> traveler scribbled:
>> Max Burke wrote:
> Oh, and by the way, you posted a dead link ^ they must have shut
> it down because of all the complaints that it was a root kit, lol
>> No it hasn't been shut down and it isn't a rootkit.
>> It's here:
>> http://www.sysinternals.com/Utilitie...tRevealer.html
> Thanks for the info, the only thing is that it dosen't look like it
> can remove the actual root kit.
That's why it's called Rootkit *Revealer,* which is understandable given the
damage an 'un-informed' user could do to their OS if they ran it then
deleted everything the scan showed....
Like all software it's not foolproof and is simply a tool to show *possible*
anomolies that might need further investigation.
For example whenever I run it, I get a prefetch entry everytime for cmd.exe
that Rootkit Revealer says is hidden from the Windows API.
It's a false positive for cmd.exe and nothing that I need to be concerned
about.
--
mlvburke@xxxxxxxx.nz
Replace the obvious with paradise.net to email me
Found Images
http://homepages.paradise.net.nz/~mlvburke