Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 13th, 2008, 06:59 PM
ring0_57aR ring0_57aR is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 4
Default RkUnhooker Extended Mode BSODs !!!

RkU? It is a brilliant piece of software. Not perfect, but top notch.

Rootkit Unhooker LE version 3.7.300.509 (build 04.10.2007)

- I activated "Use Extended Mode" & rebooted.
- Everything worked fine
- I tried to de-activate the "Extended Mode"
- I went sadly in a big blasting BSOD. Ouch

I tried both OS:
Windows XP SP2 Home edition
Windows XP SP2 Professional
and VMWare machines

The BLUE SCREEN message was:
---------------------------------------
DRIVER_UNLOADED_WITHOUT_CANCELING_PENDING_OPERATIONS

Stop: 0x000000CE (0xBA342E76, 0x00000008, 0xBA343E76, 0x00000000

rkhdr40.sys

-----------
I cannot de-activate "Extended mode" !!! I have the log saved for anyone interested.


MP_ART, EP_X0FF any ideas ?
  #2  
Old May 13th, 2008, 11:45 PM
EASTER's Avatar
EASTER EASTER is online now
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,504
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
MP_ART, EP_X0FF any ideas ?

You might, and i mean MIGHT try to post that concern at SysInternals Forums but i better let you know right now that their accounts have been banned for the time being, but EP still comes in with another name occasionally.

EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot
  #3  
Old May 14th, 2008, 03:50 PM
kwismer kwismer is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 240
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
Originally Posted by EASTER
You might, and i mean MIGHT try to post that concern at SysInternals Forums but i better let you know right now that their accounts have been banned for the time being, but EP still comes in with another name occasionally.

banned from sysinternals? considering sysinternals was acquired by microsoft and ep was acquired by microsoft, that's really something..

perhaps the OP should just wait until there's an official microsoft branded version of RU released, then there should be a more official avenue through which to obtain support...
  #4  
Old May 14th, 2008, 06:52 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
that's really something..
Nah...not really, what 'EP' does as a pastime is up to 'him'
Quote:
an official microsoft branded version of RkU
lol, yes I'd like to see that.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #5  
Old May 14th, 2008, 07:01 PM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: RkUnhooker Extended Mode BSODs !!!

Don't think it will happen folks but just for ya dreamers out there

Name:  rku.jpg
Views: 299
Size:  27.7 KB

PS No u can't have it!!!
__________________
Ade Gill
Malwarebytes Researcher
  #6  
Old May 14th, 2008, 11:27 PM
EASTER's Avatar
EASTER EASTER is online now
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,504
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
Originally Posted by fcukdat
Don't think it will happen folks but just for ya dreamers out there

Attachment 199943

PS No u can't have it!!!

Some of us can fortunately
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot
  #7  
Old May 15th, 2008, 02:10 AM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,097
Default Re: RkUnhooker Extended Mode BSODs !!!



lol how 'bout dat !!

fcukdat; first time this seen in public outside MS ??
Waaa! I want one.
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres
  #8  
Old May 15th, 2008, 02:37 AM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
Originally Posted by EASTER
Some of us can fortunately
hehe but thats old one...gotta love them
private tools now with added view memory region module Name:  rku.jpg
Views: 234
Size:  41.5 KB

Longboard...M$ no have the latest versions
__________________
Ade Gill
Malwarebytes Researcher

Last edited by fcukdat : May 15th, 2008 at 02:43 AM.
  #9  
Old May 15th, 2008, 04:52 AM
ring0_57aR ring0_57aR is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 4
Default Re: RkUnhooker Extended Mode BSODs !!!

Guys, guys.. We are out of topic.

And fcukdat we are jealous of not having these private builds.

We wish for an ultimate RkU version of course.


But the problem remains.. RkU cannot return to simple mode from extended mode.

Someone proposed to terminate with "sc delete" the service.
As far I can understand the service rkhdrv40 is hidden !!!!!!
Why is that?

I can upload the log files after the BSOD for you to examine.....

Cheers..
  #10  
Old May 15th, 2008, 01:10 PM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: RkUnhooker Extended Mode BSODs !!!

Ok have you tried uninstalling RKU,rebooting and then reinstalling again.This usually resets settings back to default
__________________
Ade Gill
Malwarebytes Researcher
  #11  
Old May 15th, 2008, 10:14 PM
Dwarden Dwarden is offline
Regular Poster
 
Join Date: Apr 2003
Location: Czech Republic
Posts: 160
Default Re: RkUnhooker Extended Mode BSODs !!!

fcukdat these shots look promising ...
i hope that same like with SI tools we get hands on new builds soon(tm)
  #12  
Old May 17th, 2008, 05:17 PM
ring0_57aR ring0_57aR is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 4
Default Re: RkUnhooker Extended Mode BSODs !!!

Quote:
Originally Posted by Dwarden
fcukdat these shots look promising ...
i hope that same like with SI tools we get hands on new builds soon(tm)


yeah! they are good news.

I hope some builds will come out for the loyal fans out there!
  #13  
Old May 17th, 2008, 05:23 PM
EASTER's Avatar
EASTER EASTER is online now
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,504
Default Re: RkUnhooker Extended Mode BSODs !!!

While moving along with each new version when RKU was progressing along publicly and even now, i used AUTORUNS to delete the driver whatever version, since it was just there and not called on unless you engaged the application to run it, it more or less was just available untill called on instead of producing itself again.

EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:05 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums