ie8 fix

Spyware, viruses, & security forum: Rootkit buster clean or not?

by: BagelAnne April 22, 2012 6:02 PM PDT

Like this

0 people like this thread

Staff pick

Resolved question

Rootkit buster clean or not?

by BagelAnne - 4/22/12 6:02 PM

I have a dell desktop with Win xp with SP3 and norton 360.
Just cleaned a ton of trojans and one rootkit (Rootkit.Boot.Piharib)
All scans are clean now except Trend Micro Rootkit Buster.
Can someone please advise me on this log:
+----------------------------------------------------
| Trend Micro RootkitBuster
| Module version: 5.0.0.1050
| Computer Name: FOX-1
| OS version: 5.1-2600
| User Name: Bob
+----------------------------------------------------


--== Dump Hidden MBR, Hidden Files and Alternate Data Streams on C:\ ==--
MBR unsupported disk type
No hidden files found.

--== Dump Hidden Registry Value on HKLM ==--
No hidden registry entries found.


--== Dump Hidden Process ==--
No hidden processes found.

--== Dump Hidden Driver ==--
No hidden drivers found.

--== Service Win32 API Hook List ==--
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d4b7e
CurrentHandler : 0x8a2b71c0
ServiceNumber : 0xc
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d4b2e
CurrentHandler : 0x8a2b87a0
ServiceNumber : 0xd
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805a8aba
CurrentHandler : 0x8a5fa008
ServiceNumber : 0x11
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d6642
CurrentHandler : 0x8a2ae140
ServiceNumber : 0x13
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805a45d0
CurrentHandler : 0x8a0c74d0
ServiceNumber : 0x1f
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x805790a8
CurrentHandler : 0xa89cfbe4
ServiceNumber : 0x25
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x806240f0
CurrentHandler : 0xa8e74710
ServiceNumber : 0x29
ModuleName : S
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x8061769e
CurrentHandler : 0x8a23f150
ServiceNumber : 0x2b
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805c39fa
CurrentHandler : 0x8a2693d8
ServiceNumber : 0x34
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d1018
CurrentHandler : 0x8a5e81c8
ServiceNumber : 0x35
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x80643b30
CurrentHandler : 0x8a2af0e0
ServiceNumber : 0x39
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80576c50
CurrentHandler : 0xa89cfddc
ServiceNumber : 0x3e
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x8062458c
CurrentHandler : 0xa8e74990
ServiceNumber : 0x3f
ModuleName : S
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x8062475c
CurrentHandler : 0xa8e74ef0
ServiceNumber : 0x41
ModuleName : S
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805be008
CurrentHandler : 0x8a5fb008
ServiceNumber : 0x44
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805b2fb2
CurrentHandler : 0x8a0c53e0
ServiceNumber : 0x53
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805f9386
CurrentHandler : 0x8a2b52e8
ServiceNumber : 0x59
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d7802
CurrentHandler : 0x8a2b53c0
ServiceNumber : 0x5b
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x80584160
CurrentHandler : 0x8a393f38
ServiceNumber : 0x61
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80626314
CurrentHandler : 0xa89d3746
ServiceNumber : 0x62
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805b203a
CurrentHandler : 0x8a0890a8
ServiceNumber : 0x6c
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x8060f04e
CurrentHandler : 0x8a2b4b48
ServiceNumber : 0x72
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x8057a1a6
CurrentHandler : 0xa89cfcfc
ServiceNumber : 0x74
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805cb440
CurrentHandler : 0x8a287188
ServiceNumber : 0x7a
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805ee054
CurrentHandler : 0x8a3991d8
ServiceNumber : 0x7b
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805aa3ec
CurrentHandler : 0x8a2b0b78
ServiceNumber : 0x7d
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805cb6cc
CurrentHandler : 0x8a2721a0
ServiceNumber : 0x80
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805b841e
CurrentHandler : 0x8a2694a8
ServiceNumber : 0x89
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80622314
CurrentHandler : 0xa89d36bc
ServiceNumber : 0xb1
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80623b12
CurrentHandler : 0xa89d3626
ServiceNumber : 0xc0
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x806261c4
CurrentHandler : 0xa89d3658
ServiceNumber : 0xc1
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80625ad0
CurrentHandler : 0xa89d368a
ServiceNumber : 0xcc
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d49ba
CurrentHandler : 0x8a2be818
ServiceNumber : 0xce
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d173a
CurrentHandler : 0x8a01f220
ServiceNumber : 0xd5
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x8057b034
CurrentHandler : 0xa89cfe82
ServiceNumber : 0xe0
ModuleName : R
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805cde8a
CurrentHandler : 0x89f1a190
ServiceNumber : 0xe4
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x8060fd06
CurrentHandler : 0x8a2b0140
ServiceNumber : 0xf0
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path : C
OriginalHandler : 0x80622662
CurrentHandler : 0xa8e75140
ServiceNumber : 0xf7
ModuleName : S
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d4a82
CurrentHandler : 0x8a2b4a70
ServiceNumber : 0xfd
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d48f4
CurrentHandler : 0x8a2bea30
ServiceNumber : 0xfe
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d29e2
CurrentHandler : 0x8a39c850
ServiceNumber : 0x101
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805d2bdc
CurrentHandler : 0x8a2bd0c0
ServiceNumber : 0x102
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805b2e48
CurrentHandler : 0x8a38d9f0
ServiceNumber : 0x10b
ModuleName :
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : Z
Image Path :
OriginalHandler : 0x805b43cc
CurrentHandler : 0x8a5fa118
ServiceNumber : 0x115
ModuleName :
SDTType : 0x0
No hidden operating system service hooks found.

