Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Can't install Microsoft's Rootkitrevealer

Oct 23, 2008 2:14AM PDT

At first I was getting the Following:

"Unable to install Rootkitrevealer service. The service did not respond to the start or control request in a timely fashion."


I have solved this but now I am getting the Following:

Interactive services dialog detection box program can't display a message on your desktop. I hit show me the message I get the following

"Error loading helper driver: Access Denies"


In the background is what appears to be the application ready to scan.
I have tried everything suggested and have gotten no where. Please I am pulling out my hair Thanks in advance

Richard

Discussion is locked

- Collapse -
Did you have a look at their forum?
Oct 23, 2008 2:22AM PDT
- Collapse -
Thanks for the reply......
Oct 23, 2008 2:57AM PDT
- Collapse -
Whoopos
Oct 23, 2008 5:48AM PDT

After checking further this software is a beta and may not be compatible with Vista, so could someome help me get Microsoft Rootkitrevealer installed or recommend something else. Any ssistance with this would be greatly appreciated as this is driving me crazy.

Richard

- Collapse -
The following rootkit detectors/scanners are compatible with
Oct 23, 2008 6:09AM PDT

The following rootkit detectors/scanners are compatible with Windows Vista (32 bit):

AVZ:(a multifunction antimalware tool with rootkit detection capability):

http://z-oleg.com/avz4.zip


BlackLight Rootkit Eliminator (F-Secure):
http://www.f-secure.com/security_center/

Direct download from F-Secure:
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe

Gmer (by Gmer):
http://gmer.net/


IceSword 1.20 Vista (by pfj):
http://202.38.64.10/%7Ejfpan/download/is120en_vista.zip


PrevxCSI (very quick scanner):
http://info.prevx.com/downloadcsi.asp

Rootkit Unhooker (recently acquired by Microsoft):
http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar

Rootkit Revealer (Microsoft):
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

Unhackme (Greatis):
http://www.greatis.com/unhackme/download.htm

- Collapse -
I installed avz
Oct 23, 2008 7:08AM PDT

I ran it and got the following. could you please tell me if the are any problems.

s (File/Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 10/23/2008 16:45:43
Database loaded: signatures - 157571, NN profile(s) - 2, microprograms of healing - 55, signature database released 06.04.2008 17:09
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 70476
Heuristic analyzer mode: Medium heuristics level
Healing mode: disabled
Windows version: 6.0.6001, Service Pack 1 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
Analysis: kernel32.dll, export table found in section .text
Analysis: ntdll.dll, export table found in section .text
Analysis: user32.dll, export table found in section .text
Analysis: advapi32.dll, export table found in section .text
Analysis: ws2_32.dll, export table found in section .text
Analysis: wininet.dll, export table found in section .text
Analysis: rasapi32.dll, export table found in section .text
Analysis: urlmon.dll, export table found in section .text
Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
Error loading driver - checking interrupted [C0000061]
1.4 Searching for masking processes and drivers
Checking not performed: extended monitoring driver (AVZPM) is not installed
Error loading driver - checking interrupted [C0000061]
2. Scanning memory
Number of processes found: 15
Number of modules loaded: 269
Scanning memory - complete
3. Scanning disks
AVZ Guard error: C0000061
4. Checking Winsock Layered Service Provider (SPI/LSP)
LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\Windows\system32\avgrsstx.dll --> Suspicion for Keylogger or Trojan DLL
C:\Windows\system32\avgrsstx.dll>>> Behavioural analysis
Behaviour typical for keyloggers not detected
Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious programs
Checking disabled by user
7. Heuristic system check
Latent loading of libraries through AppInit_DLLs suspected: "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"
>>> D:\autorun.inf HSC: suspicion for hidden autorun (high degree of probability)
Checking - complete
8. Searching for vulnerabilities
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
>> HDD autorun are allowed
>> Autorun from network drives are allowed
>> Removable media autorun are allowed
Checking - complete
Files scanned: 75837, extracted from archives: 56189, malicious software found 0, suspicions - 0
Scanning finished at 10/23/2008 17:03:00
Time of scanning: 00:17:18
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference

- Collapse -
re: I installed avz
Oct 23, 2008 8:06AM PDT
Checking not performed: extended monitoring driver (AVZPM) is not installed

AVZGuard would not load, AVZ Guard error: [c0000061]; What is causing this?

