Icesword Or The Art of War against rootkits

Miscellaneous Forums/General Discussion/Icesword Or The Art of War against rootkits

A chinese guy has made a very powerfull app to enlighten even the darkest corners of your windows. It's called Icesword. It allows a lot of things including tracing processes, port activity, keyloggers etc. especially designed to uncover well hidden rootkits. It's very powerfull, so be careful.

Unfortunately the original host cannot be reached from a lot of countries (coincedence?), Here's a german guy who mirrors the latest version, 1.18, includng md5 checksum etc.
http://c-ko.blogspot.com/2006/05/icesword-118-erschienen.html

For description and howtows refer to google etc.

I cannot give any warranty on the security of the app. Tho it seems it's a clean thing.

Icesword Or The Art of War against rootkits

Wish I knew what that ment. Its probably someting realy improtant isnt it?

rootkits are nastey little unwanted spyware/dataminer
apps some of which are near impossible to get of once they
get onto your system...i dont know how they work, but i
know that spyware or other software using this technique
cannot be removed easily...

am i wrong? - perhaps im thinking of something else..lol

http://en.wikipedia.org/wiki/Rootkit

How did I miss that entire sony thing?

Was it only a US thing?

A clever keylogger may be very harmful. Especially when you are shopping online and have a high card limit.

IceSword gives access to stuff windows is trying to hide from the user by default. It allows for example to kill a process that is protected by the OS.

Newbies should be very careful with this app, it can easily crash your machine.

Other tools with a similar purpose are: Blacklight by f-secure or rootkit revealer by sysinternals or klister.
See also www.invisiblethings.org

Can't stuff like Adaware kill rootkit hidden keyloggers?

There are rootkits and rootkits. One thing that makes it a real rootkit is the lack of tools that may detect it and / or remove it.

Adaware may be useful for a lot of things. The real mean stuff must be catched with something more powerful. Blacklight will automaticly remove things, in Icesword there's no auto remove function, it's more a multipurpose tool to investigate by your own.

For example a lot of rootkits use twin processes to keep themselfs alive. If you kill one with eg. taskmanager, the other one will restart the one you just killed. In this situation you must be able to select multiple processes and pause the os while all the processes are killed.

Other features are searching for hidden registry entries, they are suspect in general. It will especially give you a good overview over all things that will autostart and also allows to log the autostart processes. It also gives more info than eg. Zomealarm on port activity and what apps are using them. Although you may have a look at the packets, one should use a traffic anlayzer for this purpose (eg. www.atelierweb.com )

Its just seems to me, that anything that powerful, is crying out to be troygened. (Real word? Def:Made into a Troygen Horse)

crying out to be troygened. (Real word? Def:Made into a Troygen Horse)


Nothing to do with genetic splicing then?

Or did you mean Trojan?

(I'm in pedant mode today)

Stupid clasical greek nameing structure ;)

Obviously I mean Trojaned ;) As in the participle of the verb "To Trojan"

CONDOMIZE your computer!!! I'm sorry but I can't help but think of the TROJAN MAN commercials when I read about TROJANS!!! I use Blacklight... I had a sneaky little buggr in my OS and I could not figure out how these trojans kept reappearing when I had physically disconnected my modem... Blacklight solved it. Took down the OS as well but I think it HAD to kill it... the taskmgr.exe had been "infiltrated" or "subverted" and AVAST kept finding them when they went off but could not determine the root of the evil... I burned BLACKLIGHT on to a CD from a buddys house...

Reinstalled XP Pro... good to go!

Can't stuff like Adaware kill rootkit hidden keyloggers?


Adaware is doesn't always catch everything. I caught this spyware once that none of my virus/spyware programs was able to get. Ended up having to do an extensive web search and learned to manually removed it myself....a good thing too cause i was very close to reformatting...

>> that anything that powerful, is crying out to be troygened <<

If the tool is once popular, somebody may try to add his backdoor, yes. Right now it seems it's a admin tool for a minority of careful people.

In fact there's already some malware that is trying to crash Icesword.

Additionally, you can(should?) use one of the other tools with a similar purpose to watch Iceword. This is a simple Exe, no installation required. It will start a TSR process that's running in the background, until you reboot the machine. So you have pretty good control over it's actions (compared to apps that are turning the whole system upsidedown).

As Rook described, in some cases rootkits can be real nasty, replacing parts of the os and do weird things. Did you ever try to create a new textfile on a writeprotected floppydisk and there was no error message? It makes you wonder what's up, but the average user has no tools to monitor the system.