InsaneKaos wrote:RR will show the infected one. But only after a reboot.
I can confirm this, prior to reboot:
STEALTH CODE
-------------------
System 0x82ee28b4 - Hidden Code
System 0x82ee2ac8 - Hidden Code [Driver: , IRP: IRP_MJ_CLEANUP]
etc
Also with occasional reference to *.tmp
After reboot:
STEALTH CODE
-------------------
System 0x833028b4 - Hidden Code
System 0x83302ac8 - Hidden Code [Driver: , IRP: IRP_MJ_CLEANUP]
etc
System 0x83302ac8 - Hidden Code [Driver: , IRP: IRP_MJ_WRITE]
System 0xf762b8ad - Modified Entry Point [Driver: Disk, Other Val: 0xf762c514]
CALLBACKS
-------------------
LoadImage 0x8330496e <unknown>
In this case infected driver is Disk.sys, but no mention of miniport port disk driver being associated with irp redirection.