GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-07-08 22:35:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort1 ST380013AS rev.8.12
Running: dzknxbd4gamer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kftcypob.sys
---- System - GMER 1.0.15 ----
SSDT 8AF4C050 ZwAlertResumeThread
SSDT 8A87A050 ZwAlertThread
SSDT 8B356268 ZwAllocateVirtualMemory
SSDT 8AF4A050 ZwAssignProcessToJobObject
SSDT 8B4587D8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB6F43210]
SSDT 8A7228C0 ZwCreateMutant
SSDT 8A7223A8 ZwCreateSymbolicLinkObject
SSDT 8B45DCB8 ZwCreateThread
SSDT 8A878050 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB6F43490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB6F439F0]
SSDT 8B470D28 ZwDuplicateObject
SSDT 8B08CD38 ZwFreeVirtualMemory
SSDT 8A936050 ZwImpersonateAnonymousToken
SSDT 8AF8D050 ZwImpersonateThread
SSDT 8B500C98 ZwLoadDriver
SSDT 8B08CC58 ZwMapViewOfSection
SSDT 8A879050 ZwOpenEvent
SSDT 8B348F78 ZwOpenProcess
SSDT 8AF31050 ZwOpenProcessToken
SSDT 8AF8C050 ZwOpenSection
SSDT 8B3F3C60 ZwOpenThread
SSDT 8A722478 ZwProtectVirtualMemory
SSDT 8A937050 ZwResumeThread
SSDT 8AF53050 ZwSetContextThread
SSDT 8AF2F308 ZwSetInformationProcess
SSDT 8A935050 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB6F43C40]
SSDT 8AF4B050 ZwSuspendProcess
SSDT 8AF51050 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB6D28640]
SSDT 8AF52050 ZwTerminateThread
SSDT 8AF54050 ZwUnmapViewOfSection
SSDT 8B4F3F08 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 001A3984
.text C:\WINDOWS\System32\svchost.exe[1140] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 001A42DC
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 001A432B
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 001A438B
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!IsWindowVisible 7E429E3D 5 Bytes JMP 001A43B2
.text C:\WINDOWS\System32\svchost.exe[1140] USER32.dll!MessageBoxIndirectW 7E4664D5 6 Bytes [33, C0, 40, C2, 04, 00] {XOR EAX, EAX; INC EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[1140] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 001A43EA
.text C:\WINDOWS\System32\svchost.exe[1140] ole32.dll!CoGetClassObject 77515205 5 Bytes JMP 001A43B8
.text C:\WINDOWS\System32\svchost.exe[1140] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 001A4278
.text C:\WINDOWS\system32\SearchIndexer.exe[2016] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\program files\real\realplayer\update\realsched.exe[2444] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8B0332E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 8B0332E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8B0332E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8B0332E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8B0332E2
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device B27E4D20
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore@DisableSR \t 1
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----