The current version is: Version 1.2.3
Download: RootRepeal.rar
MD5 (of the EXE): 8F32CC6C8C8648B7AA227F256C4B6252
SHA-1 (of the EXE): 31295B109307B82FD756B375F01E52E9591A7BB5
RootRepeal is a new rootkit detector currently in public beta. It is designed with the following goals in mind:
- Easy to use - a user with little to no computer experience should be able to use it.
- Powerful - it should be able to detect all publicly available rootkits.
- Stable - it should work on as many different system configurations as possible, and, in the event of an incompatibility, not crash the host computer.
- Safe - it will not use any rootkit-like techniques (hooking, etc.) to protect itself.
Currently, RootRepeal includes the following features:
- Driver Scan - scans the system for kernel-mode drivers. Displays all drivers currently loaded, and shows if a driver has been hidden, and whether the driver's file is visible on-disk.
- Files Scan - scans any fixed drive on the system for hidden, locked or falsified* files.
- Processes Scan - scans the system for processes. Displays all processes currently running, and shows if a processes is hidden or locked.
- SSDT Scan - shows whether any of the functions in the System Service Descriptor Table (SSDT) are hooked.
- Stealth Objects Scan - attempts to determine if any rootkits are active by looking for typical symptoms.
- Hidden Services Scan - scans for hidden system services.
* - falsified files are files which have their size mis-reported to the Windows API. Some rootkits use this to hide data.
RootRepeal is currently in public beta. Whereas every effort has been made to ensure compatibility with every system configuration on Windows 2000, XP, 2003 and Vista, it cannot be guaranteed. There is always some risk when scanning for rootkits. Before running RootRepeal, please make sure you have backups of all important data and have saved all open documents.
强大的-它应能侦测到所有公开的rootkit 。
安全-这将不使用任何的rootkit样技术(连接等) ,以保护自己。
目前, RootRepeal包括以下功能:
SSDT扫描-表明是否有任何方面的职能系统服务描述表( SSDT )的连接。
* -伪造档案文件,其大小有错误报告的Windows API 。有些rootkits利用这一隐藏的数据。
[ 本帖最后由 jeccci5 于 2008-12-31 20:54 编辑 ] |