PDA

View Full Version : Icesword


bamaman66
August 11th, 2006, 04:05 PM
I have run Icesword and I have gotten quite a few red entries under SSDT. They are SystemRoot\System32\vsdatant.sys. Are these entries problem areas? If so, how do I get rid of them? Where can I find some instructions on how to interpret the results I get from running Icesword?

Meriadoc
August 11th, 2006, 04:24 PM
-{ Quote: "Icesword " }-
tutorial
http://www.castlecops.com/t161249-Rootkit_removal_tools.html

vsdatant.sys, do you have zonealarm

Stem
August 11th, 2006, 04:30 PM
"vsdatant.sys", this I believe is part of Zonealarm, which will be hooking into the system. Not a problem if running ZA.


Edit:
Yes, confirmed, in the location you mention, with ZA installed, "vsdatant.sys"=TrueVector Device Driver

bamaman66
August 11th, 2006, 05:32 PM
Yes I am using Zone Alarm. Where could I get instructions on interpreting IceSword results?