootkits - next bad thing?“, I reported that undetectable rootkits may be the next spyware/malware paradigm and that Microsoft researchers had developed a tool, named “Strider Ghostbuster” that can detect them.

A day later the good folks at Sysinternals released RootkitRevealer 1.4, which I now consider a vital weapon in my security arsenal:

RootkitRevealer is an advanced patent-pending root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects all persistent rootkits published at www.rootkit.com….

To my knowledge, Strider Ghostbuster hasn’t been released yet, but Microsoft mentions using RootkitRevealer on their rootkit research site. That site has some excellent references and tips on dealing with ghostware.

What Do You Think?

 

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense your hard-earned information back to the community, get involved in our community site today! You can write about anything - no matter the topic. Exceptional candidates will be offered the chance to contribute to (and generate revenue from) the main Lockergnome site. Join us today!

63 queries / 0.262 seconds.