<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; rootkit-revealer</title>
	<atom:link href="http://www.ghacks.net/tag/rootkit-revealer/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 23 Nov 2009 22:22:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sysinternals Suite</title>
		<link>http://www.ghacks.net/2007/01/30/sysinternals-suite/</link>
		<comments>http://www.ghacks.net/2007/01/30/sysinternals-suite/#comments</comments>
		<pubDate>Tue, 30 Jan 2007 10:25:10 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[autoruns]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[process-monitor]]></category>
		<category><![CDATA[regmon]]></category>
		<category><![CDATA[rootkit-revealer]]></category>
		<category><![CDATA[sysinternals]]></category>
		<category><![CDATA[sysinternals-suite]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/01/30/sysinternals-suite/</guid>
		<description><![CDATA[If you ever wanted to download all the troubleshooting applications from sysinternals at once you can do so by downloading the Sysinternals suite right from Microsoft. The suite contains all troubleshooting applications that made sysinternal famous, 67 utilities in total which make it easy to troubleshoot Windows problems. This suite is not for you if you already have most of the utilities installed.]]></description>
			<content:encoded><![CDATA[<p>If you ever wanted to download all the troubleshooting applications from sysinternals at once you can do so by downloading the <a href="http://www.microsoft.com/technet/sysinternals/utilities/sysinternalssuite.mspx" title="sysinternal suite" target="_blank">Sysinternals suite</a> right from Microsoft. The suite contains all troubleshooting applications that made sysinternal famous, 67 utilities in total which make it easy to troubleshoot Windows problems. This suite is not for you if you already have most of the utilities installed.</p>
<p>Some of the applications that are included in the Sysinternals suite should be installed on every computer such as Rootkit Revealer, Autoruns, Process Explorer and Regmon. This collection might confuse inexperienced users due to the sheer amount of exectuables that are listed in the main directory. It is difficulty to find out what some of the executables are doing, do you know for instance what psfile.exe will do ?</p>
<p><span id="more-1153"></span> It would have been nice if at least a readme file would have been included to make it easier to understand the executables. A gui would have been even better. I would advise everyone to visit the <a href="http://www.microsoft.com/technet/sysinternals/default.mspx" title="sysinternals" target="_blank">Sysinternals website</a> to lookup the programs before you execute them.</p>

	Tags: <a href="http://www.ghacks.net/tag/autoruns/" title="autoruns" rel="tag">autoruns</a>, <a href="http://www.ghacks.net/tag/freeware/" title="freeware" rel="tag">freeware</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/process-monitor/" title="process-monitor" rel="tag">process-monitor</a>, <a href="http://www.ghacks.net/tag/regmon/" title="regmon" rel="tag">regmon</a>, <a href="http://www.ghacks.net/tag/rootkit-revealer/" title="rootkit-revealer" rel="tag">rootkit-revealer</a>, <a href="http://www.ghacks.net/tag/sysinternals/" title="sysinternals" rel="tag">sysinternals</a>, <a href="http://www.ghacks.net/tag/sysinternals-suite/" title="sysinternals-suite" rel="tag">sysinternals-suite</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/10/21/zoom-it/" title="Zoom It (October 21, 2006)">Zoom It</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/12/29/tweak-vista-freeware/" title="Tweak Vista Freeware (December 29, 2006)">Tweak Vista Freeware</a> (3)</li>
	<li><a href="http://www.ghacks.net/2006/11/18/top-xp-freeware-that-every-user-needs-part-3/" title="Top Xp Freeware that every user needs part 3 (November 18, 2006)">Top Xp Freeware that every user needs part 3</a> (5)</li>
	<li><a href="http://www.ghacks.net/2006/12/07/security-and-privacy-complete/" title="Security and Privacy Complete (December 7, 2006)">Security and Privacy Complete</a> (0)</li>
	<li><a href="http://www.ghacks.net/2007/09/19/page-defrag/" title="Page Defrag (September 19, 2007)">Page Defrag</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/01/30/sysinternals-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IceSword the better Rootkit Revealer ?</title>
		<link>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/</link>
		<comments>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/#comments</comments>
		<pubDate>Wed, 19 Jul 2006 13:25:44 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[icesword]]></category>
		<category><![CDATA[rootkit-revealer]]></category>
		<category><![CDATA[rootkits]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/</guid>
