RootRepeal is a small, portable and freeware application that is designed to uncover rootkits. This tool has been picking up popularity with security groups like Systernals. This is a tool for advanced users only who know what the normal Windows drivers, processes and services are. If you don’t know what you are doing you can easily render a computer unbootable.
RootRepeal has the following features:
Once you have found something malicious, you can right click on the driver/file/service and either copy, wipe or force delete it.
Download from Official Site – 93kb
Session expired
Please log in again. The login page will open in a new tab. After logging in you can close it and return to this page.
Great post Bryce.
Crashed on Win7
Nice tool as always…Thanks
Does not support 64 bit OS’es.
really nice…it cure our pc…thanks bryce..thanks a lot…
If you click on stealth or hidden items tab anything there that is found won’t mess up your OS only rootkits show up there, drivers tab you should never remove anything there.
Thats not entirely true Galdorf, most rootkits I have seen install themselves AS A DRIVER such as “tdss.sys”.
crashes on Vista Home Premium.. no good…
My copy of XP Pro didn’t like it much either.
Great tool – one of my kids downloaded a program called “Microsoft Point Generator” to gain points for their Xbox. Well, it was a rootkit and disabled all antivirus’es and malware scanners. Could not even run in safe mode. Ran RootRepeal and found all the “hidden” garbage – cleaned it up and now back to normal. RootRepeal has been added to my arsenal of tools…(PC was infected with SKYNET*.sys, UAC*.sys, sdra64.exe, etc)