Undetermined Anomaly..

PornoSatan

2[H]4U
Joined
Sep 3, 2004
Messages
3,493
Looking through my Boot log (C:\Windows\NTBTLOG.TXT) I noticed a strange pattern, here's 2 examples pasted from recent entries, notice what I bolded, the rest is just listed to show the order.

Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\System32\Drivers\a0qfajra.SYS
Loaded driver \SystemRoot\System32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\System32\DRIVERS\rasirda.sys

Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\System32\Drivers\a2o2hlpf.SYS
Loaded driver \SystemRoot\System32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\System32\DRIVERS\rasirda.sys

I'm not quite sure what to make of it. You can see whatever it is, is being renamed on each reboot. Attempting to view/search for this randomly named file yields nothing, its either entirely invisible, or doesnt exist at all. Now after bootup, when said file is already loaded, I can do a lookup through regedit (like searching for a2o2hlpf), and the hits all point to the same places, basically confirming its the same file. One hit comes from HKEY_LOCAL_MACHINE\HARDWARE\DEVICEMAP\Scsi\Scsi Port 4

Now looking through most of these values and strings I dont entirely understand, but the basic pattern of the keys from Scsi Port 0 to 3 all utilize the same Atapi driver. So whats up with Scsi Port 4 using a constantly changing driver that has nothing to do with Atapi? The only time I really see this type of behavior (filename randomization, hidden from windows) is with trojans/rootkits. So I'm just curious, anyone else have a similar pattern going on, or can explain this one?

Searching further, I find another hit here:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNPA000\4&4d56c0f2&0

The CompatibleID's key labels it as a GEN_SCSIADAPTER (Generic Scsi Adapter?)
 
What was the solution?

I absolutely hate it when people say they fixed it and never put down what the solution was! :mad:
 
Its related to the drive emulation done by Alcohol 120. As you can see here:

solvedcu0.jpg
 
In this case I didnt have any virtual drives loaded up. So that "Target Id 0" key wasnt there when I was looking around, and when I made my original post. :p
 
Back
Top