Here is the GMER log:
I also attached the other DDSattach file in case you need it. Thanks!
DDSattach 11-27-11.txt (21.03K)
Number of downloads: 1
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-27 23:46:44
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\00000083 ST3160023A rev.8.01
Running: 2rgpjxnx.exe; Driver: C:\DOCUME~1\admin\LOCALS~1\Temp\ugldipow.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwCreateKey [0xF73900B0]
SSDT sptd.sys ZwEnumerateKey [0xF739584C]
SSDT sptd.sys ZwEnumerateValueKey [0xF7395BEC]
SSDT sptd.sys ZwOpenKey [0xF7390090]
SSDT sptd.sys ZwQueryKey [0xF7395CC4]
SSDT sptd.sys ZwQueryValueKey [0xF7395B44]
SSDT sptd.sys ZwSetValueKey [0xF7395D56]
---- Kernel code sections - GMER 1.0.15 ----
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F6F688AC 5 Bytes JMP 871D07C8
? System32\Drivers\a6teaf1l.SYS The system cannot find the path specified. !
.text i8042prt.sys F7658000 9 Bytes [90, 90, 90, 90, 8B, FF, 55, ...] {NOP ; NOP ; NOP ; NOP ; MOV EDI, EDI; PUSH EBP; MOV EBP, ESP}
.text i8042prt.sys F765800A 29 Bytes [56, 8B, 75, 08, 57, 33, FF, ...]
.text i8042prt.sys F7658028 12 Bytes [15, 5C, A4, 65, F7, 38, 5D, ...]
.text i8042prt.sys F7658036 111 Bytes [38, 5D, 0C, 0F, 85, BC, 10, ...]
.text i8042prt.sys F76580A6 6 Bytes [6A, 00, E8, 2F, 00, 00]
.text ...
? C:\WINDOWS\System32\DRIVERS\i8042prt.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 016E000A
.text C:\WINDOWS\System32\svchost.exe[1520] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 016F000A
.text C:\WINDOWS\System32\svchost.exe[1520] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 016D000C
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 873651D8
Device \FileSystem\Fastfat \FatCdrom 86FD6980
Device \Driver\USBSTOR \Device\0000008e 86FF0980
AttachedDevice \Driver\Tcpip \Device\Ip aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
Device \Driver\usbohci \Device\USBPDO-0 871B9590
Device \Driver\dmio \Device\DmControl\DmIoDaemon 873671D8
Device \Driver\dmio \Device\DmControl\DmConfig 873671D8
Device \Driver\dmio \Device\DmControl\DmPnP 873671D8
Device \Driver\dmio \Device\DmControl\DmInfo 873671D8
Device \Driver\usbohci \Device\USBPDO-1 871B9590
Device \Driver\usbehci \Device\USBPDO-2 871D2980
AttachedDevice \Driver\Tcpip \Device\Tcp aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
Device \Driver\Ftdisk \Device\HarddiskVolume1 873D81D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 873D81D8
Device \Driver\Cdrom \Device\CdRom0 871CF980
Device \Driver\Ftdisk \Device\HarddiskVolume3 873D81D8
Device \Driver\Cdrom \Device\CdRom1 871CF980
Device \Driver\Ftdisk \Device\HarddiskVolume4 873D81D8
Device \Driver\00000457 \Device\00000068 sptd.sys
Device \Driver\USBSTOR \Device\00000090 86FF0980
Device \Driver\NetBT \Device\NetBt_Wins_Export 86FF7980
Device \Driver\NetBT \Device\NetbiosSmb 86FF7980
AttachedDevice \Driver\Tcpip \Device\Udp aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{28EA8460-991F-42B2-B18D-CC86A6CD4620} 86FF7980
Device \Driver\usbohci \Device\USBFDO-0 871B9590
Device \Driver\usbohci \Device\USBFDO-1 871B9590
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86FEF980
Device \Driver\usbehci \Device\USBFDO-2 871D2980
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86FEF980
Device \Driver\Ftdisk \Device\FtControl 873D81D8
Device \Driver\a6teaf1l \Device\Scsi\a6teaf1l1Port1Path0Target0Lun0 8719D1D8
Device \Driver\a6teaf1l \Device\Scsi\a6teaf1l1 8719D1D8
Device \FileSystem\Fastfat \Fat 86FD6980
Device \FileSystem\Cdfs \Cdfs 86FC7570
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) F6E94000-F6EB4000 (131072 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0xBC 0x10 0x27 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0F 0xC8 0xBA 0x81 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x85 0x2D 0xF9 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000c55fb3816 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000c55fb3816@00128a92fffc 0xA7 0x7E 0xDE 0x06 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0xBC 0x10 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0F 0xC8 0xBA 0x81 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x85 0x2D 0xF9 0x43 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0xBC 0x10 0x27 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0F 0xC8 0xBA 0x81 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x85 0x2D 0xF9 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000c55fb3816
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000c55fb3816@00128a92fffc 0xA7 0x7E 0xDE 0x06 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -2038548205
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1830292685
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0xBC 0x10 0x27 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0F 0xC8 0xBA 0x81 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x85 0x2D 0xF9 0x43 ...
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\000c55fb3816 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\000c55fb3816@00128a92fffc 0xA7 0x7E 0xDE 0x06 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0xBC 0x10 0x27 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0F 0xC8 0xBA 0x81 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x85 0x2D 0xF9 0x43 ...
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB9151$\1020862310 0 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\bckfg.tmp 794 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\cfg.ini 208 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\keywords 0 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\L 0 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\L\akygdmgo 52480 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\lsflt7.ver 329 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U 0 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\00000001.@ 1536 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\80000000.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1020862310\U\80000032.@ 98304 bytes
File C:\WINDOWS\$NtUninstallKB9151$\1088237322 0 bytes
---- EOF - GMER 1.0.15 ----