Jump to content











Photo
- - - - -

VIPRERescue


  • Please log in to reply
15 replies to this topic

#1 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 15 August 2011 - 04:46 PM

Posted Image

File Name: VIPRERescue
File Submitter: homes32
File Submitted: 15 Aug 2011
File Updated: 29 Oct 2012
File Category: App scripts

The VIPRE Rescue Program is a command-line utility that will scan and clean an infected computer that is so infected that programs cannot be easily run. Scanning features rootkit detection, deep scan, and can log events.

I have written a lightweight portable GUI for handling scanning and downloading of updates. Please take note that this is a very large program (200+ MB). Pay special attention to the warnings in the script interface.

Click here to download this file

#2 neyrial

neyrial
  • Members
  • 1 posts
  •  
    France

Posted 11 April 2012 - 03:52 PM

it didn t work for me with default options

#3 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 16 April 2012 - 01:24 AM

you need to be more specific when reporting problems or I may have no Idea what you are talking about. There is a global shortage of crystal balls here on reboot and the one we do share between developers has been broken for years now! :)

it looks like sunbelt changed their download URL's again. I'll see if I can get it sorted out in the next day or so.

regards,
Homes32
  • Brito likes this

#4 linuxbaby

linuxbaby

    Frequent Member

  • .script developer
  • 139 posts
  •  
    Germany

Posted 16 April 2012 - 07:04 PM

The Download is not available but thanks a lot for sharing the script. :good:




404 Not Found

The server can not find the requested page homes32.winbuilder.net/scripts/VIPRERescue.script (port 80)

Please forward this error screen to homes32.winbuilder.net's [email="nunobrito.azores@gmail.com?subject=Error%20message%20[404]%20404%20Not%20Found%20for%20homes32.winbuilder.net/scripts/VIPRERescue.script%20port%2080%20on%20Monday,%2016-Apr-2012%2021:05:19%20CEST"] WebMaster[/email].



#5 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 16 April 2012 - 07:46 PM

my subdomain is in the process of being migrated over to the new server/system.
All scripts will be restored once this is complete.

#6 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 24 April 2012 - 08:45 PM

download issues fixed! v5 on server.

#7 Mikka

Mikka

    Frequent Member

  • Developer
  • 175 posts
  •  
    Germany

Posted 07 July 2012 - 12:43 PM

download issues fixed! v5 on server.

I checked that version, but VRL.exe /GetWBDownloadURL results in the error

VIPRE Rescue Launcher
---------------------------
Failed parsing html!
---------------------------
[ OK ]

:(

#8 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 16 July 2012 - 03:44 PM

That usually means they changed the download page. I'll look later tonight when I have a real computer


Edit: Fixed - v6 ready for download.

#9 Etatheta

Etatheta
  • Members
  • 4 posts
  •  
    United States

Posted 17 October 2012 - 04:24 PM

It broke again. "failed parsing html! The download URL could not be found" Then at least for me it fails with Unable to Unmount WIM files when it tries to install it but i assume that goes along with the unable to get the download.

#10 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 26 October 2012 - 03:04 PM

It broke again. "failed parsing html! The download URL could not be found" Then at least for me it fails with Unable to Unmount WIM files when it tries to install it but i assume that goes along with the unable to get the download.

looks like they changed the webpage again. I'll post a fix this weekend.
regards,
Homes32

#11 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 29 October 2012 - 02:21 PM

fixed. v7

#12 Etatheta

Etatheta
  • Members
  • 4 posts
  •  
    United States

Posted 31 October 2012 - 03:30 PM

Now when im building the system i get the following stop error on vipre

RegWrite - Type: [0x4] Section [HKLMwb-hiveControlSet001ServicesSBRE] Key [Type]: 1

any ideas?

#13 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 31 October 2012 - 06:06 PM

Now when im building the system i get the following stop error on vipre

RegWrite - Type: [0x4] Section [HKLMwb-hiveControlSet001ServicesSBRE] Key [Type]: 1

any ideas?

you need to build from the big blue play button not the small green play button in the script interface. otherwise the registry hives don't get mounted and all regwrites will fail.

#14 Etatheta

Etatheta
  • Members
  • 4 posts
  •  
    United States

Posted 31 October 2012 - 07:41 PM

I am doing a complete build using "the big blue play button" still get that error

#15 homes32

homes32

    Gold Member

  • .script developer
  • 1035 posts
  • Location:Minnesota
  •  
    United States

Posted 31 October 2012 - 08:19 PM

I am doing a complete build using "the big blue play button" still get that error

then you will need to post your full build log so we can get an idea what is going on.

#16 Mikka

Mikka

    Frequent Member

  • Developer
  • 175 posts
  •  
    Germany

Posted 14 January 2013 - 05:56 PM

Now when im building the system i get the following stop error on vipre

RegWrite - Type: [0x4] Section [HKLMwb-hiveControlSet001ServicesSBRE] Key [Type]: 1

any ideas?

 

Just a guess: Change the lines 62 - 66 to

RegWrite,HKLM,0x4,"Tmp_Software\ControlSet001\Services\SBRE","Type",1
RegWrite,HKLM,0x4,"Tmp_Software\ControlSet001\Services\SBRE","ErrorControl",1
RegWrite,HKLM,0x4,"Tmp_Software\ControlSet001\Services\SBRE","Start",3
RegWrite,HKLM,0x2,"Tmp_Software\ControlSet001\Services\SBRE","ImagePath","system32\drivers\SBREdrv.sys"
RegWrite,HKLM,0x2,"Tmp_Software\ControlSet001\Services\SBRE","Group","Base"

and see if that helps.

 

@homes32:

I did tests with a new up to date desktop system here. Unfortunately there were several errors.

 

#1:

Whenever I launch the app like this

1st.png

this will happen:

2nd.png

Simple workaround: Not choosing this very option. :D

 

#2:

If I choose Scan for Rootkits, VIPRERescue runs on x:\ (ramdisk) and, after 7 seconds or so a BSOD shows up.

The usual stuff there: STOP: 0x00000024 ... Ntfs.sys - Address 8BE28D1B base at 8BE13000, and so forth.

 

#2's a bummer. Any idea what might cause the BSOD?

 

 

Addendum:

I noticed that BSOD (always Ntfs.sys) also occurs running McAfee Stinger (executable out-of-box) just 2 seconds after the first "Scanning for rootkits" line is logged.
AVZ Toolkit and Emsisoft Emergency Kit both run without problems (i.e. no BSOD yet).

 

McAfee Stinger runs without RunScanner, as Emsisoft Emergency Kit does.

AVZ Toolkit and VIPRERescue rely on RunScanner (latest version 1.0.0.26).

So my first idea ("some RunScanner quirks") was wrong...

 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users