| Tizer™ Rootkit Razor offers many options to allow you to quickly scan your system. Below is a detailed description of all the scans that are available to you for free using Rootkit Razor. |
| 1. |
Main Screen: This page displays information related to your operating system and memory usage. |
| |
a.) Smart Scan: This feature automatically scans all the critical areas in the system and displays hidden objects, hence making things easier for the user. |
| |
NOTE: User is provided with a feature to fix the hidden object (if any). |
| 2. |
Process Scan: This module scans processes currently running on the machine. A process entry will be highlighted in red if it is a hidden rootkit. The user can click on an individual process to display any hidden modules loaded by the process. |
| |
NOTE: The user is provided with the option to terminate processes and delete modules. |
| 3. |
Registry Scan: This module scan is for hidden registry objects. |
| |
a.) Smart Scan: A smart scan will scan the critical areas of the registry. |
| |
b.) Custom View: This module provides a virtual registry editor view, hence enables the user to navigate through the registry and check for hidden keys or values. (Hidden keys/values will be highlighted) |
| 4. |
Kernel Module Scan: This module scans for loaded drivers in the memory. A module entry will be highlighted in red if it is hidden. |
| |
NOTE: The user is provided with a feature to unload and delete a driver module from memory. |
| 5. |
Services Scan: This module scans all installed services on the local machine. A particular service entry will be highlighted if it is hidden. |
| |
NOTE: The user is provided with start, stop, pause, and resume features. They may also change the startup type of service. |
| 6. |
SPI Scan: This module lists all the LSPs installed in the system. This is read only information. |
| |
NOTE: The user can check for any unauthorized LSP installed. |
| 7. |
SSDT Scan: This module scans for any altered value in the System Service Descriptor Table (SSDT). The process of alteration is termed as "Hooking." |
| |
NOTE: The user can restore the altered value to its original value. |
| 8. |
Ports Scan: This module will scan all open TCP and UDP ports. A particular port entry will be highlighted if it is hidden. |
| |
NOTE: The user is provided with the option to terminate the connection. |
| 9. |
Thread Scan: This module will enumerate all running processes. The user can click on a particular process to view and scan all threads running in context of that process. Any hidden threads will be highlighted in red. |
| |
NOTE: The user is provided with the option to terminate a thread. |
| 10. |
File/Object Scan: This module will scan for any hidden files in the system. The user selects a location on the computer to scan. |
| |
NOTE: The user is provided with a feature to delete the file. |