PDA

View Full Version : Dr Web now installs a driver...?


Lovecraft
January 9th, 2009, 05:41 PM
I've just downloaded DrWeb Cureit from freedrweb.com and ran it, as usual... but this time, after a scan, it asked to reboot. I checked the memory with Root Repeal just in case, and noticed that these items appeared:

Name: MnbRWV2m.sys
Image Path: C:\WINDOWS\TEMP\MnbRWV2m.sys
Address: 0xF22CE000 Size: 142464 File Visible: No
Status: -

also these:
Name: Fastfat.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Address: 0xF2DFF000 Size: 143360 File Visible: -
Status: Hidden from Windows API!

Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xF73C7000 Size: 574592 File Visible: -
Status: Hidden from Windows API!

(I also have regular, non-hidden Ntfs.sys and Fastfat.sys listed.)

None of these files, when dumped with RootRepeal, is flagged by anything on Virustotal.

The file apparently ran/installed/whatever by DrWeb is the MnbRWV2m.sys file, which is 142464 bytes when dumped with RootRepeal, and its CRC32 is EF2FECF5 then.

Did they add something or am I getting paranoid?

Lovecraft
January 9th, 2009, 05:48 PM
Now I noticed it's updated to v5.0 from the previous 4.44. I guess that should be the reason...

I have not yet restarted yet, but for some reason, after I ran it CureIt again, it has not asked me to restart now.

Edit: I restarted, ran Cureit again, and it again asks me to restart after completing scanning... what is this, was this introduced in v5? Will it keep happening after every scan, and why?

risl
January 9th, 2009, 06:55 PM
Don't know about CureIt but Dr.Web AV 5.0 uses atleast 2 drivers, spider.sys as a file system monitor and dwprot.sys for self-protection. But it doesn't sound "OK" that it asks for you to reboot after each scan, do you have some other software that prevents driver installations or even writing them to HD? I assume they use some kind of driver in CureIt too and it sounds like something pervents it.

C.S.J
January 9th, 2009, 07:42 PM
unless im mistaken, cureit used to use a driver and remove it when you exit from the program, dont know if this is still the case.

format_c
January 10th, 2009, 06:20 AM
-{ Quote: "unless im mistaken, cureit used to use a driver and remove it when you exit from the program, dont know if this is still the case." }-

no, you're right ;) Dr.Web/CureIt scanner loads Dr.Web Shield (anti-rootkit) driver at its start-up time