What is RootkitRevealer.exe?

The genuine RootkitRevealer.exe file is a software component of Sysinternals Rootkitrevealer by Microsoft.
RootkitRevealer.exe is an executable file that runs the Sysinternals Rootkitrevealer utility, a tool designed for detecting rootkits (hidden software programs) on computers running Microsoft Windows. This is not a critical Windows component and should be removed if known to cause problems. RootkitRevealer was created for Windows XP and Windows Server 2003. The program looked for discrepancies in the system registry and file system to indicate the presence of a rootkit. This tool is credited with unearthing secretive measures taken by Sony BMG as copy protection which ultimately turned out to be deceptive, illegal, and potentially harmful, causing a major scandal. Sysinternals is a website launched in 1996 by Mark Russinovich and Bryce Cogswell to host their free yet advanced system utilities designed to administer and monitor computers running Microsoft Windows. In 2006, Microsoft acquired Sysinternals, as well as Winternals Software LP, the company that operated the Sysinternals website. Windows Sysinternals is currently part of the Microsoft TechNet website. Microsoft was founded in 1975 by Bill Gates and Paul Allen and quickly rose to prominence following the launch of their popular operating system, MS-DOS for early personal computers. After the company went public in 1986, its rising share prices created three billionaires and roughly 12,000 millionaires from Microsoft employees. Microsoft began developing graphical user interfaces and the distinguishable Start-button after the introduction of Windows 95. Further additions like networking and security soon followed. Microsoft is currently headquartered in Redmond, Washington, USA.

RootkitRevealer stands for RootkitRevealer: Rootkit detection utility

The .exe extension on a filename indicates an executable file. Executable files may, in some cases, harm your computer. Therefore, please read below to decide for yourself whether the RootkitRevealer.exe on your computer is a Trojan that you should remove, or whether it is a file belonging to the Windows operating system or to a trusted application.

Click to Run a Free Scan for RootkitRevealer.exe related errors

RootkitRevealer.exe file information

The process known as Rootkit detection utility belongs to software Sysinternals Rootkitrevealer by Sysinternals - ( or Microsoft (

Description: RootkitRevealer.exe is not essential for the Windows OS and causes relatively few problems. RootkitRevealer.exe is located in a subfolder of the user's profile folder or sometimes in a subfolder of the user's "Documents" folder or in a subfolder of Windows folder for temporary files. The file size on Windows 10/8/7/XP is 334,720 bytes. 
The program is not visible. RootkitRevealer.exe is not a Windows system file. It is digitally signed. Therefore the technical security rating is 36% dangerous; however you should also read the user reviews.

Recommended: Identify RootkitRevealer.exe related errors

Important: Some malware camouflages itself as RootkitRevealer.exe, particularly when located in the C:\Windows or C:\Windows\System32 folder. Therefore, you should check the RootkitRevealer.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.


User Comments

Sysinternals Rootkitrevealer. Scan the system for Rootkits
  Alex   (further information)
it is a trojan and keyboard monitor, it seems to work well.
  Patrick M Murphy   (further information)
Rootkit scanner - SysInternals - By Bryce Cogswell and Mark Russinovich
  MJ   (further information)

Summary: Average user rating of RootkitRevealer.exe: based on 2 votes with 3 user comments. One user thinks RootkitRevealer.exe is essential for Windows or an installed application. One user thinks it's neither essential nor dangerous. One user is not sure about it.

Do you have additional information? Help other users!
What do you know about RootkitRevealer.exe:
How would you rate it:
Link for more info:
Your Name:

Best practices for resolving RootkitRevealer issues

A clean and tidy computer is the key requirement for avoiding problems with RootkitRevealer. This means running a scan for malware, cleaning your hard drive using cleanmgr and sfc /scannow, uninstalling programs that you no longer need, checking for Autostart programs (using msconfig) and enabling Windows' Automatic Update. Always remember to perform periodic backups, or at least to set restore points.

Should you experience an actual problem, try to recall the last thing you did, or the last thing you installed before the problem appeared for the first time. Use the resmon command to identify the processes that are causing your problem. Even for serious problems, rather than reinstalling Windows, you are better off repairing of your installation or, for Windows 8 and later versions, executing the DISM.exe /Online /Cleanup-image /Restorehealth command. This allows you to repair the operating system without losing data.

To help you analyze the RootkitRevealer.exe process on your computer, the following programs have proven to be helpful: Security Task Manager displays all running Windows tasks, including embedded hidden processes, such as keyboard and browser monitoring or Autostart entries. A unique security risk rating indicates the likelihood of the process being potential spyware, malware or a Trojan. Malwarebytes Anti-Malware detects and removes sleeping spyware, adware, Trojans, keyloggers, malware and trackers from your hard drive.

Other processes

RootkitRevealer.exe [all]