CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Help with darkspy

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sat Sep 30, 2006 7:51 pm    Post subject: Help with darkspy
Reply with quote

Hi, I don't know if you guys can or will help me with this problem.

Lately I have problems getting darkspy to run.

I click on the file, an hour glass appears then disappears. i look at the task manager and it showing darkspy running (at 99% cpu but with no slow down) but i can't find the darkspy interface at all?

Please help! Maybe i need to remove the driver or something from a failed install...

I didn't change my security setup so I know that's not causing the problem. and i shut everything down anyway, from services to drivers that might cause troubles...

Please help experts...

There's only a possiblity that i'm infected and it is stopping darkspy from working properly....

Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Oct 01, 2006 10:01 am    Post subject:
Reply with quote

Hi,
Which version of DarkSpy you have?


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sun Oct 01, 2006 4:56 pm    Post subject:
Reply with quote

1.0.5 is there a newer version?

Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Oct 01, 2006 5:25 pm    Post subject:
Reply with quote

Nope. 1.0.5 is the latest version. Please try an older version of DarkSpy available here:
http://www.fyyre.net/~cardmagic/index_en.html


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sun Oct 01, 2006 5:36 pm    Post subject:
Reply with quote

It looks like I might really have a rootkit problem! Sad

When I ran rootkit unhooker (yeah I know you guys frown on it, but I backup and restore every time I try it),
it says "Rootkit Unhooker has detected parasite inside itself!"

It didn't used to do so!

Anyway it is able to remove the parasite for a while to start, but I don't see anything bad in it.

However I don't really understand how to use such things (much) so I probably missed something

I think the rootkit is stopping darkspy from starting at all! Icesword and Gmer works okay though both don't find anything (or maybe I missed something).

Please help!!!!

I will post a HJT log if you want, but I posted one recently (to fix another recent problem that turned out to be a False positive) and they didn't find anything.

I'm hoping this one to be a FP too maybe the "parasite" detected is some security program, but the fact Darkspy has problems starting is very suspicious!!

Back to top
View users profile Send private message
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Sun Oct 01, 2006 5:43 pm    Post subject:
Reply with quote

I try 1.0.3 I get an error Sorry can't support multiple cpu , please wait for public version or something like that!!!

Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Oct 02, 2006 2:29 pm    Post subject:
Reply with quote

Hi,
Can you post RootkitRevealer and GMER logs?
Download GMER ZIP file and extract it to a folder. Run GMER.exe and go to "Rootkit" tab. Here, click "Scan" button and allow the scan to complete. After the scan, copy the results and please post it back here.
Note:- Do NOT select the "Show All" option while scanning.

Next, download Rootkit Revealer (link is at the very bottom of the page)


  • Unzip it to your desktop.
  • Open the rootkitrevealer folder and double-click rootkitrevealer.exe
  • Click the Scan button (bottom right)
  • It may take a while to scan (don't do anything while it's running)
  • When it's done, go up to File > Save. Choose to save it to your desktop.
  • Open rootkitrevealer.txt on your desktop and copy the entire contents and paste them here.

** NOTEBefore performing a scan it is recommended to do the following.
1. Physically unplug the cable from the PC to the internet connection.
2. Close down All Scheduling/Updating + Running Background tasks etc.
3. Launch and run the program.
4. While it is scanning DO NOT use your computer at ALL until the scan has been completed.
5. Save your Log File, and then Enable those things you closed down, or Reboot, and ONLY then Reconnect to the Internet.


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Wed Oct 04, 2006 4:39 pm    Post subject:
Reply with quote

Never mind I got it to work.

And the whole rootkit unhooker warning was due to another security program that I thought I neutered, but it respawned. Once I killed it (for sure) , no warning occurs..

Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Wed Oct 04, 2006 5:55 pm    Post subject:
Reply with quote

Hi,
Glad to hear that everything's working fine Thumbs Up


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer