GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-07-11 21:14:24
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 ST3500418AS rev.CC38
Running: tc2of2xw.exe; Driver: C:\Users\User\AppData\Local\Temp\kxldapob.sys
---- System - GMER 1.0.15 ----
SSDT 86E859C0 ZwAlertResumeThread
SSDT 86E85A80 ZwAlertThread
SSDT 86E841D8 ZwAllocateVirtualMemory
SSDT 86E1B868 ZwAlpcConnectPort
SSDT 86E97870 ZwAssignProcessToJobObject
SSDT 86E85710 ZwCreateMutant
SSDT 86E97590 ZwCreateSymbolicLinkObject
SSDT 86E85460 ZwCreateThread
SSDT 86E97680 ZwCreateThreadEx
SSDT 86E97950 ZwDebugActiveProcess
SSDT 86E26320 ZwDuplicateObject
SSDT 86E86728 ZwFreeVirtualMemory
SSDT 86E85800 ZwImpersonateAnonymousToken
SSDT 86E858E0 ZwImpersonateThread
SSDT 86BC56A0 ZwLoadDriver
SSDT 86E86628 ZwMapViewOfSection
SSDT 86E97D38 ZwOpenEvent
SSDT 86E85348 ZwOpenProcess
SSDT 86E26260 ZwOpenProcessToken
SSDT 86E97B78 ZwOpenSection
SSDT 86E263F0 ZwOpenThread
SSDT 86E97780 ZwProtectVirtualMemory
SSDT 86E84CD0 ZwResumeThread
SSDT 86E84F70 ZwSetContextThread
SSDT 86E86458 ZwSetInformationProcess
SSDT 86E97A30 ZwSetSystemInformation
SSDT 86E97C58 ZwSuspendProcess
SSDT 86E84DB0 ZwSuspendThread
SSDT 86E97E10 ZwTerminateProcess
SSDT 86E84E90 ZwTerminateThread
SSDT 86E86548 ZwUnmapViewOfSection
SSDT 86E84108 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 82A42339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A7BD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82A82DD0 5 Bytes [C0, 59, E8, 86, 80]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10E1 82A82DD6 2 Bytes [E8, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82A82DE8 4 Bytes [D8, 41, E8, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82A82DF4 4 Bytes [68, B8, E1, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82A82E48 4 Bytes [70, 78, E9, 86]
.text ...
.text peauth.sys 9BF65C9E 27 Bytes [46, EE, D5, EA, C1, 27, 64, ...]
.text peauth.sys 9BF65CC2 27 Bytes [46, EE, D5, EA, C1, 27, 64, ...]
.text autochk.exe 00681204 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text autochk.exe 0068120C 1 Byte [00]
.text autochk.exe 00681210 1 Byte [00]
.text autochk.exe 00681214 2 Bytes [00, 00] {ADD [EAX], AL}
.text autochk.exe 00681218 2 Bytes [00, 00] {ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] ntdll.dll!NtMapViewOfSection 77C05C28 5 Bytes JMP 01F5003A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] ntdll.dll!NtSetInformationProcess 77C06678 5 Bytes JMP 01F500F7
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!K32GetPerformanceInfo + 1B6 7790602A 7 Bytes JMP 01F50266
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!ReadProcessMemory + B 7790C1D9 7 Bytes JMP 01F501B0
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!TerminateProcess + B 7791233C 7 Bytes JMP 01F503D2
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!GetEnvironmentStringsA + 11 77922FB1 7 Bytes JMP 01F5031C
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!CreateThread 7792375D 5 Bytes JMP 6C8971CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] kernel32.dll!SetUnhandledExceptionFilter + 19C 77923E9D 7 Bytes JMP 01F50488
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!EnableWindow 77228D02 5 Bytes JMP 6C8D98BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!CallNextHookEx 7722ABE1 5 Bytes JMP 6C8F7A3F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!UnhookWindowsHookEx 7722ADF9 5 Bytes JMP 6C91E9F8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DefWindowProcA 7722BB1C 7 Bytes JMP 6C8993F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!CreateWindowExA 7722BF40 5 Bytes JMP 6C8A3223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!SetWindowsHookExW 7722E30C 5 Bytes JMP 6C8D204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!CreateWindowExW 7722EC7C 5 Bytes JMP 6C8FFE1F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DefWindowProcW 7723507D 7 Bytes JMP 6C8F7AA2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DialogBoxParamW 77243B9B 5 Bytes JMP 6C8315E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DialogBoxIndirectParamW 77253B7F 5 Bytes JMP 6CA25E86 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DialogBoxParamA 7726CF42 5 Bytes JMP 6CA25E21 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!DialogBoxIndirectParamA 7726D274 5 Bytes JMP 6CA25EEB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!MessageBoxIndirectA 7727E869 5 Bytes JMP 6CA25DA8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!MessageBoxIndirectW 7727E963 5 Bytes JMP 6CA25D2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!MessageBoxExA 7727E9C9 5 Bytes JMP 6CA25CCB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] USER32.dll!MessageBoxExW 7727E9ED 5 Bytes JMP 6CA25C67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] ole32.dll!OleLoadFromStream 779B6143 5 Bytes JMP 6CA2666E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] ole32.dll!CoGetMarshalSizeMax + 62BD 779E54A8 7 Bytes JMP 01F5053E
