PDA

View Full Version : Rootkit Scan Problems



TwentyThou
06-19-2007, 11:50 AM
I have read other similar threads on this general hanging/crashing problem associated with Rootkit Scanner, but rather than piggyback on those threads I'll start another.

I installed Cyberhawk v2.0.4.34 on two WinXP Home computers, and one is functioning fine and the other is hanging/crashing on both Quick and Full Rootkit Scans.

On the crashy machine, the file counter on the Quick scan always stops at 12 files, although the progress graph continues to move. After 5 minutes I stop it, because nothing is scanning. This is easily replicated.

The file counter on the Full scan stops around 28,523 files. Once it got there in a matter of 15 seconds, another time it took 3 1/2 minutes to get to that point.

Again, the progress graph continues to move, but the hang that occurs here with Full scan is quite troublesome. Neither Pause nor Stop buttons do anything when I click on them. I can move the mouse cursor around the desktop but I can't click on anything. Task manager won't open. Finally a forced shutdown reboot is needed.

I tried repair via the Add/Remove program menu, but nothing improved.

I uninstalled and reinstalled and got the same trouble.

On each install, I shut down resident AVs and security programs.

Everything else appears to be fine on the hang/crash installation. The trouble is all Rootkit Scanner. Once I use the scanner, if I am able to close it and go on to other tasks (as is possible with Quick Scans), everything gets very sluggish. I mean very sluggish, and I end up having to reboot.

As stated at the top, the other computer is handling Cyberhawk just fine. Rootkit Scanner runs perfectly, both Quick and Full scans.

The main difference between the two systems is antivirus programs. The system that is crashy has Norton AntiVirus 2005. The one that is behaving fine has avast! 4 Home Edition.

Here are the other resident security programs I am running in common on both machines.

BOClean 4.22.002
ZoneAlarm Pro v7.0.337.000
Spybot Resident "SD Helper" (but not Resident "Tea Timer")

As another poster said, I too can live without the Rootkit Scanner feature for now. If other features were messed up, I'd be very discouraged and the software would already be off my computers. But I like everything else enough to justify hanging around (no pun intended) to see how this gets worked out.

djames
06-19-2007, 03:10 PM
Thanks for you input, and the details. I will attempt to re-create this so we can debug it.

TwentyThou
06-19-2007, 08:27 PM
I'm wondering if i should open a support ticket?

Without doing anything with the Rootkit Scanner feature, Cyberhawk "encountered a problem and needs to close".

I had just opened HijackThis v1.99.1 to run a scan to see what was present on my system, and Cyberhawk Service produced an error report. I was unable to reproduce this error.

"Cyberhawk Service has encountered a problem and needs to close.

szAppName : CHService.exe szAppVer : 1.7.5.16 szModName : msvcr80.dll
szModVer : 8.0.50727.762 offset : 0004ff28

Error Report Contents
The following files will be included in this error report:

C:\DOCUME~1\name\LOCALS~1\Temp\WERdb87.dir00\CHSer vice.exe.mdmp
C:\DOCUME~1\name\LOCALS~1\Temp\WERdb87.dir00\appco mpat.txt"

Is this forum the appropriate place to attempt to diagnose this problem, or should I open a ticket?

djames
06-19-2007, 08:30 PM
I would like the dmp file if you could send it to me. I will PM the e-mail address.

Thanks

TwentyThou
06-24-2007, 06:22 AM
Way too many crashes and hangs and instability for me to stick with Cyberhawk any longer.

I opened a support ticket two or three days ago, and got very good service from Armando, but nothing was resolved.

I would love to have Cyberhawk be a part of my security set up, but I can't get it to work effectively. I have removed it and also removed some other programs that I felt were either obsolete or no longer worthy. Perhaps some of them were conflicting, who knows?

I will try Cyberhawk again before long. Armando told me that another update will be pushed out with some stuff fixed, and I believe the MailWasher pro false positive has been or will be corrected.

Just wanted to post back and thank the Moderator, djames, for the help and advice, and to contribute my 2 cents to this effort.

Regards to all.

djames
06-25-2007, 05:02 AM
I appreciate your patients with us. It is hard to create a product that will work perfectly with every 3rd party software out there. But we are trying and each release we believe we will be better and better.

TwentyThou
06-25-2007, 07:54 PM
I'll keep my eye out for new version releases.

elmisti
07-19-2007, 04:38 PM
I'm using 2.0.4.34 CH pro
and have had root-kit scan (full) hang-ups too...:eek:

though I suspect it was caused by another AV/spy/file scan running or starting while CH was scaning.
I read somewhere that it's best not to do much else with your computer while root-kit scans are running, aparently this is good advice.:o