From: Ǝиçεl on

IceSword
http://www.antirootkit.com/software/IceSword.htm
-=-



"Mingo" wrote:

>
> "FromTheRafters" <erratic @nomail.afraid.org> ¼¶¼g©ó¶l¥ó·s»D:ebjIOhzkKHA.2132(a)TK2MSFTNGP05.phx.gbl...
> | "Mingo" <sly_007_2007_remove_(a)yahoo.com.remove> wrote in message
> | news:uosfJbzkKHA.1536(a)TK2MSFTNGP06.phx.gbl...
> | > Hello
> | > I'm using Win xp sp3 with 2g Ram CPU2.8G. After a period of time
> | > working
> | > with MS office 2007, office will pop up a notice telling me that my pc
> | > is
> | > running low on memory (But I only have Words open). I ran Malwarebytes
> | > followed with NOD32 and didn't find anything. I downloaded Gmer and
> | > found 2
> | > hidden files. My problem is when I run gmer, my pc slowly run out of
> | > memory
> | > and after 30 minutes, every mouse actions lags and my pc response
> | > extrimely
> | > slow and I can't finish run gmer before my pc hangs.
> | >
> | > I can't get into safe mode. My pc will stop at
> | > multi......partition(2)\system32\drivers\agpcpq.sys
> | >
> | > My pc normally run ok and every apps i open works fine. But when i
> | > start
> | > scan with gmer, that's where my problem start.
> | > Is there any other tools beside GMER?
> |
> | Sure, you may have just used one.
> |
> | http://www.eset.com/onlinescan/scanner_help.php?page=faq
> |
> |
>
>
> Thank you .. I alrealy have ESET smart security 4.0 installed on the pc. But
> I was wondering if there's any other tools similar to gmer.
> I'm sure ESET is not suitable for detect rootkits.
>
>
>
> .
>
From: Mingo on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> ���g��l��s�D:%23IkaEu3kKHA.1652(a)TK2MSFTNGP05.phx.gbl...
| From: "Mingo" <sly_007_2007_remove_(a)yahoo.com.remove>
|
|
|
|
|| Thank you .. I alrealy have ESET smart security 4.0 installed on the pc.
But
|| I was wondering if there's any other tools similar to gmer.
|| I'm sure ESET is not suitable for detect rootkits.
|
| Why do you think you need to run an anti RootKit utility in the first
place ?
|
| --

Few days ago my pc pop a notice saying my memory is not enough when i try to
save a word document. I closed all apps and try to save again and same
notice shows. I reset my pc and every thing when back to normal. I
downloaded malwarebytes; run a scan and an message show error 731 (0,6) it
closeditseft by runing out of stack. So I download Gmer and found 2 hidden
items by just opening gmer. I couldn't delete the 2 items becuase the
options was in grey. So i click on scan and that's when i notice my pc
getting slower and slower. That's when i assume it was a rootkit. I
restarted my pc and try gmer again, but same result. Do you think it's a
hardware problem instead? Should I remove one memory stick out?



From: Mingo on

"FromTheRafters" <erratic @nomail.afraid.org> ���g��l��s�D:%23lzfT$4kKHA.6096(a)TK2MSFTNGP02.phx.gbl...
| "Mingo" <sly_007_2007_remove_(a)yahoo.com.remove> wrote in message
| news:%23cSgoN3kKHA.2188(a)TK2MSFTNGP04.phx.gbl...
| >
| > "FromTheRafters" <erratic @nomail.afraid.org>
| > ���g��l��s�D:ebjIOhzkKHA.2132(a)TK2MSFTNGP05.phx.gbl...
| > | "Mingo" <sly_007_2007_remove_(a)yahoo.com.remove> wrote in message
| > | news:uosfJbzkKHA.1536(a)TK2MSFTNGP06.phx.gbl...
| > | > Hello
| > | > I'm using Win xp sp3 with 2g Ram CPU2.8G. After a period of time
| > | > working
| > | > with MS office 2007, office will pop up a notice telling me that
| > my pc
| > | > is
| > | > running low on memory (But I only have Words open). I ran
| > Malwarebytes
| > | > followed with NOD32 and didn't find anything. I downloaded Gmer
| > and
| > | > found 2
| > | > hidden files. My problem is when I run gmer, my pc slowly run out
| > of
| > | > memory
| > | > and after 30 minutes, every mouse actions lags and my pc response
| > | > extrimely
| > | > slow and I can't finish run gmer before my pc hangs.
| > | >
| > | > I can't get into safe mode. My pc will stop at
| > | > multi......partition(2)\system32\drivers\agpcpq.sys
| > | >
| > | > My pc normally run ok and every apps i open works fine. But when i
| > | > start
| > | > scan with gmer, that's where my problem start.
| > | > Is there any other tools beside GMER?
| > |
| > | Sure, you may have just used one.
| > |
| > | http://www.eset.com/onlinescan/scanner_help.php?page=faq
| > |
| > |
| >
| >
| > Thank you .. I alrealy have ESET smart security 4.0 installed on the
| > pc. But
| > I was wondering if there's any other tools similar to gmer.
| > I'm sure ESET is not suitable for detect rootkits.
|
| From the link I provided:
|
| "Does ESET Online Scanner include anti-rootkit technology?
| Yes, ESET Online Scanner now includes anti-stealth - ESET�s well known
| anti-rootkit technology used also in ESET Smart Security and ESET NOD32
| Antivirus. To obtain a full feature 30-day trial version of these
| products please click here.


I already have ESET smart security 4.0 on my pc. It must be better than ESET
Online Scanner.. is it??





From: Mingo on

"??c�`l" <l(a)discussions.microsoft.com> ���g��l��s�D:4B1C29B8-E2B1-4EDA-AC34-7402BE9BB98B(a)microsoft.com...
|
| IceSword
| http://www.antirootkit.com/software/IceSword.htm
| -=-
|
|


Thank you. I will try it..



From: David H. Lipman on
From: "Mingo" <sly_007_2007_remove_(a)yahoo.com.remove>


|| --

| Few days ago my pc pop a notice saying my memory is not enough when i try to
| save a word document. I closed all apps and try to save again and same
| notice shows. I reset my pc and every thing when back to normal. I
| downloaded malwarebytes; run a scan and an message show error 731 (0,6) it
| closeditseft by runing out of stack. So I download Gmer and found 2 hidden
| items by just opening gmer. I couldn't delete the 2 items becuase the
| options was in grey. So i click on scan and that's when i notice my pc
| getting slower and slower. That's when i assume it was a rootkit. I
| restarted my pc and try gmer again, but same result. Do you think it's a
| hardware problem instead? Should I remove one memory stick out?

Mingo:

How much physical RAM ? You may need to add more RAM to the system.

Please provide a log snippet showing what Gmer found in those 2 hidden items.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp