<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwizguide.com/rss_namespace/">
 <channel>
  <title>Sysinternals Forums</title>
  <link>http://forum.sysinternals.com/</link>
  <description>This is an XML content feed of; Sysinternals Forums : Last 10 Posts</description>
  <pubDate>Sat, 07 Nov 2009 12:19:28 +0000</pubDate>
  <lastBuildDate>Sat, 07 Nov 2009 11:00:27 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 9.54</generator>
  <ttl>30</ttl>
  <WebWizForums:feedURL>forum.sysinternals.com/RSS_topic_feed.asp</WebWizForums:feedURL>
  <image>
   <title>Sysinternals Forums</title>
   <url>http://forum.sysinternals.com/forum_images/images_hero_windows_sysinternals.jpg</url>
   <link>http://forum.sysinternals.com/</link>
  </image>
  <item>
   <title>Internals : Device Driver Listing</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21009&amp;PID=111242#111242</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=12029" rel="nofollow">Meriadoc</a><br /><strong>Subject:</strong> Device Driver Listing<br /><strong>Posted:</strong> 07 November 2009 at 11:00am<br /><br />&nbsp;Maybe<a href="http://www.nirsoft.net/utils/driverview.html" target="_blank">DriverView</a><br><br>The only way to confirm it for yourself would be to run Windbg or something like <a href="http://www.nirsoft.net/utils/blue_screen_view.html" target="_blank">blue screen view</a>.<br><br><br><span style="font-size:10px"><br /><br />Edited by Meriadoc - <strong>Today</strong> at 11:35am</span>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 11:00:27 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21009&amp;PID=111242#111242</guid>
  </item> 
  <item>
   <title>Malware : Analyzing memory dump for malware</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21013&amp;PID=111241#111241</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=22171" rel="nofollow">PROROOTECT</a><br /><strong>Subject:</strong> Analyzing memory dump for malware<br /><strong>Posted:</strong> 07 November 2009 at 9:05am<br /><br />Hi Bomb123,<DIV>&nbsp;</DIV><DIV>Try free tool from Mandiant, called Memoryze: <a href="http://www.mandiant.com/software/freesoftware.htm" target="_blank">http://www.mandiant.com/software/freesoftware.htm</A>&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>... also MBAM, a-squared ...</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>P.</DIV>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 09:05:43 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21013&amp;PID=111241#111241</guid>
  </item> 
  <item>
   <title>Malware : Analyzing memory dump for malware</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21013&amp;PID=111240#111240</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=30837" rel="nofollow">Bomb123</a><br /><strong>Subject:</strong> Analyzing memory dump for malware<br /><strong>Posted:</strong> 07 November 2009 at 8:15am<br /><br />Hello. Is there any tool that would search some malicious code from a memory dump file. I have this memory dump of explorer.exe and it size is 61.6 mb, so how could i find some tool that would tell me if there something malicious in it. All av says that it's clean. Thanks.&nbsp;<span style="font-size:10px"><br /><br />Edited by Bomb123 - <strong>Today</strong> at 8:15am</span>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 08:15:22 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21013&amp;PID=111240#111240</guid>
  </item> 
  <item>
   <title>RootkitRevealer Logs : my Gmer log</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21012&amp;PID=111239#111239</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=17216" rel="nofollow">bug_hunt</a><br /><strong>Subject:</strong> my Gmer log<br /><strong>Posted:</strong> 07 November 2009 at 6:22am<br /><br />Using Gmer, my RKR gives so much unwanted data like it filles pages,tht is even after <br>uninstalling most programs and doing a full disk cleanup.get lots of&nbsp; readings from<br>application data,i formated my system recently.<br><br>My details<br>asus eee<br>windows vista premium<br><br>GMER 1.0.15.15163 - http://www.gmer.net<br>Rootkit scan 2009-11-04 12:06:02<br>Windows 6.0.6000 <br>Running: boor187g.exe; Driver: C:\Users\droid\AppData\Local\Temp\pgroapod.sys<br><br><br>---- System - GMER 1.0.15 ----<br><br>INT 0x62&nbsp; ?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 99FBE550<br>INT 0x71&nbsp; ?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 99FC5A50<br>INT 0x72&nbsp; ?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 99FBEA50<br>INT 0x81&nbsp; ?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 99FC5CD0<br>INT 0xB2&nbsp; ?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 99FBECD0<br><br>---- Devices - GMER 1.0.15 ----<br><br>Device&nbsp;&nbsp;&nbsp; \Driver\BTHUSB \Device\0000005b&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)<br>Device&nbsp;&nbsp;&nbsp; \Driver\BTHUSB \Device\0000005d&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)<br><br>---- Registry - GMER 1.0.15 ----<br><br>Reg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015aff97688&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;<br>Reg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015aff97688 (not active ControlSet) &nbsp;<br><br>---- EOF - GMER 1.0.15 ----<br><br>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 06:22:28 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21012&amp;PID=111239#111239</guid>
