PDA

View Full Version : RootKit UnHooker Log Analysis


aigle
April 26th, 2007, 12:12 AM
Not sure where I should post. Their site is down I think.
I use XP SP2. Security application in my sig.
Thanks for any expert opinions.
My system is OK, just tried it out of curiosity.

BTW, Sysinternals forums are still not working?

Meriadoc
April 26th, 2007, 03:40 AM
Hi,
Sysinternals forums are back since 2 weeks, log looking clean as you know. Perhaps there (http://forum.sysinternals.com/) or antirootkit (http://www.antirootkit.com/forums/viewforum.php?f=35&sid=546f3fd11a399383a5f81b208ecec348) for analysis. Is there a reason why you do not use latest ver.?

EP_X0FF
April 26th, 2007, 04:51 AM
Hello,

your log is full of false positives which was removed in v3.20 - v3.30.

I suggest you use exactly 3.30 because 3.31 have some general problems with IO operations.

incursari
April 26th, 2007, 08:02 AM
Hi EP_X0FF, is there any mirror for version 3.30 english?

aigle
April 26th, 2007, 03:40 PM
{QUOTE-> Hello,

your log is full of false positives which was removed in v3.20 - v3.30.

I suggest you use exactly 3.30 because 3.31 have some general problems with IO operations. <-QUOTE}
Thanks a lot. i was really expecting a reply from u.

aigle
April 26th, 2007, 03:41 PM
{QUOTE-> Hi,
Sysinternals forums are back since 2 weeks, log looking clean as you know. Perhaps there (http://forum.sysinternals.com/) or antirootkit (http://www.antirootkit.com/forums/viewforum.php?f=35&sid=546f3fd11a399383a5f81b208ecec348) for analysis. Is there a reason why you do not use latest ver.? <-QUOTE}

Thanks, no specific reason. I just used the versio that was on my PC at that time. Too lazy.;D

EP_X0FF
April 26th, 2007, 08:49 PM
{QUOTE-> Hi EP_X0FF, is there any mirror for version 3.30 english? <-QUOTE}

http://rku.nm.ru/rkunhooker_v3/RkU3.30.150.400.rar

aigle
April 26th, 2007, 08:54 PM
thanks.

incursari
April 27th, 2007, 08:08 AM
{QUOTE-> http://rku.nm.ru/rkunhooker_v3/RkU3.30.150.400.rar <-QUOTE}

Thank you.