Wednesday, October 18, 2006

Anti-Rootkit Tools

There are two free tools that can help with detecting rootkits: Sophos Anti-Rootkit (www.sophos.com/products/free-tools/sophos-anti-rootkit.html) and Rootkit Revealer (www.sysinternals.com/Utilities/RootkitRevealer.html). While both are useful tools, Rootkit Revealer digs deeper and returns more information than the Sophos tool. Some rootkits may prevent Rootkit Revealer from running properly, and you will receive an error message. This is a good sign that there is a rootkit on the machine. Some rootkits that I detected with Rootkit Revealer, were not detected by Sophos Anti-Rootkit, therefore I would recommend running both if you suspect a rootkit on your system.