  </item> 
  <item>
   <title>Filemon : Security Event Logs being cleared by User=SYSTEM</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21011&amp;PID=111238#111238</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=11966" rel="nofollow">acuster</a><br /><strong>Subject:</strong> Security Event Logs being cleared by User=SYSTEM<br /><strong>Posted:</strong> 07 November 2009 at 2:35am<br /><br /><PRE =WNPost style="WORD-WRAP: break-word"><PRE =WNPost style="WORD-WRAP: break-word">OK, I am dumbfounded on this one.&nbsp; </PRE><PRE =WNPost style="WORD-WRAP: break-word">Our Security event logs are being cleared.&nbsp; This is a serious violation of out ITRM policy for obvious reasons.&nbsp; The event log states USER=system.&nbsp; Clearing always occurs&nbsp; at the top of the hour.&nbsp; This behavior is indicative of a script or EXE.&nbsp; All the obvious have been checked; GPO and scheduled tasks.&nbsp; We have checked the other logs, and nothing occurs around the same time. The SA team is thinking it is an application proc doing this, but I need definitive proof of the root cause.</PRE><PRE =WNPost style="WORD-WRAP: break-word">Is there any other logs, or auditing that will show what proc, running under the system context, is clearing the security log?&nbsp; Or does anyone know of a free app that has more granular auditing. </PRE><PRE =WNPost style="WORD-WRAP: break-word">I am hoping this community can help me before I open a case with MSThanks In AdvanceAaron</PRE>Aaron</PRE>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 02:35:56 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21011&amp;PID=111238#111238</guid>
  </item> 
  <item>
   <title>Autoruns : no icons in list</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111237#111237</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=12978" rel="nofollow">molotov</a><br /><strong>Subject:</strong> no icons in list<br /><strong>Posted:</strong> 07 November 2009 at 1:29am<br /><br />Excellent - good to hear!]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 01:29:21 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111237#111237</guid>
  </item> 
  <item>
   <title>Autoruns : no icons in list</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111236#111236</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=31238" rel="nofollow">mcatis</a><br /><strong>Subject:</strong> no icons in list<br /><strong>Posted:</strong> 07 November 2009 at 1:26am<br /><br />Oh my God!! Simply solution!! Thanks, It works!]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 01:26:24 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111236#111236</guid>
  </item> 
  <item>
   <title>Autoruns : no icons in list</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111235#111235</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=12978" rel="nofollow">molotov</a><br /><strong>Subject:</strong> no icons in list<br /><strong>Posted:</strong> 07 November 2009 at 1:24am<br /><br />Hi mcatis,<div><br></div><div>Consider exiting Autoruns, renaming/removing &#091;HKEY_CURRENT_USER\Software\Sysinternals\AutoRuns&#093;, and then starting Autoruns again. &nbsp;Does that help?</div>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 01:24:19 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111235#111235</guid>
  </item> 
  <item>
   <title>Autoruns : no icons in list</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111234#111234</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=31238" rel="nofollow">mcatis</a><br /><strong>Subject:</strong> no icons in list<br /><strong>Posted:</strong> 07 November 2009 at 12:57am<br /><br />I don't see the little icons in the left of the list in all sections of Autoruns. <P align=left><img src="http://forum.sysinternals.com/uploads/31238/capt.PNG" height="306" width="193" border="0" /></P><DIV><img src="http://forum.sysinternals.com/uploads/31238/capt2.PNG" height="101" width="112" border="0" /></DIV><DIV>The images&nbsp;are only&nbsp;an example to explain better my problem. Solutions? I have win7 64bit. Little problem but very strange.</DIV><span style="font-size:10px"><br /><br />Edited by mcatis - <strong>Today</strong> at 1:13am</span>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 00:57:19 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=21010&amp;PID=111234#111234</guid>
  </item> 
  <item>
   <title>Miscellaneous Utilities : Procdump Hung Window Functionality</title>
   <link>http://forum.sysinternals.com/forum_posts.asp?TID=20790&amp;PID=111233#111233</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.sysinternals.com/member_profile.asp?PF=6786" rel="nofollow">MrMoo</a><br /><strong>Subject:</strong> Procdump Hung Window Functionality<br /><strong>Posted:</strong> 07 November 2009 at 12:54am<br /><br />Same here.&nbsp; I'm trying to use procdump, but it's a royal pain as hung window detection appears to be enabled all the time.&nbsp; I'm just trying a basic:<br><blockquote>procdump -e 1234<br></blockquote>This is on 32-bit XP SP3.&nbsp; I have to use an ugly workaround like:<br><blockquote>procdump -e -n 100 1234<br></blockquote>]]>
   </description>
   <pubDate>Sat, 07 Nov 2009 00:54:23 +0000</pubDate>
   <guid isPermaLink="true">http://forum.sysinternals.com/forum_posts.asp?TID=20790&amp;PID=111233#111233</guid>
  </item> 
 </channel>
</rss>