05-28-2009 09:10 PM
Stealth part2
Object: Hidden Code [Driver: , IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86a021f8 Size: -
Object: Hidden Code [Driver: , IRP_MJ_POWER]
Process: System Address: 0x86a021f8 Size: -
Object: Hidden Code [Driver: , IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86a021f8 Size: -
Object: Hidden Code [Driver: , IRP_MJ_PNP]
Process: System Address: 0x86a021f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_CREATE]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_CLOSE]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_READ]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_WRITE]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_POWER]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: USBSTOR扎〳Ѕ䍃䡤, IRP_MJ_PNP]
Process: System Address: 0x880811f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_CREATE]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_CLOSE]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_POWER]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: usbuhcilj䅓䍓Ѝ䵆汳`돁돁, IRP_MJ_PNP]
Process: System Address: 0x86a4c1f8 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_CREATE]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_READ]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_WRITE]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_POWER]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: cdrom, IRP_MJ_PNP]
Process: System Address: 0x86ba4500 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_CREATE]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_CLOSE]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_CLEANUP]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: Smb, IRP_MJ_PNP]
Process: System Address: 0x87ff91f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_CREATE]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_CLOSE]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_CLEANUP]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: netbt
က, IRP_MJ_PNP]
Process: System Address: 0x880511f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_CREATE]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_CLOSE]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_POWER]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: iScsiPrt瑎牦掸溰觤, IRP_MJ_PNP]
Process: System Address: 0x86ba01f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x8520c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x869fb1f8 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLOSE]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_READ]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_WRITE]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_EA]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLEANUP]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_POWER]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_PNP]
Process: System Address: 0x86a0f500 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_CREATE]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_CLOSE]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_READ]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_WRITE]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_CLEANUP]
Process: System Address: 0x89b8f1f8 Size: -
Object: Hidden Code [Driver: cdfs慖І癅, IRP_MJ_PNP]
Process: System Address: 0x89b8f1f8 Size: -
05-28-2009 09:11 PM
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/05/28 21:31
Program Version: Version 1.2.3.0
Windows Version: Windows Vista SP1
==================================================
Hidden Services
-------------------
Service Name: gxvxcserv.sys
Image Path: C:\Windows\system32\drivers\gxvxcvxmuiisiusdatjuqf
05-28-2009 09:47 PM - edited 05-28-2009 09:53 PM
Ok
None of the .dll files belonging to it show but hopefully this will be enough to break it.
Now I will post the script further down, don't use the script on the "Avenger" thread as it doesn't contain your, but does contain theirs
1. Go to http://community.norton.com/norton/board/message?b
Read that post on using "Avenger" boxes ticked etc,
For #3 on that post instead use this script
3. In the "Input script here:" copy and paste the script between the lines
05-30-2009 05:56 PM
05-30-2009 07:22 PM
05-30-2009 07:31 PM - edited 05-30-2009 07:33 PM
Hi Quads -
Yes, good work! I'm glad that it didn't have to come to a re-image.
Perhaps you could share the technical details with us on exactly how this correction came about.
Was it a rootkit?
TIA ![]()
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
05-30-2009 07:35 PM
Compumind:
This is a little something that Quads put together in his secret underground laboratory. I suspect none of us would understand the technical details anyway. If we did, he might have to.....you know.![]()
05-30-2009 07:54 PM
matyellott wrote:
Quads and others you peoplpe are tru pros, scan in running not and the trojan had already been removed.. thanks so much!!
Can I ask, Please can you post the Avenger log after that appeared after Avenger did it's thing??
Quads
05-31-2009 10:24 AM
05-31-2009 01:55 PM
Hi
It should be in this location "C:\avenger.txt"
I only had it remove the file on your PC that we knew and hopefully it would be enough to break the Rootkit from working, allowing MBAM, SAS, Norton etc being able to run and mop up anything else.
Quads
