Click to See Complete Forum and Search --> : Interesting Utility of the Day


slgrieb
November 10th, 2008, 05:20 PM
Mandiant Memoryze (http://blogs.zdnet.com/security/?p=2150) is a free tool that can, among other things:

"# enumerate all running processes (including those hidden by rootkits). For each process, Memoryze can:

* report all open handles in a process (for example, all files, registry keys, etc.).
* list the virtual address space of a given process including:
o displaying all loaded DLLs.
o displaying all allocated portions of the heap and execution stack.
* list all network sockets that the process has open, including any hidden by rootkits.
* output all strings in memory on a per process basis.

# identify all drivers loaded in memory, including those hidden by rootkits.

Mandiant (http://www.mandiant.com/software/usememoryze.htm)'s site has additional information about the utility.

sjohnson2
November 10th, 2008, 05:44 PM
hey there slgrieb. This sounds great & all, I love free things, except because I'm a newbie & just learning about the goings on of the computer (you know, other than the basic program usage), and I'd sure love to understand what you just said, or is it one of those things I need more time/experience before I'm even ready to understand?
Thanks. Sam

slgrieb
November 10th, 2008, 07:04 PM
I'd consider this to be an industrial strength program more appropriate for a professional, and fairly specialized, tech rather than a home or casual user. If you're looking for ways to keep your own machine free from nasties, I don't think you can do better than caution and Spybot Search & Destroy. Just don't use the System Protection (Tea Timer) option.

Niclo Iste
November 10th, 2008, 07:19 PM
Thanks for the posting SL. I'm also checking out the other tools they offer it looks like they have one or two more that could be additionally useful in rooting out problems.

NooNoo
November 11th, 2008, 03:50 AM
pun not intended no doubt!