timepiece
October 14th, 2005, 05:38 PM
Can someone explain to me how i can use IceSword (English version) to detect rootkits? Where do I start? This program doesn't seem as straight foward as something like Unhackme, which will tell you right away if you have a rootkit.
It seem like with IceSword you really have to know what your doing to find a rootkit. Can anyone help me to understand how to use IceSword to find out if I have a rootkit or not?
For example should I look under KernelModule, SPI, Win32 Services, Message Hooks, or something else to see if I have a rootkit? How do I know if IceSword has actually found a rootkit or not?
Thanks very much if anyone can help.
It seem like with IceSword you really have to know what your doing to find a rootkit. Can anyone help me to understand how to use IceSword to find out if I have a rootkit or not?
For example should I look under KernelModule, SPI, Win32 Services, Message Hooks, or something else to see if I have a rootkit? How do I know if IceSword has actually found a rootkit or not?
Thanks very much if anyone can help.