Rootkit Scan and Daemon Tools

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Chewy
    Super Moderator
    • Nov 2003
    • 18971

    Rootkit Scan and Daemon Tools

    After over 2 years I am still removing crap

    GMER 1.0.15.14878 - http://www.gmer.net
    Rootkit scan 2009-03-10 00:47:24
    Windows 5.1.2600 Service Pack 3


    ---- System - GMER 1.0.15 ----

    SSDT 82524E98 ZwConnectPort

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

    AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

    Device \Driver\UlSata \Device\Scsi\UlSata1Port2Path0Target2Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\UlSata \Device\Scsi\UlSata1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\UlSata \Device\Scsi\UlSata1Port2Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@khjeh 0x51 0x80 0x63 0xC9 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@khjeh 0x51 0x80 0x63 0xC9 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4@khjeh 0x51 0x80 0x63 0xC9 ...
    Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@khjeh 0x51 0x80 0x63 0xC9 ...

    ---- EOF - GMER 1.0.15 ----
  • blutach
    Not a god of digital video
    • Oct 2004
    • 24627

    #2
    Dunno what you got against DT. I have used it for years without incident.

    Regards
    Les

    Essential progs - [PgcEdit] [VobBlanker] [MenuShrink] [IfoEdit] [Muxman] [DVD Remake Pro] [DVD Rebuilder] [BeSweet] [Media Player Classic] [DVDSubEdit] [ImgBurn]

    Media and Burning - [Golden Rules of Burning] [Media quality] [Fix your DMA] [Update your Firmware] [What's my Media ID Code?] [How to test your disc]
    [What's bitsetting?] [Burn dual layer disks safely] [Why not to burn with Ner0] [Interpret Ner0's burn errors] [Got bad playback?] [Burner/Media compatibility]

    Cool Techniques - [2COOL's guides] [Clean your DVD] [Join a flipper] [Split into 2 DVDs] [Save heaps of Mb] [How to mock strip] [Cool Insert Clips]

    Real useful info - [FAQ INDEX] [Compression explained] [Logical Remapping of Enabled Streams] [DVD-Replica] [Fantastic info on DVDs]


    You should only use genuine Verbatim or Taiyo Yuden media. Many thanks to www.pcx.com.au for their supply and great service.

    Explore the sites and the programs - there's a gold mine of information in them

    Don't forget to play the Digital Digest Quiz!!! (Click here)

    Comment

    • cynthia
      Super Moderatress
      • Jan 2004
      • 14278

      #3
      The Daemon Tools driver slowed my reading speed down.

      Comment

      • Chewy
        Super Moderator
        • Nov 2003
        • 18971

        #4
        Originally Posted by blutach
        Dunno what you got against DT. I have used it for years without incident.

        Regards
        I just installed it for testing to see if it interfered with burning programs, the uninstaller should remove the hidden drivers, StarForce Protection Synchronization Driver/Protection Technology

        I googled this for quite a while before I found the uninstaller and tied it to daemon tools

        For over a year my safe mode boots kept stalling on sptd

        Nothing personal Blu
        Last edited by Chewy; 11 Mar 2009, 01:00 AM.

        Comment

        • Abuilder
          Digital Video Enthusiast
          Digital Video Enthusiast
          • Oct 2006
          • 347

          #5
          Chewy
          So GMER didn't report demon tools as a rootkit? Or did it?
          They tried to Assimilate me and failed!

          Comment

          • Chewy
            Super Moderator
            • Nov 2003
            • 18971

            #6
            Gmer reports it as a hidden driver, I guess with layers of hiding

            Unlabeled, random named might indicate a rootkit

            My point was hidden drivers should be uninstalled

            Comment

            • blutach
              Not a god of digital video
              • Oct 2004
              • 24627

              #7
              In safe mode, windows telling you to press esc if you do not want to load SPTD.sys. So, press esc (or don't).

              Regards
              Les

              Essential progs - [PgcEdit] [VobBlanker] [MenuShrink] [IfoEdit] [Muxman] [DVD Remake Pro] [DVD Rebuilder] [BeSweet] [Media Player Classic] [DVDSubEdit] [ImgBurn]

              Media and Burning - [Golden Rules of Burning] [Media quality] [Fix your DMA] [Update your Firmware] [What's my Media ID Code?] [How to test your disc]
              [What's bitsetting?] [Burn dual layer disks safely] [Why not to burn with Ner0] [Interpret Ner0's burn errors] [Got bad playback?] [Burner/Media compatibility]

              Cool Techniques - [2COOL's guides] [Clean your DVD] [Join a flipper] [Split into 2 DVDs] [Save heaps of Mb] [How to mock strip] [Cool Insert Clips]

              Real useful info - [FAQ INDEX] [Compression explained] [Logical Remapping of Enabled Streams] [DVD-Replica] [Fantastic info on DVDs]


              You should only use genuine Verbatim or Taiyo Yuden media. Many thanks to www.pcx.com.au for their supply and great service.

