PDA

View Full Version : Rescue disk wont scan anything?!


BuckoA51
April 10th, 2009, 04:48 AM
I'm trying to use the new ESET Sysrescue disk on a laptop. The laptop has two hard drive partitions c: and d: with a lot of files on.

So I boot the rescue CD, choose "custom scan" tick both C: and D: even go into setup and select extensions and tick "scan all files"

then I hit scan, ESET scans for 7 seconds then says "Scan completed sucessfully in 7 seconds"

Number of scanned objects 0

0?!

What the heck?

HELP!

EDIT - Just tried same disc on another PC, with 2gb of memory, same problem! The scanner on the resue disk will not touch any files.

miki69
April 10th, 2009, 05:19 AM
maybe you need to select all folders/subfolders? It sounds like you scanned only root on both partitions, or scan didn't trigger at all (0 files).

Marcos
April 10th, 2009, 06:31 AM
What platform, OS and service pack do you use?

GrammatonCleric
April 10th, 2009, 08:18 AM
I have EXACTLY THE SAME PROBLEM.

Not to Hijack the thread but I will also Answer Marco's question (as I did in the previous SYSResque post on AV subforum...the answer to Marcos question went unanswered by ESET there maybe I will have more luck here).

So I stated in my previous post about this problem:
I have SysRescue disk made from 4.x.417 version of ESET ANTIVIRUS:
WIndows XP SP3 (patched up to last patch tuesday).

Sys Rescue boots fine, ALL FILES ARE SELECTED, MAX SETTINGS SELECTED, ALL DRIVES are VISIBLE and SELECTED, The drives are Multi Terabyte Arrays, the scan completed in 40 seconds, I can see the folders being accessed and flown through via the Real Time ESET scanner aka C:\, c:\Program Files, c:\Secret Pron Stash etc. But at the end the number of files scanned is 0. :)

YAY!!!

BuckoA51
April 10th, 2009, 10:14 AM
Yes I double and triple checked that all files were selected, I can see the scanner going through the folders but it never scans any files.

Windows XP Pro SP3

DarrenDavisLeeSome
April 10th, 2009, 03:26 PM
Correct me if I'm mistaken, but isn't SysRescue more intended for Vista?

I looked into the SysRescue bit. It said I needed to have Windows AIK installed. Clicked on the link they provided. Took me to a Microsoft download page:

Automated Installation Kit (AIK) for Windows Vista SP1 and Windows Server 2008
Brief Description
The Windows Automated Installation Kit (Windows AIK) is designed to help corporate IT professionals customize and deploy the Windows Vista and Windows Server 2008 family of operation systems.
On This Page
Quick DetailsOverviewSystem RequirementsInstructionsRelated ResourcesWhat Others Are Downloading

Quick Details
File Name: 6001.18000.080118-1840-kb3aikl_en.iso
Version: 936330AIK
Date Published: 4/9/2008
Language: English
Download Size: 1375.9 MB
Estimated Download Time: 55 hr 55 min 56K Dial-up (56K)DSL/Cable (256K)DSL/Cable (768K)T1 (1.5M) 55 hr 55 min

--------------------------------------------------------------------------------

Change Language: ArabicChinese (Simplified)Chinese (Traditional, Taiwan)CzechDanishDutchEnglishFinnishFrenchGermanGreekHebrewHungarianItalianJapaneseKoreanNorwegian (Bokmål)PolishPortuguese (Brazil)Portuguese (Portugal)RussianSpanishSwedishTurkish


Overview
The Windows Automated Installation Kit (Windows AIK) is designed to help corporate IT professionals customize and deploy the Windows Vista and Windows Server 2008 family of operation systems. By using Windows AIK, you can perform unattended Windows installations, capture Windows images with ImageX, and create Windows PE images.

This update is provided to you and licensed under the Windows Vista License Terms.
Top of page

System Requirements
Supported Operating Systems: Windows Server 2008; Windows Vista


Windows Vista

Windows Vista Service Pack 1

Windows Server 2008

Windows Server 2003 Service Pack 1 with KB926044

Windows Server 2003 Service Pack 2

Windows XP Service Pack 2 with KB926044



I reckon it could be setup for Windows XP SP3 even though there is no mention of it in the System Requirements. May need some other KB's installed.
.
.
.
.
.

GrammatonCleric
April 13th, 2009, 08:52 AM
Any update on this or are we again going to be left hanging after providing the requested info?

Also provided the same info on April 7th in this thread:
http://www.wilderssecurity.com/showthread.php?t=238368

DarrenDavisLeeSome
April 13th, 2009, 11:56 AM
The whole SysRescue aspect of ESS 4.0 is based on Vista. But, I'm sure that it could be used with XP IF Windows AIK is used during the PREINSTALLATION.



