![]() |
Error dumping hive |
Post Reply
|
| Author | ||
louiscar
Newbie
Joined: 25 April 2009 Online Status: Offline Posts: 5 |
Quote Reply
Topic: Error dumping hivePosted: 25 April 2009 at 7:30am |
|
|
I just scanned my system and ended up with a few things that I investigated and then fixed after creating a restore point.
The fixes were embedded nulls which I established were from legit software I no longer had on my system so I removed them using RegDelNull
After rescanning I am getting several errors dumping hive. Whether this was due to running RegDelNull or not I have no idea but I restored the registry and am still getting the following:
Note the date stamp (did they have computers back then)?
At this point Status bar shows:
Dumping HKLM SYSTEM hive
... then an error (see below)
Edit:
What I forgot to mention is that on the first scan RKR stopped eventually with an error:
"An error occurred in CMD.EXE that prevents Rootkitrevealer from acurately analysing your system.
If CMD.EXE is available on your system please report the failure."
and on the second scan eventually I get the same thing.
CMD.exe is definitely available, I use it regularly and checked after this message without any problems.
Perhaps on the first scan RKR messed something up by terminating abnormally? Either way it seems like it's permanent. Can anyone tell me what went wrong and how to fix this? Edited by louiscar - 25 April 2009 at 7:51am |
||
![]() |
||
louiscar
Newbie
Joined: 25 April 2009 Online Status: Offline Posts: 5 |
Quote Reply
Posted: 25 April 2009 at 8:36am |
|
|
Might be worth mentioning after checking a few related threads that I have no detected malware using several scanners and no abnormal problems that others reported such as regedit closing or crashing exporer etc.
I decided to run RKR because Services.exe is taking up 640MB or memory and once I had freed this memory using process hacker only to find it eventually returned I then looked at what was happening with Process Monitor at the point where the memory popped back up to 640MB. It showed some FASTIO_READ events at that point which a Google search for FASTIO_READ and services.exe let me to a discussion on rootkits.
|
||
![]() |
||
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17287 |
Quote Reply
Posted: 26 April 2009 at 5:12am |
|
|
Hi louiscar,
If you reboot, are you still unable to scan with RKR? Have you tried another ARK such as Root Repeal? |
||
|
Daily affirmation:
net helpmsg 4006 |
||
![]() |
||
louiscar
Newbie
Joined: 25 April 2009 Online Status: Offline Posts: 5 |
Quote Reply
Posted: 26 April 2009 at 3:22pm |
|
Still happens after a reboot. As I say, I restored the registry to see if it was something I had done.
I just downloaded rootrepeal which runs ok although doesn't seem to try to load hives. Interestingly it comes up with MBR rootkit detected on C: - dont' know if that's a false positive or not (guessing that it is). Edited by louiscar - 26 April 2009 at 4:02pm |
||
![]() |
||
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17287 |
Quote Reply
Posted: 27 April 2009 at 3:23am |
|
|
What about GMER?
|
||
|
Daily affirmation:
net helpmsg 4006 |
||
![]() |
||
louiscar
Newbie
Joined: 25 April 2009 Online Status: Offline Posts: 5 |
Quote Reply
Posted: 27 April 2009 at 6:09pm |
|
|
Looks like it's Mebroot rootkit unfortunately
|
||
![]() |
||
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17287 |
Quote Reply
Posted: 27 April 2009 at 6:20pm |
|
|
That would of course have some impact on what you are experiencing...
|
||
|
Daily affirmation:
net helpmsg 4006 |
||
![]() |
||
louiscar
Newbie
Joined: 25 April 2009 Online Status: Offline Posts: 5 |
Quote Reply
Posted: 27 April 2009 at 7:41pm |
|
|
It's certainly the reason for th bloated services.exe. Once I removed the compromising data file it returned to normal size. Just have to deal with the rootkit now.
Edited by louiscar - 27 April 2009 at 7:42pm |
||
![]() |
||
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |