A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #2633  by 4everyone
 Fri Sep 03, 2010 11:31 pm
Hi all,

I have a Quick Question on Rootkit Unhooker.

As nullptr explained, the below setting change makes the RKU to run in safe mode.

Setup > Settings > use "Extended Mode".......reboot.

Question: If a System is not booting in to Normal mode & boots in safe mode alone, is there any other way to make use of RKU directly in Safemode ?

Guess NO is the Answer. But, would like to hear it from the Authors or Experts. :)

Thanks All :)
 #2634  by EP_X0FF
 Sat Sep 04, 2010 1:30 am
The answer is Yes.

You need to run Rootkit Unhooker with console.

Add "-console" (no quotes) to rku lnk path. If all done properly it will show you console window at start.
Type "forcesafemode" (no quotes) in console, press ENTER, close it by command "exit" (ENTER), reboot Windows. It should now be able to work in Safe Mode, however files scan will be unavailable because of absence of Service Control Manager.

There is a small bug with "check" command, never mind it output. Will be fixed in next update (presumable October).