--== Dump Hidden Port ==--
No hidden ports found.

--== Dump Kernel Code Patching ==--
No kernel code patching detected.

--== Dump Hidden Services ==--
No hidden services found.

Forum Icon Legend

  • UnreadUnread
  • ReadRead
  • Locked threadLocked thread
  •   
  •   
  •   
  •   
  •   
  •   
  •   
  • ModeratorModerator
  • CNET StaffCNET Staff
  • Samsung StaffSamsung Staff
  • Norton Authorized Support TeamNorton Authorized Support Team
  • AVG StaffAVG Staff
  • avast! Staffavast! Staff
  • Webroot Support TeamWebroot Support Team
  • Acer Customer Experience TeamAcer Customer Experience Team
  • Windows Outreach TeamWindows Outreach Team
  • DISH staffDISH staff
  • Dell StaffDell Staff
  • Intel StaffIntel Staff
  • QuestionQuestion
  • Resolved questionResolved question
  • General discussionGeneral discussion
  • TipTip
  • Alert or warningAlert or warning
  • PraisePraise
  • RantRant

You are e-mailing the following post: Post Subject

Your e-mail address is used only to let the recipient know who sent the e-mail and in case of transmission error. Neither your address nor the recipient's address will be used for any other purpose.

Sorry, there was a problem emailing this post. Please try again.

Submit Email Cancel

Thank you. Sent email to

Close

Thank you. Sent email to

Close

You are reporting the following post: Post Subject

If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

Offensive: Sexually explicit or offensive language

Spam: Advertisements or commercial links

Disruptive posting: Flaming or offending other users

Illegal activities: Promote cracked software, or other illegal content

Sorry, there was a problem submitting your post. Please try again.

Submit Report Cancel

Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.

Close

Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.

Close

You are posting a reply to: Post Subject

The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to the CNET Forums policies for details. All submitted content is subject to CBS Interactive Site Terms of Use.

You are currently tracking this discussion. Click here to manage your tracked discussions.

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Sorry, there was a problem submitting your post. Please try again.

Sorry, there was a problem generating the preview. Please try again.

Duplicate posts are not allowed in the forums. Please edit your post and submit again.

Submit Reply Preview Cancel

Thank you, , your post has been submitted and will appear on our site shortly.

Close

You are requesting a clarification of the question: Post Subject

The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to the CNET Forums policies for details. All submitted content is subject to CBS Interactive Site Terms of Use.

You are currently tracking this discussion. Click here to manage your tracked discussions.

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Sorry, there was a problem submitting your post. Please try again.

Sorry, there was a problem generating the preview. Please try again.

Submit Clarification Request Preview Cancel

Thank you, , your post has been submitted and will appear on our site shortly.

Close

You are posting an answer to the question: Post Subject

The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to the CNET Forums policies for details. All submitted content is subject to CBS Interactive Site Terms of Use.

You are currently tracking this discussion. Click here to manage your tracked discussions.

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Sorry, there was a problem submitting your post. Please try again.

Sorry, there was a problem generating the preview. Please try again.

Submit Answer Preview Cancel

Thank you, , your post has been submitted and will appear on our site shortly.

Close
close

Click here to be notified via e-mail when someone submits an answer.

Would you like to resolve this question? close

Based on your response, it looks like this question has been answered.



Sorry, there was a problem resolving this question. Please try again.

Resolve Leave unresolved