              Explore the sites and the programs - there's a gold mine of information in them

              Don't forget to play the Digital Digest Quiz!!! (Click here)

              Comment

              • gonwk
                Lord of Digital Video
                Lord of Digital Video
                • Dec 2005
                • 1500

                #8
                Hi folks,

                I have Daemon Tools Lite on my laptop and when I run MBAM and SAS and Avira they don't see anything!!!

                Are you telling me that it might be a Sophisticated Trojan of some sort!?!?

                If so, I will have it uninstalled ... but I love the Program ... I can play my Games without asking for the darn 1st CD ... which is great when I am on travel ... so I am lugging 3 or 4 1st CD discs.

                Thanks,

                G!

                Comment

                • Chewy
                  Super Moderator
                  • Nov 2003
                  • 18971

                  #9
                  Keep using daemon, my gripe was at it leaving those rootkit like drivers after an uninstall.
                  Without those drivers it wouldn't do what you want it to.

                  I wonder what's happening with Vista64 bit and daemon and game protection?

                  Comment

                  • cynthia
                    Super Moderatress
                    • Jan 2004
                    • 14278

                    #10
                    Originally Posted by gonwk
                    Hi folks,
                    If so, I will have it uninstalled ... but I love the Program ... I can play my Games without asking for the darn 1st CD ... which is great when I am on travel ... so I am lugging 3 or 4 1st CD discs.
                    I replaced Daemon Tools with the free version of Virtual Clone Drive. No issues with that program.

                    Comment

                    • Abuilder
                      Digital Video Enthusiast
                      Digital Video Enthusiast
                      • Oct 2006
                      • 347

                      #11
                      Originally Posted by Chewy
                      I wonder what's happening with Vista64 bit and daemon and game protection?
                      Chewy
                      This is some of the Release notes from Version 4.30.0304.47
                      What's new:

                      - Added helper process for executing admin rights required operations under Vista with enabled UAC;
                      - Silent installation:
                      "/kfp " - mandatory;
                      "/email " - mandatory;
                      "/name " - optional;
                      - Grabber logging improvements;
                      WTF
                      They tried to Assimilate me and failed!

                      Comment

                      • gonwk
                        Lord of Digital Video
                        Lord of Digital Video
                        • Dec 2005
                        • 1500

                        #12
                        Originally Posted by Chewy
                        Keep using daemon, my gripe was at it leaving those rootkit like drivers after an uninstall.
                        Without those drivers it wouldn't do what you want it to.

                        I wonder what's happening with Vista64 bit and daemon and game protection?

                        http://blogs.msdn.com/windowsvistase...11/695993.aspx
                        Hi folks,

                        @ Chewy ... funny you should post this ... becuase my Unstopable Daemon Tools Lite 4.30.3 (DT) would not work yesterday when I tried to do what I was always able to do few weeks back Mount my CD1.iso and play the already installed game on my laptop. So may be the last update by Sneaky Microsoft (May Bill Gates eat S**t) crashed my DT.

                        Also, when I download DT from various sources it WILL NOT telll me that it is an "ADWARE" ... yet from Softpedia site it tells you that is an Adware. But when installing it I don't see anything (me anyway) ... and when I use it and I am online I don't see any funny pop-ups ... so

                        Q: So How is it an ADWARE then!?!?

                        @ Cynthia ... "Hi" ... Cynthia ... SlySoft VCD will not do what I wanted to do ... although it will give you a plain old Virtual Drive ... but it can NOT fool the system to play without my Original CD ... for that I need GameJackal ... which I could never figure out how to use during their Trial Period so I said the heck with it.

                        @ ABuilder ... Does DT Lite have those funny commands also ... and where did you find those "Silent" installation tags!?!? THX!

                        Oh well!

                        Thanks folks!

                        G!
                        Last edited by gonwk; 15 Mar 2009, 05:05 AM.

                        Comment

                        • Abuilder
                          Digital Video Enthusiast
                          Digital Video Enthusiast
                          • Oct 2006
                          • 347

                          #13
                          gonwk
                          It looks like the lite version has the "silent" install switch also.


                          They tried to Assimilate me and failed!

                          Comment

                          • gonwk
                            Lord of Digital Video
                            Lord of Digital Video
                            • Dec 2005
                            • 1500

                            #14
                            Originally Posted by Abuilder
                            gonwk
                            It looks like the lite version has the "silent" install switch also.


                            Hi ABuilder,

                            Well I unistalled it and it is gone ... I think ... that is if it has NOT left behind some goodies on my laptop.

                            Q: How can I make sure it is totally wiped from my Hard Drive? Easiest way!?!?

                            Thanks,

                            G!

                            Comment

                            • Abuilder
                              Digital Video Enthusiast
                              Digital Video Enthusiast
                              • Oct 2006
                              • 347

                              #15
                              gonwk
                              Run gmer the utility that Chewy listed on post 1.
                              They tried to Assimilate me and failed!

                              Comment

                              Working...