Personally, I have no need for SysRescue. I was just curious about it.

GrammatonCleric
April 13th, 2009, 12:14 PM
-{ Quote: "The whole SysRescue aspect of ESS 4.0 is based on Vista. But, I'm sure that it could be used with XP IF Windows AIK is used during the PREINSTALLATION.



Personally, I have no need for SysRescue. I was just curious about it." }-


Hmm well in that case, it makes sense but sucks for me since my Vista system is using KAV and I don't feel like swapping.

CrunchieBite
April 14th, 2009, 01:51 PM
-{ Quote: "

Also provided the same info on April 7th in this thread:
http://www.wilderssecurity.com/showthread.php?t=238368" }-

Also posted same problem on 3rd March here:
http://www.wilderssecurity.com/showthread.php?t=234902

~M

GrammatonCleric
April 14th, 2009, 04:01 PM
Hmmm well let's hope they fix it or post a note saying that RESCUE DISK IS FOR VISTA ONLY.

Otherwise I can make a blank CD to scan my system and get the same result, but at least I will still have a CD that I can use for something else.

eisefr
April 15th, 2009, 12:25 AM
So many bugs in a software...
God.. how much more ridiculous can it get ? ::)

trencan
April 15th, 2009, 02:49 AM
-{ Quote: "Hmmm well let's hope they fix it or post a note saying that RESCUE DISK IS FOR VISTA ONLY.
" }-

SyRescue in not dedicated only to Vista. You can build it on XP too.

WinPE OS which is used in SysRescue is based on Vista SP1.

GrammatonCleric
April 15th, 2009, 07:03 AM
-{ Quote: "SyRescue in not dedicated only to Vista. You can build it on XP too.

WinPE OS which is used in SysRescue is based on Vista SP1." }-


That's what I thought, afterall it built OK on WinXP SP3 HOWEVER it DOES NOT SCAN A SINGLE FILE.


Now according to:

-{ Quote: " The whole SysRescue aspect of ESS 4.0 is based on Vista. But, I'm sure that it could be used with XP IF Windows AIK is used during the PREINSTALLATION. " }-

ESET 4.0 SYSRESCUE is for VISTA ONLY????
Unless I hear otherwise from ESET I will be forced to assume that this is true, if so then why not place that disclaimer on the page?
So far the ESET MODS have gone AWOL once the mod requested info was posted. I mean it's nice to come in give a generic question to show the presence and then when the question is answered go AWOL.
At least say something, like "we are working on it" since we know that you are reading this thread, after all the initial mod response was 2 hours after posting.
This will at least show a continual level of support or at least vigilance, otherwise the "Bad ESET support" stereotype is just being drawn out in yet another example. And please don't come in and say: "NO ESET 4.0 SYSRESCUE is not for VISTA ONLY" and then leave, since that I can answer that myself.

BedreAntivirus
April 15th, 2009, 08:49 AM
you need to use the "If you are using Windows XP or earlier, you must also install Windows IMAPI 2.0 (Image Mastering API) before creating your ESET SysRescue media" for SysRescue on XP
http://kb.eset.com/esetkb/index?page=content&id=SOLN2103

GrammatonCleric
April 15th, 2009, 09:27 AM
-{ Quote: "you need to use the "If you are using Windows XP or earlier, you must also install Windows IMAPI 2.0 (Image Mastering API) before creating your ESET SysRescue media" for SysRescue on XP
http://kb.eset.com/esetkb/index?page=content&id=SOLN2103" }-
Gotcha will give it a try.

The SysRescue wizard should detect the OS and presence or absence of the IMAPI then prompt the user for appropriate action. It should not successfully complete giving the user a useless disk.

DarrenDavisLeeSome
April 15th, 2009, 10:06 AM
Hey GrammatonCleric

Could you please explain the steps you took prior to running SysRescue for the first time?

Did you already use Windows AIK to install and/or preinstall your XP SP3 OS?

I understand that Windows AIK and IMAPI 2.0 need to be installed on an XP OS before SysRescue can make a bootable media.

But...

I've been searching Microsoft's website for 3 days and the only thing that I could come up with is that Windows AIK CAN be installed on an XP OS.... to deploy a customized installation of VISTA...on another system. How can there possibly be a way to create any kind of CD,DVD, or other media using files intended for Vista to scan an XP System? Windows AIK always been a deployment tool for Vista family of OS's. XP and Vista...apples and oranges.
Despite their simularities, XP and Vista are 2 completely different OS's.

This whole concept of making a "working" SysRescue media to scan an XP system...just doesn't make any sense at all to me.

BedreAntivirus
April 15th, 2009, 02:29 PM
can sysrescue find the disks?
meybe its missing some sata/ide drivers

GrammatonCleric
April 15th, 2009, 02:55 PM
-{ Quote: "Hey GrammatonCleric

Could you please explain the steps you took prior to running SysRescue for the first time?