		<description><![CDATA[IceSword is a new contender for the title of the best rootkit revealing and removing program out there at the moment. It is rather hard to find a working download of IceSword but as always I provide a fast way to download the latest version of Icesword named IceSword1.18.rar. Click the link to download the rootkit scanner from rapidshare. In contrast to other rootkit scanners like Blacklight Icesword can not be run automatically.  Icesword only provides  perhaps the most powerful utilities to scan your system for rootkits and other information.]]></description>
			<content:encoded><![CDATA[<p>IceSword is a new contender for the title of the best rootkit revealing and removing program out there at the moment. It is rather hard to find a working download of IceSword but as always I provide a fast way to download the latest version of Icesword named <a title="IceSword 1.18 English Download" target="_blank" href="http://rapidshare.de/files/26290975/IceSword1.18en.rar.html">IceSword1.18.rar</a>. Click the link to download the rootkit scanner from <a href="http://www.ghacks.net/2008/01/04/5-rapidshare-search-engines/">rapidshare</a>. In contrast to other rootkit scanners like Blacklight Icesword can not be run automatically.  Icesword only provides  perhaps the most powerful utilities to scan your system for rootkits and other information.</p>
<p>There is no way that I have enough time to write about all features of IceSword. I therefor decided to mention the most important ones and leave the rest up to you. The process tab of IceSword is one of the most important ones when it comes to detecting rootkits. Icesword will color most hidden processes red which means it is a good idea to take a look at those first. Some rootkits are not colored however so a second look never hurts. You are able to terminate a process by right clicking and selecting Terminate Process.</p>
<p><span id="more-642"></span>A good idea is to check the compare the findings with other programs. Use a process explorer that shows the amount of processes but is able to view hidden processes. Compare that number with the number in Icesword and you should have the same amount of processes, if not take a closer look and compare the results.The <a target="_blank" href="http://www.mitec.cz/Data/XML/data_downloads.xml">Mitec Process Viewer</a> is a good tool for this for example.</p>
<p>The ports tab lists all open ports and their applications. Compare the applications with the one that you´ve started. If you see for example that iexplorer.exe is currently connected to the internet but you are not using this program, well you know that you should block the connection and check what´s going on. IceSword should show the same connections that the command netstat -an shows. If they differ something is not right.</p>
<p>The Kernel Module tab in Icesword colors hidden drivers red. The BHO tab (Browser Helper Objects) should be empty if you are not using Internet Explorer but Firefox for example. If you see something in there search for it using Google to see if it is spyware or not.</p>
<p>As you can see it is not that easy to use Icesword compared to other rootkit scanners that work by clicking on the scan button. Iceswords biggest advantage is the fact that it offers more information which is good if you know what you are doing or how to search for the information that you need.</p>
<p>Alternatives to Icesword are still the <a target="_blank" href="http://www.sysinternals.com/">sysinternals</a> rootkit revealer and <a target="_blank" href="http://www.f-secure.com/blacklight">blacklight</a> from f-secure.</p>

	Tags: <a href="http://www.ghacks.net/tag/icesword/" title="icesword" rel="tag">icesword</a>, <a href="http://www.ghacks.net/tag/rootkit-revealer/" title="rootkit-revealer" rel="tag">rootkit-revealer</a>, <a href="http://www.ghacks.net/tag/rootkits/" title="rootkits" rel="tag">rootkits</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/05/03/how-to-scan-your-linux-distro-for-root-kits/" title="How to scan your Linux-Distro for Root Kits (May 3, 2006)">How to scan your Linux-Distro for Root Kits</a> (2)</li>
	<li><a href="http://www.ghacks.net/2006/05/12/how-to-check-your-system-for-rootkits/" title="How to check your system for rootkits (May 12, 2006)">How to check your system for rootkits</a> (0)</li>
	<li><a href="http://www.ghacks.net/2006/02/15/dvd-rootkit-on-the-way/" title="Dvd Rootkit on the way (February 15, 2006)">Dvd Rootkit on the way</a> (3)</li>
	<li><a href="http://www.ghacks.net/2007/04/05/avg-anti-rootkit-free/" title="AVG Anti Rootkit free (April 5, 2007)">AVG Anti Rootkit free</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/yahoo-marks-dangerous-search-results/" title="Yahoo marks dangerous search results (May 7, 2008)">Yahoo marks dangerous search results</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2006/07/19/icesword-the-better-rootkit-revealer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
