<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; icesword</title>
	<atom:link href="http://www.ghacks.net/tag/icesword/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 03:24:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IceSword the better Rootkit Revealer ?</title>
		<link>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/</link>
		<comments>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/#comments</comments>
		<pubDate>Wed, 19 Jul 2006 13:25:44 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[icesword]]></category>
		<category><![CDATA[rootkit-revealer]]></category>
		<category><![CDATA[rootkits]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/</guid>
		<description><![CDATA[IceSword is a new contender for the title of the best rootkit revealing and removing program out there at the moment. It is rather hard to find a working download of IceSword but as always I provide a fast way to download the latest version of Icesword named IceSword1.18.rar. Click the link to download the rootkit scanner from rapidshare. In contrast to other rootkit scanners like Blacklight Icesword can not be run automatically.  Icesword only provides  perhaps the most powerful utilities to scan your system for rootkits and other information.]]></description>
			<content:encoded><![CDATA[<p>IceSword is a new contender for the title of the best rootkit revealing and removing program out there at the moment. It is rather hard to find a working download of IceSword but as always I provide a fast way to download the latest version of Icesword named <a title="IceSword 1.18 English Download" target="_blank" href="http://rapidshare.de/files/26290975/IceSword1.18en.rar.html">IceSword1.18.rar</a>. Click the link to download the rootkit scanner from <a href="http://www.ghacks.net/2008/01/04/5-rapidshare-search-engines/">rapidshare</a>. In contrast to other rootkit scanners like Blacklight Icesword can not be run automatically.  Icesword only provides  perhaps the most powerful utilities to scan your system for rootkits and other information.</p>
<p>There is no way that I have enough time to write about all features of IceSword. I therefor decided to mention the most important ones and leave the rest up to you. The process tab of IceSword is one of the most important ones when it comes to detecting rootkits. Icesword will color most hidden processes red which means it is a good idea to take a look at those first. Some rootkits are not colored however so a second look never hurts. You are able to terminate a process by right clicking and selecting Terminate Process.</p>
<p><span id="more-642"></span>A good idea is to check the compare the findings with other programs. Use a process explorer that shows the amount of processes but is able to view hidden processes. Compare that number with the number in Icesword and you should have the same amount of processes, if not take a closer look and compare the results.The <a target="_blank" href="http://www.mitec.cz/Data/XML/data_downloads.xml">Mitec Process Viewer</a> is a good tool for this for example.</p>
<p>The ports tab lists all open ports and their applications. Compare the applications with the one that you´ve started. If you see for example that iexplorer.exe is currently connected to the internet but you are not using this program, well you know that you should block the connection and check what´s going on. IceSword should show the same connections that the command netstat -an shows. If they differ something is not right.</p>
<p>The Kernel Module tab in Icesword colors hidden drivers red. The BHO tab (Browser Helper Objects) should be empty if you are not using Internet Explorer but Firefox for example. If you see something in there search for it using Google to see if it is spyware or not.</p>
<p>As you can see it is not that easy to use Icesword compared to other rootkit scanners that work by clicking on the scan button. Iceswords biggest advantage is the fact that it offers more information which is good if you know what you are doing or how to search for the information that you need.</p>
<p>Alternatives to Icesword are still the <a target="_blank" href="http://www.sysinternals.com/">sysinternals</a> rootkit revealer and <a target="_blank" href="http://www.f-secure.com/blacklight">blacklight</a> from f-secure.</p>

	Tags: <a href="http://www.ghacks.net/tag/icesword/" title="icesword" rel="tag">icesword</a>, <a href="http://www.ghacks.net/tag/rootkit-revealer/" title="rootkit-revealer" rel="tag">rootkit-revealer</a>, <a href="http://www.ghacks.net/tag/rootkits/" title="rootkits" rel="tag">rootkits</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/05/03/how-to-scan-your-linux-distro-for-root-kits/" title="How to scan your Linux-Distro for Root Kits (May 3, 2006)">How to scan your Linux-Distro for Root Kits</a> (2)</li>
	<li><a href="http://www.ghacks.net/2006/05/12/how-to-check-your-system-for-rootkits/" title="How to check your system for rootkits (May 12, 2006)">How to check your system for rootkits</a> (0)</li>
	<li><a href="http://www.ghacks.net/2006/02/15/dvd-rootkit-on-the-way/" title="Dvd Rootkit on the way (February 15, 2006)">Dvd Rootkit on the way</a> (3)</li>
	<li><a href="http://www.ghacks.net/2007/04/05/avg-anti-rootkit-free/" title="AVG Anti Rootkit free (April 5, 2007)">AVG Anti Rootkit free</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/yahoo-marks-dangerous-search-results/" title="Yahoo marks dangerous search results (May 7, 2008)">Yahoo marks dangerous search results</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