Did you already use Windows AIK to install and/or preinstall your XP SP3 OS?

I understand that Windows AIK and IMAPI 2.0 need to be installed on an XP OS before SysRescue can make a bootable media.

But...

I've been searching Microsoft's website for 3 days and the only thing that I could come up with is that Windows AIK CAN be installed on an XP OS.... to deploy a customized installation of VISTA...on another system. How can there possibly be a way to create any kind of CD,DVD, or other media using files intended for Vista to scan an XP System? Windows AIK always been a deployment tool for Vista family of OS's. XP and Vista...apples and oranges.
Despite their simularities, XP and Vista are 2 completely different OS's.

This whole concept of making a "working" SysRescue media to scan an XP system...just doesn't make any sense at all to me." }-

I installed Windows AIK off the MS website, rebooted the system and ran the SysRescue, followed the rescue steps, created the iso or rather sysrescue created the iso.
I burnt the iso with NERO and rebooted the system and told it to load from CD.
There Sysrescue loaded into the environment, eset asked me to updated defs I told it no since I had no net connection on the PC (yanked it before scan). Started the custom scan by checking everything and all files, max out the scan parameters (AH, unknown programs, all extensions etc).
Saw the scan look at drives and into folders, after 40 seconds to a min or so it came up done and 0 files scanned.

IT could not be the drivers since ESET scan saw the drives and actually went through the folders as could be seen by the real time scanning path window thingy.

I have WinXP system and ESET does not mention that their sysrescue is VISTA only, if it is indeed VISTA only then please say so and provide the XP users with a different tool, otherwise please fix this.

When I get back home today I will try the steps again as per the KB article and see what happens.

DarrenDavisLeeSome
April 15th, 2009, 03:55 PM
Looks like you had better success than I did.

I downloaded the WAIK .IMG. Used Nero to burn the DVD Image.

Ran the DVD: started the WAIK Setup. It couldn't continue. Said .NET Framework and MSXML6 needed to be installed. So I installed .NET then MSXML 6.

Then I installed the IMAPI 2.0 as per the ESET KB.

Ran SysRescue. Chose to have it burn an ISO. Clicked Next and a moment later I got a popup> SysRescue Error: could not find required module. Same thing if I tried chose to burn to CD/DVD.

DarrenDavisLeeSome
April 15th, 2009, 05:53 PM
Okay. I think the reason why I couldn't get SysRescue to work before was because I didn't reboot my system after installing Windows AIK. I didn't see that mentioned in the ESET KB before.

So, I made a successful SysRescue DVD using my External DVD Burner/Player. My External DVD is not bootable so I stuck it in my friend's system and it booted up. Neato. Went to go run a scan and I got the same thing GrammatonCleric got: 1 second to scan, 0 scanned files, etc...

Then I noticed the Update(r) was running. It was actually updating the Virus Database. Neato. The Virus Database that's on the SysRescue is #4000. The Updater installed the latest updates to #4011 (20090415). Neato. After it was finished updating I went and ran a scan and it began scanning everything. Neato. Took a little over 6 minutes on my friend's system.

My guess the reason why GrammatonCleric got nothing but zeros was cuz it was updating the VD. It takes awhile to finish. First the SysRescue program has to establish a network/internet connection, then it downloads them, then installs them.

So, GrammatonCleric, give it some time to complete the updates (granted that you're still connected to your network/internet) and then run the scan. Could it be that simple? Must be. I got my SysRescue DVD to work....on my friend's system, and he doesn't have ESS installed on it anymore (his trial for ESS 4.0 expired 5 days ago so he restored his Ghost Image with Norton AV on it :gack: He hates it. Loves ESS 4.0 though...even thought he gets the same Application popups I do on my system) .

GrammatonCleric
April 15th, 2009, 06:34 PM
Hmm the update thing will be bit of a problem since the system will be offline during the scan but let see if I can do it while it's online.

If that indeed is the case then I will be very happy.



My wife and I were happy for twenty years. Then we met.

DarrenDavisLeeSome
April 15th, 2009, 06:42 PM
Did you install the IMAPI 2.0 ??

