Security Basics mailing list archives

Applications abruptly terminating in Windows XP / Rootkit Revealer


From: forposts () aol com
Date: 11 May 2006 22:43:55 -0000

Hello everyone,

I am trying to determine the cause of abrupt termination of applications in  
Windows XP Professional.  I am honestly wondering if I am just suffering  from 
low memory or too many apps running at once rather than having malware or a  
malicious software or rootkit installed, but then again, I want to be  safe.

I did run SysInternals Rootkit Revealer  (RKR); it actually came  up with 
about 170 problems after a scan.  I did actually try to save the  output to a 
file so that I could digest the significance of all this, but when I  tried to do 
so, RKR abruptly terminated.

Some of you are probably saying: "Flatten the system and rebuild!" but  
here's the rub: I think the RKR output is wrong!

You are admonished "For best results exit all applications and keep the  
system otherwise idle during the RootkitRevealer scanning process."  

My questions:  If you have a lot of stuff running in the system tray,  how 
can you keep the system idle?  Can I disable startup items with  MSCONFIG and 
expect a reliable result from RKR?  Can anyone point me to  good data related to 
how to use RKR?

Comments welcomed.  Thanks for your help.

Mike


Current thread: