More here:
http://forum.sysinternals.com/forum_topics.asp?FID=15
![]() | Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years. Thanks, CNET Support |
At first I was getting the Following:
"Unable to install Rootkitrevealer service. The service did not respond to the start or control request in a timely fashion."
I have solved this but now I am getting the Following:
Interactive services dialog detection box program can't display a message on your desktop. I hit show me the message I get the following
"Error loading helper driver: Access Denies"
In the background is what appears to be the application ready to scan.
I have tried everything suggested and have gotten no where. Please I am pulling out my hair Thanks in advance
Richard
Discussion is locked
This ir fast getting over my head . I think I am going to use RootRepeal found at http://rootrepeal.googlepages.com/home unless someone no's a reason why I should't. Thanks
Richard
After checking further this software is a beta and may not be compatible with Vista, so could someome help me get Microsoft Rootkitrevealer installed or recommend something else. Any ssistance with this would be greatly appreciated as this is driving me crazy.
Richard
The following rootkit detectors/scanners are compatible with Windows Vista (32 bit):
AVZ:(a multifunction antimalware tool with rootkit detection capability):
http://z-oleg.com/avz4.zip
BlackLight Rootkit Eliminator (F-Secure):
http://www.f-secure.com/security_center/
Direct download from F-Secure:
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe
Gmer (by Gmer):
http://gmer.net/
IceSword 1.20 Vista (by pfj):
http://202.38.64.10/%7Ejfpan/download/is120en_vista.zip
PrevxCSI (very quick scanner):
http://info.prevx.com/downloadcsi.asp
Rootkit Unhooker (recently acquired by Microsoft):
http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar
Rootkit Revealer (Microsoft):
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx
Unhackme (Greatis):
http://www.greatis.com/unhackme/download.htm
I ran it and got the following. could you please tell me if the are any problems.
s (File/Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 10/23/2008 16:45:43
Database loaded: signatures - 157571, NN profile(s) - 2, microprograms of healing - 55, signature database released 06.04.2008 17:09
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 70476
Heuristic analyzer mode: Medium heuristics level
Healing mode: disabled
Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
Analysis: kernel32.dll, export table found in section .text
Analysis: ntdll.dll, export table found in section .text
Analysis: user32.dll, export table found in section .text
Analysis: advapi32.dll, export table found in section .text
Analysis: ws2_32.dll, export table found in section .text
Analysis: wininet.dll, export table found in section .text
Analysis: rasapi32.dll, export table found in section .text
Analysis: urlmon.dll, export table found in section .text
Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
Error loading driver - checking interrupted [C0000061]
1.4 Searching for masking processes and drivers
Checking not performed: extended monitoring driver (AVZPM) is not installed
Error loading driver - checking interrupted [C0000061]
2. Scanning memory
Number of processes found: 15
Number of modules loaded: 269
Scanning memory - complete
3. Scanning disks
AVZ Guard error: C0000061
4. Checking Winsock Layered Service Provider (SPI/LSP)
LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\Windows\system32\avgrsstx.dll --> Suspicion for Keylogger or Trojan DLL
C:\Windows\system32\avgrsstx.dll>>> Behavioural analysis
Behaviour typical for keyloggers not detected
Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious programs
Checking disabled by user
7. Heuristic system check
Latent loading of libraries through AppInit_DLLs suspected: "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"
>>> D:\autorun.inf HSC: suspicion for hidden autorun (high degree of probability)
Checking - complete
8. Searching for vulnerabilities
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
>> HDD autorun are allowed
>> Autorun from network drives are allowed
>> Removable media autorun are allowed
Checking - complete
Files scanned: 75837, extracted from archives: 56189, malicious software found 0, suspicions - 0
Scanning finished at 10/23/2008 17:03:00
Time of scanning: 00:17:18
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
suitable for Win XP's (all)? That is Vista specific only? Thanks for your wisdom! Sandy ![]()
What I had posted was titled:
The following rootkit detectors/scanners are compatible with Windows Vista (32 bit):
I just did some research for XP compatible:
ALL of these:
Avz Antiviral Toolkit
Recently added the above security app to my cleanup routine.
Standalone and has heaps of other system features that can come in handy besides the malware scan.
If you decide to try it go to File and update the data base.
http://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http://z-oleg.com/secur/avz/index.php
Some discussion and screenshots here:
http://www.wilderssecurity.com/showthread.php?t=179806
Since its Kaspersky based, it may be similar to the
Kaspersky AVP Tool, however the download file size of AVZ is much smaller than AVP.
http://www.theeldergeek.com/forum/index.php?showtopic=30877
...
F-Secure Blacklight Rootkit Eliminator
http://www.pcworld.com/downloads/file/fid,72632-order,4-page,1-c,antispywaretools/reviews.html
Direct download from F-Secure:
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe
BlackLight also runs on 64-bit Windows XP and Windows 2003 Server (32 and 64-bit)
......
Gmer (by Gmer)
GMER runs on Windows NT/W2K/XP/VISTA
http://gmer.net/index.php
...
IceSword
Windows XP Users - Direct Download IceSword English Version 1.22
http://mail.ustc.edu.cn/~jfpan/download/IceSword122en.zip
http://www.castlecops.com/t165203-IceSword_Instructions_in_English_Illustrated.html
.....
Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx
See list of malicious software including prevalent rootkits detected by the MSRT here:
http://www.microsoft.com/security/malwareremove/families.mspx
...
Rootkit Hook Analyzer by Resplendence (Checks SSDT hooks only):
http://resplendence.com/hookanalyzer
.....
Rootkit Unhooker (recently acquired by Microsoft):
http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar
...
Rootkit Revealer (Microsoft)
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx
...
Unhackme (Greatis)
http://www.greatis.com/unhackme/download.htm
I finally decided on black light. IT downloaded and installed right of the bat and was easy to run.
Richard
I have & have always used Blacklight & AVG Rootkit Scan but it's probably like the Dodo by now . Some of my others MBAM & SAS have
rootkit abilities, but sometimes I want a quick check for rootkit
rather than a long full scan taking perhaps over an hour (SAS).
Also I need to keep up to date to advise others (many who haven't even heard the term) and you, Donna, Roddy32 & Curcat are as up to the minute as it gets in my world!! Thanks again! Sandy
![]()