CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]spyr.sys - 4th on loadorder and nowhere to be found

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
fiepluqoufri

Cadet
Cadet


Joined: Jun 11, 2008
Posts: 3
Location: EU

PostPosted: Wed Jun 11, 2008 3:47 pm    Post subject: spyr.sys - 4th on loadorder and nowhere to be found
Reply with quote

Having a driver with 'spy' in its name that loads so early kinda creeps me out ... Can someone have a look please ? Full gmer log attached, below i'm pasting only the lines containing spyr.sys

Code:
---------- GMER.LOG
SSDT            spyr.sys                                                          ZwEnumerateKey [0xF8434CA2]
SSDT            spyr.sys                                                          ZwEnumerateValueKey [0xF8435030]
?               spyr.sys                                                          The system cannot find the file specified. !
IAT             pci.sys[ntoskrnl.exe!IoDetachDevice]                              [F8447C4C] spyr.sys
IAT             pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                 [F8447CA0] spyr.sys
IAT             atapi.sys[HAL.dll!READ_PORT_UCHAR]                                [F8417040] spyr.sys
IAT             atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                        [F841713C] spyr.sys
IAT             atapi.sys[HAL.dll!READ_PORT_USHORT]                               [F84170BE] spyr.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                       [F84177FC] spyr.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                               [F84176D2] spyr.sys
IAT             \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR][F8427048] spyr.sys
Device          \Driver\sptd \Device\4274730890                                   spyr.sys
Device          \Driver\PCI_PNP9640 \Device\0000004f                              spyr.sys


icesword shows it as loading 4th after ntoskrnl.exe

\WINDOWS\system32\ntoskrnl.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
spyr.sys

Shocked


xp sp2, nod32, outpost firewall, sandboxie and pgp installed ... i don't think the driver belongs to any of them.




gmer.txt
 Description:

Download
 Filename:  gmer.txt
 Filesize:  72.96 KB
 Downloaded:  280 Time(s)

Back to top
View users profile Send private message
fiepluqoufri

Cadet
Cadet


Joined: Jun 11, 2008
Posts: 3
Location: EU

PostPosted: Wed Jun 11, 2008 5:15 pm    Post subject:
Reply with quote

Update.

Played a bit with sysinternals' procexp to see if i could find out anything about the driver ...

It seems it changes its name at every reboot, but always starts with letter s.

Also, when pressing the "Module" button in the "threads" section of the "system" process in procexp i get the properties window of the documents and settings folder instead of the driver file.

screenshot http://img389.imageshack.us/img389/7203/procexpdm5.jpg

Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Thu Jun 12, 2008 2:25 am    Post subject:
Reply with quote

Do you use Daemon Tools?

Gmer Log wrote:
Device \Driver\sptd \Device\4274730890 spyr.sys


It always launches a randomly named driver but the naming convention it uses varies depending on the version that is being used A lot of DT users are puzzled by this.

FYI:
http://www.greatis.com/security/random_spXX.sys_drivers.htm


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
fiepluqoufri

Cadet
Cadet


Joined: Jun 11, 2008
Posts: 3
Location: EU

PostPosted: Thu Jun 12, 2008 4:04 am    Post subject:
Reply with quote

Ok now I feel silly Smile

Thanks for answering!

Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Fri Jun 13, 2008 2:57 am    Post subject:
Reply with quote

You're wlecome, and there's no need to feel silly, fiepluqoufri.

It's wise to question why a randomly named driver keeps regenerating after every reboot. You are in good company because many people are baffled by that same issue. I'd say questions about the Daemon Tools driver and red SSDT hooks in IceSword probably top the list of concerns here.

Since this issue is resolved, I will now mark this topic as "Done".


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer