Author Topic: Antirootkit  (Read 7118 times)

0 Members and 1 Guest are viewing this topic.

July 09, 2014, 11:45:47 AM

steddye

  • Guest
Antirootkit
« on: July 09, 2014, 11:45:47 AM »
Hello just checked the pc , I did other scan before but this is the first time i see the antorootkit log with so many entries

RogueKiller V9.2.0.0 (x64) [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : foca [Admin rights]
Mode : Scan -- Date : 07/09/2014  11:32:46

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 8 ¤¤¤
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | EnableLUA : 0  -> Trovato
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | EnableLUA : 0  -> Trovato
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0  -> Trovato
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0  -> Trovato
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2558236547-444649337-1807880188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> Trovato
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2558236547-444649337-1807880188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> Trovato
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2558236547-444649337-1807880188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> Trovato
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2558236547-444649337-1807880188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> Trovato

¤¤¤ Le attività pianificate : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost

¤¤¤ Antirootkit : 5 (Driver: LOADED) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP3T0L0-3 : \Driver\iaStorF @ Unknown (\SystemRoot\System32\Drivers\mup.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP2T0L0-2 : \Driver\iaStorF @ Unknown (\SystemRoot\System32\Drivers\mup.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP1T0L0-1 : \Driver\iaStorF @ Unknown (\SystemRoot\System32\Drivers\mup.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP0T0L0-0 : \Driver\iaStorF @ Unknown (\SystemRoot\System32\Drivers\mup.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\system32\CI.dll)

¤¤¤ I browser Web : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD1003FZEX-00MK2A0 ATA Device +++++
--- User ---
[MBR] adcc5058a2b3ffdb25ff293490119835
[BSP] 690b767b6d8bc467a0a947e1263cffed : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Maxtor 6H500F0 ATA Device +++++
--- User ---
[MBR] 9f931b9192b6a19b905787b8e88450ae
[BSP] cf0b651b0fab45c6ab8f1d8c9f955908 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476939 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: ADATA SP900 ATA Device +++++
--- User ---
[MBR] 2b9f2e12b490e0005987573fb446e66e
[BSP] c08dc13d915e62ae570e0b6e7e1dc92a : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 122102 MB
User = LL1 ... OK
User = LL2 ... OK

something to worry about ? 

Thanks

Reply #1July 10, 2014, 10:12:22 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Antirootkit
« Reply #1 on: July 10, 2014, 10:12:22 AM »
Hello
It looks like mup.sys is microsoft file.
But I can't find anything for CI.dll, can you please dig into the system32 folder to inspect the file? (publisher, maybe a scan on virus total)

Reply #2July 10, 2014, 11:20:05 AM

steddye

  • Guest
Re: Antirootkit
« Reply #2 on: July 10, 2014, 11:20:05 AM »
ci.dll Microsoft corporation version 61.7601.1714

scanned on virus total 0/54

On virus total using the button  "choose the file" and browsing to the system32 folder, the file is not there but if I browse there from desktop,computer,windows,system32 folder i find it and many others , so I copied the file to  the desktop and then scanned.

Reply #3July 10, 2014, 01:49:50 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Antirootkit
« Reply #3 on: July 10, 2014, 01:49:50 PM »
That's a bug with your web browser, file redirection on 64 bits systems.
If it's microsoft file, then it shall be whitelisted too. :)

Reply #4July 10, 2014, 02:29:23 PM

steddye

  • Guest
Re: Antirootkit
« Reply #4 on: July 10, 2014, 02:29:23 PM »
good ,thanks again