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] ole32.dll!CoCreateInstance + 3E 779F9D49 7 Bytes JMP 01F505F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WININET.dll!HttpAddRequestHeadersA 763D1B9C 5 Bytes JMP 003D6822
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WININET.dll!HttpAddRequestHeadersW 7641F7A8 5 Bytes JMP 003D6A2D
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!closesocket 77D23918 5 Bytes JMP 005D000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!getaddrinfo 77D24296 5 Bytes JMP 0060000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!recv 77D26B0E 5 Bytes JMP 005A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!connect 77D26BDD 5 Bytes JMP 005C000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!send 77D26F01 3 Bytes JMP 005E000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!send + 4 77D26F05 1 Byte [88]
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!gethostbyname 77D37673 3 Bytes JMP 005F000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2656] WS2_32.dll!gethostbyname + 4 77D37677 1 Byte [88]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] ntdll.dll!NtMapViewOfSection 77C05C28 5 Bytes JMP 0181003A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] ntdll.dll!NtSetInformationProcess 77C06678 5 Bytes JMP 018100F7
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] ntdll.dll!LdrLoadDll 77C222B8 5 Bytes JMP 00221410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] kernel32.dll!K32GetPerformanceInfo + 1B6 7790602A 7 Bytes JMP 01810266
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] kernel32.dll!ReadProcessMemory + B 7790C1D9 7 Bytes JMP 018101B0
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] kernel32.dll!TerminateProcess + B 7791233C 7 Bytes JMP 018103D2
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] kernel32.dll!GetEnvironmentStringsA + 11 77922FB1 7 Bytes JMP 0181031C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] kernel32.dll!SetUnhandledExceptionFilter + 19C 77923E9D 7 Bytes JMP 01810488
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] WS2_32.dll!closesocket 77D23918 5 Bytes JMP 004F000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] WS2_32.dll!getaddrinfo 77D24296 5 Bytes JMP 0062000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] WS2_32.dll!connect 77D26BDD 5 Bytes JMP 003A000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] WS2_32.dll!send 77D26F01 5 Bytes JMP 0060000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3152] WS2_32.dll!gethostbyname 77D37673 5 Bytes JMP 0061000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!EnableWindow 77228D02 5 Bytes JMP 6C8D98BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!DialogBoxParamW 77243B9B 5 Bytes JMP 6C8315E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!DialogBoxIndirectParamW 77253B7F 5 Bytes JMP 6CA25E86 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!DialogBoxParamA 7726CF42 5 Bytes JMP 6CA25E21 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!DialogBoxIndirectParamA 7726D274 5 Bytes JMP 6CA25EEB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!MessageBoxIndirectA 7727E869 5 Bytes JMP 6CA25DA8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!MessageBoxIndirectW 7727E963 5 Bytes JMP 6CA25D2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!MessageBoxExA 7727E9C9 5 Bytes JMP 6CA25CCB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] USER32.dll!MessageBoxExW 7727E9ED 5 Bytes JMP 6CA25C67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] WININET.dll!HttpAddRequestHeadersA 763D1B9C 5 Bytes JMP 00996822
.text C:\Program Files\Internet Explorer\iexplore.exe[3684] WININET.dll!HttpAddRequestHeadersW 7641F7A8 5 Bytes JMP 00996A2D
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdD3Transition] [80BC05E9] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdD0Transition] [80BC05DF] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdReceivePacket] [80BC060D] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdSendPacket] [80BC0631] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdRestore] [80BC0619] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdSave] [80BC0625] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdDebuggerInitialize0] [80BC05F3] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\ntkrnlpa.exe[KDCOM.dll!KdDebuggerInitialize1] [80BC05FF] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
IAT \SystemRoot\system32\halmacpi.dll[KDCOM.dll!KdRestore] [80BC0619] \SystemRoot\system32\kdcom.dll (Serial Kernel Debugger/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[1844] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [75C9FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:208] 865180B3
Thread System [4:220] 865197FB
---- EOF - GMER 1.0.15 ----