GrammatonCleric
April 15th, 2009, 06:44 PM
-{ Quote: "Did you install the IMAPI 2.0 ??" }-
Downloading it as I type...however I don't see a need for IMAPI 2.0 when I am making an ISO. IMAPI 2.0 is required when I want the app to burn the disk for me.
But I will give it a whirl.

trencan
April 16th, 2009, 01:59 AM
-{ Quote: "Downloading it as I type...however I don't see a need for IMAPI 2.0 when I am making an ISO. IMAPI 2.0 is required when I want the app to burn the disk for me.
But I will give it a whirl." }-

Right, IMAPI2.0 is windows API for burning CD/DVD. If you want to create only ISO, you don't need it at all.

trencan
April 16th, 2009, 02:43 AM
-{ Quote: "
There Sysrescue loaded into the environment, eset asked me to updated defs I told it no since I had no net connection on the PC (yanked it before scan).
" }-

So when SysRescue asked you to update defs, what did you do exactly? Did you click "Cancel"? If so, then you cancelled update at all and therefore it is not able to scan any files on HDD, because defs are not loaded. To be able to function correctly, you need to select either update "from installed ESS/EAV on your HDD" or "from web". You can select "from web" also if you don't have internet connection, doesn't matter, SysRescue will try to download update un-successfully and then it uses defs on CD.

To clarify things, you can build SysRescue disk on XP as well as on Vista. You can use SysRescue disc for HDD scan on PC with whatever Win OS installed. Then it's matter only of correct disk drivers in SysRescue. But if you see drives, then there should be no problem with scanning at all.

trencan
April 16th, 2009, 03:06 AM
-{ Quote: "
Then I noticed the Update(r) was running. It was actually updating the Virus Database. Neato. The Virus Database that's on the SysRescue is #4000. The Updater installed the latest updates to #4011 (20090415). Neato. After it was finished updating I went and ran a scan and it began scanning everything. Neato. Took a little over 6 minutes on my friend's system.
" }-

That's right. While VD is being downloaded you are not able to scan any files. Reason is that SysRescue doesn't use VD on CD, if it is downloading VD from web. So you need to wait till download is finished.

GrammatonCleric
April 16th, 2009, 06:53 AM
Yes made the CD, chose use the av bases found on the CD (same as I did with my previous cd) but now it scanned. :) :D
Thanks all for all your help.
The only think I can think of is that maybe the previous CD was .314 version???
Don't know I chucked it few days ago.
But I am very happy that it works, thanks all.

DarrenDavisLeeSome
April 16th, 2009, 10:06 AM
-{ Quote: "The only think I can think of is that maybe the previous CD was .314 version" }-

Shouldn't have anything to do with it. I'm using the v.314 too. ;D

-{ Quote: "Reason is that SysRescue doesn't use VD on CD, if it is downloading VD from web. So you need to wait till download is finished." }-

Downloading VD isn't really necessary to run the scan. SysRescue just has to go through the motions of updating. Once it sees that there are no updates available, namely because there is no internet connection, it will load whatever VD is on the disk.

Here's an interesting note: if you have ESS or NOD32 installed on the same system SysRescue will find the VD update package installed. You'll be prompted to choose between that update package or to use the web to download updates.

DarrenDavisLeeSome
April 16th, 2009, 10:32 AM
Just thought of a question.

If SysRescue finds some viruses or spyware on any given system, regardless if ESS or NOD32 is installed on that system, is there a way to copy that log someplace so that virus/spyware files could be submitted later? Or will they have to be submitted while the system is still in the SysRescue Environment?

trencan
April 16th, 2009, 12:50 PM
-{ Quote: "
Downloading VD isn't really necessary to run the scan. SysRescue just has to go through the motions of updating. Once it sees that there are no updates available, namely because there is no internet connection, it will load whatever VD is on the disk.

Here's an interesting note: if you have ESS or NOD32 installed on the same system SysRescue will find the VD update package installed. You'll be prompted to choose between that update package or to use the web to download updates." }-

SysRescue boots up. It tries to find installed ESS/EAV on all of your HDDs. If there is some with VD newer than it has on CD, it prompts user if to use VD found on HDD or to try to download VD from web. If you click Cancel, then update process is cancelled and it doesn't use any VD. That's why it is then not usable and scanning ends up with 0 scanned files.

If you choose to update from web, then it starts to download VD from internet. This can take same time and during this time it is not possible to use HDD scanning, since SysRescue doesn't use VD on CD in that case. It waits till VD from web are downloaded. If internet connection is not available, SysRescue uses VD on CD.

trencan
April 16th, 2009, 12:58 PM
-{ Quote: "Just thought of a question.

If SysRescue finds some viruses or spyware on any given system, regardless if ESS or NOD32 is installed on that system, is there a way to copy that log someplace so that virus/spyware files could be submitted later? Or will they have to be submitted while the system is still in the SysRescue Environment?" }-

As soon as SysRescue is turned off, all changes made to drive X: (system drive for SysRescue) are forgotten. So you need to copy log file to your HDD or USB key. It can be done via copy cmd in shell. Or you can put some file manager when building iso (e.g. FAR). Then launch it when running sysrescue.

BuckoA51
May 13th, 2009, 04:47 AM
So if the computer has no network connection then we just have to what, wait a moment while it tries to update?