GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-01-24 14:21:37 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 HDS728080PLAT20 rev.PF2OA28A Running: hzcs4v2s.exe; Driver: C:\DOCUME~1\owner\LOCALS~1\Temp\uxtdqpoc.sys ---- Devices - GMER 1.0.15 ---- Device 836E81F8 Device 840EB500 Device 84315500 Device 845881F8 Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation) Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation) AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) Device Ntfs.sys (NT File System Driver/Microsoft Corporation) Device Udfs.SYS (UDF File System Driver/Microsoft Corporation) .text ... ---- System - GMER 1.0.15 ---- INT 0x63 ? 842AFBF8 INT 0x63 ? 842AFBF8 INT 0x63 ? 842AFBF8 INT 0x63 ? 842AFBF8 INT 0x62 ? 8458ABF8 INT 0x82 ? 8458ABF8 INT 0x83 ? 8458ABF8 INT 0xA4 ? 84590BF8 ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!! Device \Driver\a06mu7ca \Device\Scsi\a06mu7ca1 842AB500 Device \Driver\a06mu7ca \Device\Scsi\a06mu7ca1Port5Path0Target0Lun0 842AB500 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP2T0L0-12 83FF52C6 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T0L0-7 83FF52C6 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 83FF52C6 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 83FF52C6 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 83FF52C6 Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 83FF52C6 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-12 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-7 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F737DB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Cdrom \Device\CdRom0 843B81F8 Device \Driver\Cdrom \Device\CdRom1 843B81F8 Device \Driver\Cdrom \Device\CdRom2 843B81F8 Device \Driver\dmio \Device\DmControl\DmConfig 8458B1F8 Device \Driver\dmio \Device\DmControl\DmInfo 8458B1F8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8458B1F8 Device \Driver\dmio \Device\DmControl\DmPnP 8458B1F8 Device \Driver\Ftdisk \Device\FtControl 8458C1F8 Device \Driver\Ftdisk \Device\HarddiskVolume1 8458C1F8 Device \Driver\NetBT \Device\NetbiosSmb 837141F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{3C620658-A5E7-4852-B13B-A9DE11785BC5} 837141F8 Device \Driver\NetBT \Device\NetBt_Wins_Export 837141F8 Device \Driver\PCI_PNP9510 \Device\00000047 spnr.sys Device \Driver\sptd \Device\2199060760 spnr.sys AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) Device \Driver\usbehci \Device\USBFDO-2 843BC1F8 Device \Driver\usbehci \Device\USBPDO-2 843BC1F8 Device \Driver\usbohci \Device\USBFDO-0 842AE1F8 Device \Driver\usbohci \Device\USBFDO-1 842AE1F8 Device \Driver\usbohci \Device\USBPDO-0 842AE1F8 Device \Driver\usbohci \Device\USBPDO-1 842AE1F8 Device \Driver\usbstor \Device\0000006d 836D91F8 Device \Driver\usbstor \Device\00000070 836D91F8 Device \Driver\usbstor \Device\00000071 836D91F8 Device \Driver\usbstor \Device\00000072 836D91F8 Device \Driver\usbstor \Device\00000073 836D91F8 Device \Driver\usbstor \Device\00000078 836D91F8 Device \Driver\usbstor \Device\00000079 836D91F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 836E81F8 ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!HalGetInterruptVector] 74AAB000 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!HalTranslateBusAddress] 8986C636 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KeGetCurrentIrql] 9E880000 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KfLowerIrql] 0E798366 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KfRaiseIrql] 00001CB1 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!READ_PORT_USHORT] 001C9686 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2 IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E IAT \SystemRoot\System32\Drivers\a06mu7ca.SYS[WMILIB.SYS!WmiSystemControl] 8800001C SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xEB1B3F3C] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xEB1B3FE4] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xEB1B4080] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xEB1B411C] ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7439B90] spnr.sys ---- Kernel code sections - GMER 1.0.15 ---- .text a06mu7ca.SYS F5D78386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...] .text a06mu7ca.SYS F5D783AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...] .text a06mu7ca.SYS F5D783C4 3 Bytes [00, 80, 02] .text a06mu7ca.SYS F5D783C9 1 Byte [30] .text a06mu7ca.SYS F5D783C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL} ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F742A13E] spnr.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F742A042] spnr.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F742A0C0] spnr.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F742A800] spnr.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F742A6D6] spnr.sys ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Real\RealPlayer\update\realsched.exe[1312] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4} ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF63D0000, 0x1C5D38, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\System32\svchost.exe[1328] kernel32.dll!WriteFile 7C810E27 5 Bytes JMP 0092000C .text C:\WINDOWS\System32\svchost.exe[1328] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 0095000A .text C:\WINDOWS\System32\svchost.exe[1328] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0361000A .text C:\WINDOWS\System32\svchost.exe[1328] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 0363000A .text C:\WINDOWS\System32\svchost.exe[1328] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 0362000A ---- Registry - GMER 1.0.15 ---- Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore@Flags 4 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains\roblox.com Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3C 0xB6 0x5F 0x52 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x08 0x9B 0x59 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x33 0xBC 0x43 0x16 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3C 0xB6 0x5F 0x52 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x08 0x9B 0x59 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x33 0xBC 0x43 0x16 ... ---- Kernel code sections - GMER 1.0.15 ---- ? spnr.sys The system cannot find the file specified. ! SSDT spnr.sys ZwCreateKey [0xF74290E0] SSDT spnr.sys ZwEnumerateKey [0xF7441DA4] SSDT spnr.sys ZwEnumerateValueKey [0xF7442132] SSDT spnr.sys ZwOpenKey [0xF74290C0] SSDT spnr.sys ZwQueryKey [0xF744220A] SSDT spnr.sys ZwQueryValueKey [0xF744208A] SSDT spnr.sys ZwSetValueKey [0xF744229C] ---- Kernel code sections - GMER 1.0.15 ---- .text USBPORT.SYS!DllUnload F63AF8AC 5 Bytes JMP 842AF1D8 ---- Files - GMER 1.0.15 ---- File C:\WINDOWS\$NtUninstallKB34979$\3882991254 0 bytes File C:\WINDOWS\$NtUninstallKB34979$\40340164 0 bytes File C:\WINDOWS\$NtUninstallKB34979$\40340164\L 0 bytes File C:\WINDOWS\$NtUninstallKB34979$\40340164\U 0 bytes ---- EOF - GMER 1.0.15 ----