Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > RootkitRevealer Usage
  New Posts New Posts RSS Feed: RKR freezing...
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

RKR freezing...

 Post Reply Post Reply
Author
Message Reverse Sort Order
Fatal View Drop Down
Newbie
Newbie
Avatar

Joined: 27 February 2007
Location: United States
Online Status: Offline
Posts: 4
Post Options Post Options   Quote Fatal Quote  Post ReplyReply Direct Link To This Post Topic: RKR freezing...
    Posted: 27 February 2007 at 4:11pm

 Karl...Omg cant believe i found you just searching the net for my rootkit revealer error....where you been bro!?

Miss you in CoD come play!

ok to get a tad more serious bro..i have error in Rootkit revealer to run program:(error loading helper driver access is denied) any help would be greatly Apreciatted.

Ok got it to run:

 

 

 

peace bro!

 



Edited by Fatal - 27 February 2007 at 4:46pm
Back to Top
burf View Drop Down
Newbie
Newbie


Joined: 17 February 2007
Online Status: Offline
Posts: 4
Post Options Post Options   Quote burf Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 2:25pm
So I did another scan... a couple of interesting entries.
Like:
"HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\L$_RasDefaultCre dentials#0\OldVac"
- Hidden from Windows API, timestamp: 4/1/05, which was the last time I did a clean install of Windows.
Doing a search, I found nothing, but I suspect it's nothing.

I guess I was able to prevent any possible damage, when I moved that file, and removed the startup entry, before rebooting.

Thanks again for your help, Karl!
Back to Top
burf View Drop Down
Newbie
Newbie


Joined: 17 February 2007
Online Status: Offline
Posts: 4
Post Options Post Options   Quote burf Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 11:24am
Your English is fine!
Yes, I showed hidden devices, and opened every thread... nothing.

I tried Dark Spy, but it didn't seem to analyze anything.  I'd dump a hive, and then do the offline analyze, and it just seemed to show the whole hive tree.  But it's ok ;)

I ran RKR again, this time it finished the scan, although it took much longer than usual.  And it crashed, when I tried to save the results.
So, I have to scan it again.  There were a couple of entries, but nothing that looked like a problem, although I only looked quickly, before I tried to save the results.
It took 20 minutes to dump one hive, with no apparent disk activity.
That is probably what was happening earlier, and I just didn't wait.
I would minimize RKR, and it would freeze.  This time, I was going to give it an hour, before touching anything.

I'll let you know how the next scan is.
And thank you again, for your kind help!

Edited by burf - 17 February 2007 at 11:24am
Back to Top
Karlchen View Drop Down
Senior Member
Senior Member
Avatar

Joined: 18 June 2005
Location: Germany
Online Status: Offline
Posts: 5121
Post Options Post Options   Quote Karlchen Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 10:45am
Hi, burf.

saw nothing strange in device manager.

You will only be able to see any unused devices (like possibly left behind entries by crashed RKR runs) provided you tell the device manager to show hidden/unused devices, too. (devmgmt.msc => view => 2nd item from bottom)
(My translation back from German to English may not be absolutely correct. )

After posting, I actually ran IceSword, and everything looked fine.

Good. Maybe you managed to get rid of the beast already. So, it is up to you if you wish to try out Darkspy and RKU as well. (Though it should do no harm.)

Wondering if RKR will work again, or if it will get stuck in the middle once more ... If the latter which registry hive is being processed?

Karl



Edited by Karlchen - 17 February 2007 at 8:40pm
Back to Top
burf View Drop Down
Newbie
Newbie


Joined: 17 February 2007
Online Status: Offline
Posts: 4
Post Options Post Options   Quote burf Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 9:45am
Thanks, Karl!
I cleaned up the services, and saw nothing strange in device manager.

For a while, I was wondering what those *strange* services were.
I discovered earlier today, that they must be RKR remnants, when after the crash, I actually saw the exe file in the temp folder.

After posting, I actually ran IceSword, and everything looked fine.
I'll try DarkSpy (a new one for me)... then I'll try RKR again, and hopefully, it'll work this time.
I'll post back, afterwards.

Thanks again!



Edited by burf - 17 February 2007 at 9:46am
Back to Top
Karlchen View Drop Down
Senior Member
Senior Member
Avatar

Joined: 18 June 2005
Location: Germany
Online Status: Offline
Posts: 5121
Post Options Post Options   Quote Karlchen Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 7:57am
Hello, burf.

About your RKR issue:

It is a known fact that some malware product will actively try to keep RKR from running. This may or may not be the case on your machine.

Yet, as you launched RKR several times and as it stopped in the middle of its work, it did not have a chance of doing its normal cleanup.
Therefore, it is worth the try to do so yourself manually now. Perhaps this will make RKR work properly again.
Please, have a look at the thread "- Removing junk in services list -"
Note that in addition to any left behind services, there may also be some left behind randomly named device drivers. You may find those using the device manager.


About the malware issue:

You might try (in alphabetical order) one or more of the following products to check (and clean) your machine:
+ DarkSpy
+ IceSword
+ RootkitUnhooker

Kind regards,
Karl


Edited by Karlchen - 17 February 2007 at 8:01am
Back to Top
burf View Drop Down
Newbie
Newbie


Joined: 17 February 2007
Online Status: Offline
Posts: 4
Post Options Post Options   Quote burf Quote  Post ReplyReply Direct Link To This Post Posted: 17 February 2007 at 7:39am
Hi - -  Periodically, I run RKR, and everything comes up normal.
Yesterday, in a brainlock moment, I ran a suspect file on my computer.
It installed a file in system32, ran it, and put it in my startup files.
I closed the file in task manager.  And removed the entry from startup
(HKLM...MS...Run)... and renamed the file.
I then ran a series of different scans, including Blacklight, and Sophos anti-rootkit... everything came up clean.
Then I ran RKR, and after a couple of seconds, it froze.
I waited 15 minutes, and nothing happened.
When I tried to minimize RKR, the whole computer froze.
RKR was stuck on dumping a hive.

Eventually, I shut down my computer, rebooted into recovery console, and did a chkdsk, which fixed some errors, then rebooted.
Everything is coming up clean, but any time I run RKR now, the same freeze happens.  This never happened before.

I'm not an *expert* with computers, but far from a novice.
Any ideas on what might be happening... and what I can do to make sure the computer is clean, would be appreciated.
I have full admin rights on my computer.

Thanks very much!!



Edited by burf - 17 February 2007 at 7:41am
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down