Not enough rights on Vista, I suppose.
http://virusinfo.info/archive/index.php/t-15451.html


AVZGuard Free Malware detection/removal App

http://www.dslreports.com/forum/remark,17201621

......
C:\Windows\system32\avgrsstx.dll --> Suspicion for Keylogger or Trojan DLL

description

avgrsstx.dll is a avgrsst belonging to AVG Internet Security from AVG Technologies CZ, s.r.o.

http://www.processlibrary.com/directory/files/avgrsstx/

.....

Looks like Russian to me...... I found their forum (English) here:

http://virusinfo.info/forumdisplay.php?f=91

..

7. Heuristic system check
Latent loading of libraries through AppInit_DLLs suspected: "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"

avgrsstx.dll =

avgrsstx.dll is a avgrsst belonging to AVG Internet Security from AVG Technologies CZ, s.r.o.

http://www.processlibrary.com/directory/files/avgrsstx/

.....

Files scanned: 75837, extracted from archives: 56189, malicious software found 0, suspicions - 0

So............ you are good to go Happy
- Collapse -
Hi Marianna, Are Any In The List NOT...
Oct 23, 2008 3:08PM PDT

suitable for Win XP's (all)? That is Vista specific only? Thanks for your wisdom! Sandy Happy

- Collapse -
Hi Sandy,
Oct 23, 2008 3:36PM PDT

What I had posted was titled:

The following rootkit detectors/scanners are compatible with Windows Vista (32 bit):

I just did some research for XP compatible:

ALL of these:

Avz Antiviral Toolkit

Recently added the above security app to my cleanup routine.

Standalone and has heaps of other system features that can come in handy besides the malware scan.

If you decide to try it go to File and update the data base.

http://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http://z-oleg.com/secur/avz/index.php


Some discussion and screenshots here:

http://www.wilderssecurity.com/showthread.php?t=179806

Since its Kaspersky based, it may be similar to the
Kaspersky AVP Tool, however the download file size of AVZ is much smaller than AVP.

http://www.theeldergeek.com/forum/index.php?showtopic=30877

...

F-Secure Blacklight Rootkit Eliminator

http://www.pcworld.com/downloads/file/fid,72632-order,4-page,1-c,antispywaretools/reviews.html

Direct download from F-Secure:
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe

BlackLight also runs on 64-bit Windows XP and Windows 2003 Server (32 and 64-bit)

......

Gmer (by Gmer)

GMER runs on Windows NT/W2K/XP/VISTA

http://gmer.net/index.php

...

IceSword

Windows XP Users - Direct Download IceSword English Version 1.22

http://mail.ustc.edu.cn/~jfpan/download/IceSword122en.zip

http://www.castlecops.com/t165203-IceSword_Instructions_in_English_Illustrated.html

.....

Malicious Software Removal Tool

http://www.microsoft.com/security/malwareremove/default.mspx

See list of malicious software including prevalent rootkits detected by the MSRT here:

http://www.microsoft.com/security/malwareremove/families.mspx

...

Rootkit Hook Analyzer by Resplendence (Checks SSDT hooks only):

http://resplendence.com/hookanalyzer

.....

Rootkit Unhooker (recently acquired by Microsoft):

http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar

...

Rootkit Revealer (Microsoft)

http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

...

Unhackme (Greatis)

http://www.greatis.com/unhackme/download.htm

- Collapse -
Thanks for the help-...
Oct 24, 2008 6:06AM PDT

I finally decided on black light. IT downloaded and installed right of the bat and was easy to run.


Richard

- Collapse -
(NT) Super :) You Are Welcome !
Oct 24, 2008 6:34AM PDT
- Collapse -
Thanks So Much For The Extra Work, Lady M!!
Oct 24, 2008 3:12PM PDT

I have & have always used Blacklight & AVG Rootkit Scan but it's probably like the Dodo by now . Some of my others MBAM & SAS have
rootkit abilities, but sometimes I want a quick check for rootkit
rather than a long full scan taking perhaps over an hour (SAS).

Also I need to keep up to date to advise others (many who haven't even heard the term) and you, Donna, Roddy32 & Curcat are as up to the minute as it gets in my world!! Thanks again! Sandy Grin Love