· Регистрация 
софт скрипты драйвера форумы блоги  
Пример: windows
Софт
Новости софта
Обзоры
Статьи
Авторам
Софт
Mac Linux PDA/Mobile
Windows Безопасность Антивирусы

Страница программы RootkitRevealer 1.71

RootkitRevealer is an advanced root kit detection utility


  Описание программы   Комментарии (0)   Скриншоты (0)   Файлы (1)  
АвторSysinternals
СайтПерейти
Обновление11.11.2005, 00:38
НазваниеRootkitRevealer
ВерсияRootkitRevealer 1.71
ЯзыкиАнглийский
ЛицензияFreeware
СтоимостьБесплатно 
СистемыWindows NT/2K/XP
Размер210 Кб
Рейтинг
Голосов: 2

Скачать бесплатно RootkitRevealer
Закачек: 86
найти или купить на Allsoft.ru
софт в Allsoft.ru 




Описание программы RootkitRevealer
RootkitRevealer is an advanced root kit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.
RootkitRevealer can successfully detect all persistent rootkits published at www.rootkit.com, including Vanquish, AFX and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys).
The term rootkit is used to describe the mechanisms and techniques whereby malware, including viruses, spyware, and trojans, attempt to hide their presence from spyware blockers, antivirus, and system management utilities. There are several rootkit classifications depending on whether the malware survives reboot and whether it executes in user mode or kernel mode.
Persistent Rootkits
A persistent rootkit is one associated with malware that activates each time the system boots. Because such malware contain code that must be executed automatically each system start or when a user logs in, they must store code in a persistent store, such as the Registry or file system, and configure a method by which the code executes without user intervention.
Memory-Based Rootkits
Memory-based rootkits are malware that has no persistent code and therefore does not survive a reboot.
User-mode Rootkits
There are many methods by which rootkits attempt to evade detection. For example, a user-mode rootkit might intercept all calls to the Windows FindFirstFile/FindNextFile APIs, which are used by file system exploration utilities, including Explorer and the command prompt to enumerate the contents of file system directories. When an application performs a directory listing that would otherwise return results that contain entries identifying the files associated with the rootkit, the rootkit intercepts and modifies the output to remove the entries.
The Windows native API serves as the interface between user-mode clients and kernel-mode services and more sophisticated user-mode rootkits intercept file system, Registry, and process enumeration functions of the Native API. This prevents their detection by scanners that compare the results of a Windows API enumeration with that returned by a native API enumeration.
Kernel-mode Rootkits
Kernel-mode rootkits can be even more powerful since, not only can they intercept the native API in kernel-mode, but they can also directly manipulate kernel-mode data structures. A common technique for hiding the presence of a malware process is to remove the process from the kernel's list of active processes. Since process management APIs rely on the contents of the list, the malware process will not display in process management tools like Task Manager or Process Explorer.
· Ключевые особенности и характеристики RootkitRevealer 1.71
Не определены
· Ограничения RootkitRevealer 1.71
Ограничения не определены
· Специальные требования RootkitRevealer 1.71
Специальные требования не определены
· История версий и изменений RootkitRevealer
История пуста
· Описание и дополнения от редакторов и пользователей сайта
Пока нет
Связанные статьи, обзоры и новости
Нет относящихся к программе статей и обзоров.


Другие программы от Sysinternals

TCPView 2.40
a detailed listings of all TCP and UDP endpoints
05.09.2006, 16:11 | 85 Кб | Freeware | 308


ASTRA - Advanced Sysinfo Tool 5.33
Программа определения конфигурации и диагностики компьютера.
24.07.2007, 23:23 | 737.23 Кб | Demo | 126


VolumeID 2.01
Set volume ids on FAT and NTFS hard drives and floppy disks using this little utility
27.02.2007, 08:56 | 42 Кб | Freeware | 255


ASTRA32 - Advanced System Information Tool 1.54
Программа определения конфигурации и диагностики компьютера.
25.07.2007, 16:12 | 1.31 Мб | Demo | 86


BGInfo 4.07
BGInfo automatically generates desktop backgrounds that include important information about the system including IP addresses...
17.01.2005, 05:56 | 244 Кб | Freeware | 78

     
Похожие программы

Dr.WEB CureIt! 4.44.5
Бесплатное и средство для лечения компьютеров от вирусов, руткитов, троянских программ, шпионского ПО и разного рода вредоносных объектов
13.09.2008, 10:27 | 10.75 Мб | Freeware | 49


ViGUARD Pro 11.1427
ViGUARD is an IPS solution (Intrusion Protection System) used by government and military institutions
09.06.2007, 07:29 | 9.25 Мб | Demo | 61


ViGUARD 11.1427
ViGUARD is an IPS solution (Intrusion Protection System) used by government and military institutions
09.06.2007, 05:29 | 9.2 Мб | Demo | 3


PCSafer 3.00
This software is an application of Internet safety and it helps scan in real time your machine to protect from parasite
03.06.2007, 08:05 | 4.78 Мб | Shareware | 7


HandyBits VirusScan Integrator 5.5.0.207
VirusScan Integrator allows you to scan the same files with several antiviral programs
30.05.2007, 09:51 | 1.56 Мб | Freeware | 19

Разделы