<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; freeware</title>
	<atom:link href="http://www.spamchronicles.com/tag/freeware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Computer Security Logs</description>
	<lastBuildDate>Tue, 05 Oct 2010 22:13:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Rootkit Revealer</title>
		<link>http://www.spamchronicles.com/2007/06/12/rootkit-revealer/</link>
		<comments>http://www.spamchronicles.com/2007/06/12/rootkit-revealer/#comments</comments>
		<pubDate>Tue, 12 Jun 2007 17:37:28 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[freeware]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/anti-spyware/rootkit-revealer/</guid>
		<description><![CDATA[Rootkit Revealer was created by the guys at SysInternals and since Microsoft bought SysInternals it calls Microsoft home. The current version is v1.71 and is available as a free download from Microsoft. I ran the Rootkit Revealer on my Windows XP SP2 PC. It found two registry keys that were suspect but a quick search [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Rootkit Revealer </strong>was created by the guys at SysInternals and since <strong>Microsoft</strong> bought <strong>SysInternals</strong> it calls Microsoft home. The current version is v1.71 and is available as a <a title="Jump to the Rootkit Revaler webpage" href="http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx">free download from Microsoft</a>.</p>
<p>I ran the Rootkit Revealer on my Windows XP SP2 PC. It found two registry keys that were suspect but a quick search showed they were <a title="Jump to the SysInternals posting about these registry keys" href="http://forum.sysinternals.com/forum_posts.asp?TID=8881&amp;PN=1">normal with the latest version of Rootkit Revealer</a>. On a second run, immediately after a reboot, it found some additional files all dated post-reboot. The only old files it flagged were from Microsoft Defender and also appeared to be temporary files that were deleted during normal operations and are an indication of disk/file problems rather than spyware.</p>
<p>The scan also found several files in my Windows\temp directory. Rather than being spyware they all seemed to be temp files that were deleted. The timestamp on all of them was today and since the last boot. The discrepancy is probably due to a disk/file system problem rather than spyware. The message was &#8220;Visible in directory index, but not Windows API or MFT&#8221;.</p>
<p>I also scanned using Microsoft Defender and AVG Anti-Rootkit (both are available from my links page under <a title="Jump to the Free Security Software section on the Links page" href="http://www.spamchronicles.com/links/#Free%20Security%20Software">Free Security Software</a>). Neither found any spyware or rootkits.</p>
<p>Rootkit Revealer looks for rootkit type activity at a much lower level than the more user friendly scan tools which seem to look for specific rootkits. It&#8217;s then up to you to research it and see if it&#8217;s a rootkit. Rootkit Revealer also doesn&#8217;t include any rootkit removal tools. The SysInternal forums are still around and can be used to <a title="Jump to the rootkit revealer log forum" href="http://forum.sysinternals.com/forum_topics.asp?FID=17">help decipher the scan results</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/11/grisoft-avg-releases-free-anti-rootkit/" rel="bookmark" class="crp_title">Grisoft AVG Releases Free Anti-Rootkit</a></li><li><a href="http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/" rel="bookmark" class="crp_title">U.S. AntiSpyware Legislation: Oh-oh</a></li><li><a href="http://www.spamchronicles.com/2007/04/23/viruses-spam-and-software-updates-2/" rel="bookmark" class="crp_title">Viruses, Spam and Software Updates</a></li><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/12/rootkit-revealer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

