See the attachment
Attachments
(29.59 KiB) Downloaded 134 times
A forum for reverse engineering, OS internals and malware analysis
kmd wrote:me again 8-) i'm plan to test this rootkit on x64 windows, should i take latest win version or try on smth like windows 7?As far as I remember this trash using embedded in the dropper bcdedit to set boot option TESTSIGNING with forced reboot next. Since Windows 8+ with SecureBoot enabled this will no longer work. Take out-dated OS like vista/7.
WinDefend BITS wuauserv KSLDriver.sys Microsoft Malware Protection KProcessHacker VirusBuster Ltd Beijing Jiangmin SUNBELT SOFTWARE Sunbelt Software K7 Computing Immunet Corporation Beijing Rising G DATA Software Quick Heal Technologies Comodo Security Solutions Sophos Plc Anti-Virus CJSC Returnil Software NovaShield Inc antimalware BullGuard Ltd Check Point Software Technologies Ltd Panda Software International Kaspersky Lab FRISK Software International Ltd ESET, spol. s r.o. Doctor Web Ltd Comodo Inc BitDefender SRL BITDEFENDER LLC Avira GmbH GRISOFT, s.r.o. PC Tools ALWIL Software Agnitum Ltd kprocesshacker.sys Vba32dNT.sys v3engine.sys AntiyFW.sys AhnRec2k.sys ahnflt2k.sys KmxStart.sys KmxAMVet.sys KmxAMRT.sys KmxAgent.sys ssfmonm.sys rvsmon.sys lbd.sys klif.sys kldtool.sys kldlinf.sys kldback.sys klbg.sys avgntflt.sys MiniIcpt.sys PktIcpt.sys HookCentre.sys aswmonflt.sys AVC3.SYS bdfm.sys bdfsfltr.sys AVCKF.SYS issfltr.sys nvcmflt.sys K7Sentry.sys cmdguard.sys mfehidk.sys mfencoas.sys kmkuflt.sys catflt.sys ggc.sys PZDrvXP.sys antispyfilter.sys ZxFsFilt.sys ikfilesec.sys PCTCore.sys PCTCore64.sys fsgk.sys vradfil2.sys savant.sys sascan.sys strapvista64.sys strapvista.sys ssvhook.sys snscore.sys HookSys.sys Rtw.sys cwdriver.sys fpav_rtp.sys fsfilter.sys fildds.sys SCFltr.sys UFDFilter.sys STKrnl64.sys Spiderg3.sys dwprot.sys EstRkr.sys EstRkmon.sys pwipf6.sys OADevice.sys savonaccess.sys fortishield.sys fortirmon.sys fortimon2.sys avgmfrs.sys avgmfi64.sys avgmfx64.sys avgmfx86.sys pervac.sys THFilter.sys issregistry.sys nregsec.sys nprosec.sys shldflt.sys NanoAVMF.sys AntiLeakFilter.sys NxFsMon.sys vchle.sys vcreg.sys vcdriv.sys V3Flu2k.sys OMFltLh.sys AszFltNt.sys AhnRghLh.sys ArfMonNt.sys V3IftmNt.sys V3Ift2k.sys V3MifiNt.sys V3Flt2k.sys ATamptNt.sys SMDrvNt.sys tkfsavxp64.sys tkfsavxp.sys tkfsft64.sys tkfsft.sys BdFileSpy.sys NovaShield.sys eeyehv64.sys eeyehv.sys SegF.sys csaav.sys AshAvScan.sys PLGFltr.sys avmf.sys ino_fltr.sys caavFltr.sys amm6460.sys amm8660.sys amfsm.sys PSINFILE.SYS PSINPROC.SYS mpFilter.sys drivesentryfilterdriver2lite.sys vcMFilter.sys tmpreflt.sys tmevtmgr.sys SDActMon.sys MaxProtector.sys eamonm.sys mbam.sys a2acc64.sys a2acc.sys a2gffi64.sys a2gffx64.sys a2gffx86.sys SRTSP64.SYS SRTSPIT.sys SRTSP.sys eraser.sys eeCtrl.sys ZwFlushBuffersFile \??\PCI#VEN_25AF&DEV_0209&SUBSYS_070455AF&REV_00 \Device\NTPNP_PCI2F81 *%08x%08x PAGE Boot Bus Extender Group \SystemRoot\System32\Drivers\ ImagePath Tag Start Type ErrorControl DisplayName %s\Services\%S ControlSet \REGISTRY\MACHINE\SYSTEM \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\%S \SystemRoot\System32\Drivers\%S.sys %x%x services.exe DB1 20101 ObRegisterCallbacks \SystemRoot\ \??\ \SystemRoot\System32\Drivers\%s.sys System32\ * DB5 DB6 \SystemRoot\System32\winload.exe \bootmgr \boot.ini \ntldr \SystemRoot\System32\ *.dll \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services \SystemRoot\System32\ntdll.dll win32k.sysInstead of "\??\NtSecureSys" and "\Device\NtSecureSys" it's now using "\??\PCI#VEN_25AF&DEV_0209&SUBSYS_070455AF&REV_00" and "\Device\NTPNP_PCI2F81".