![]() |
|
#1
|
|||
|
|||
|
RkU? It is a brilliant piece of software. Not perfect, but top notch.
Rootkit Unhooker LE version 3.7.300.509 (build 04.10.2007) - I activated "Use Extended Mode" & rebooted. - Everything worked fine - I tried to de-activate the "Extended Mode" - I went sadly in a big blasting BSOD. Ouch I tried both OS: Windows XP SP2 Home edition Windows XP SP2 Professional and VMWare machines The BLUE SCREEN message was: --------------------------------------- DRIVER_UNLOADED_WITHOUT_CANCELING_PENDING_OPERATIONS Stop: 0x000000CE (0xBA342E76, 0x00000008, 0xBA343E76, 0x00000000 rkhdr40.sys ----------- I cannot de-activate "Extended mode" !!! I have the log saved for anyone interested. MP_ART, EP_X0FF any ideas ? |
|
#2
|
||||
|
||||
|
Quote:
You might, and i mean MIGHT try to post that concern at SysInternals Forums but i better let you know right now that their accounts have been banned for the time being, but EP still comes in with another name occasionally. EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★|
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11
¶Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
|
|
#3
|
|||
|
|||
|
Quote:
banned from sysinternals? considering sysinternals was acquired by microsoft and ep was acquired by microsoft, that's really something.. perhaps the OP should just wait until there's an official microsoft branded version of RU released, then there should be a more official avenue through which to obtain support... |
|
#4
|
||||
|
||||
|
Quote:
Quote:
__________________
Who controls the past controls the future Who controls the present controls the past vmworld |
|
#5
|
||||
|
||||
|
Don't think it will happen folks
but just for ya dreamers out there PS No u can't have it!!!
__________________
Ade Gill Malwarebytes Researcher |
|
#6
|
||||
|
||||
|
Quote:
Some of us can fortunately ![]()
__________________
★AX 64 Time Machine★
★Shadow Defender★|
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11
¶Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
|
|
#7
|
||||
|
||||
lol how 'bout dat !! fcukdat; first time this seen in public outside MS ?? Waaa! I want one.
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#8
|
||||
|
||||
|
Quote:
but thats old one...gotta love themprivate tools now with added view memory region module Longboard...M$ no have the latest versions ![]()
__________________
Ade Gill Malwarebytes Researcher Last edited by fcukdat : May 15th, 2008 at 02:43 AM. |
|
#9
|
|||
|
|||
|
Guys, guys.. We are out of topic.
And fcukdat we are jealous of not having these private builds. We wish for an ultimate RkU version of course. But the problem remains.. RkU cannot return to simple mode from extended mode. Someone proposed to terminate with "sc delete" the service. As far I can understand the service rkhdrv40 is hidden !!!!!! Why is that? I can upload the log files after the BSOD for you to examine..... Cheers.. |
|
#10
|
||||
|
||||
|
Ok have you tried uninstalling RKU,rebooting and then reinstalling again.This usually resets settings back to default
![]()
__________________
Ade Gill Malwarebytes Researcher |
|
#11
|
|||
|
|||
|
fcukdat these shots look promising ...
i hope that same like with SI tools we get hands on new builds soon(tm) |
|
#12
|
|||
|
|||
|
Quote:
yeah! they are good news. I hope some builds will come out for the loyal fans out there! |
|
#13
|
||||
|
||||
|
While moving along with each new version when RKU was progressing along publicly and even now, i used AUTORUNS to delete the driver whatever version, since it was just there and not called on unless you engaged the application to run it, it more or less was just available untill called on instead of producing itself again.
EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★|
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11
¶Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|