
RootkitRevealer:可以檢測註冊表和檔系統的API變化情況,這些變化指明了某個用戶模式或內核模式rootkit的存在。
RootkitRevealer is an advanced rootkit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects many ...