GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-04-29 18:32:41
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 8216D5F8 ZwEnumerateKey
Code 82070B20 ZwFlushInstructionCache
Code 82197B16 IofCallDriver
Code 8219A4C6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 82197B1B
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 8219A4CB
PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 5 Bytes JMP 8216D5FC
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577693 5 Bytes JMP 82070B24
? C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\rootrepeal.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\spoolsv.exe[1456] msvcrt.dll!tan 77C4D5E4 2 Bytes [83, 7C]
.text C:\WINDOWS\system32\spoolsv.exe[1456] msvcrt.dll!tan + 3 77C4D5E7 5 Bytes [08, 01, 75, 19, 6A]
.text C:\WINDOWS\system32\spoolsv.exe[1456] msvcrt.dll!tan + 9 77C4D5ED 28 Bytes [6A, 00, 68, 88, 67, 90, 7C, ...]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2804] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00A3000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2804] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00A6000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2804] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00A4000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2804] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00A5000A
---- Processes - GMER 1.0.15 ----
Library C:\WINDOWS\system32\dll.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1456] this shows in red in gmer 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxceenagdlvksblmkmuqxducvqsyufxceju.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [2804]
0x10000000 this one also shows in red
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys (*** hidden *** ) [SYSTEM] gxvxcserv.sys <-- ROOTKIT !!! this one also
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxceenagdlvksblmkmuqxducvqsyufxceju.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxceenagdlvksblmkmuqxducvqsyufxceju.dll
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\SYSTEM32\DRIVERS\gxvxcrsvpxeoewqelwbwexvitalnbmqppyrbb.sys 32256 bytes executable <-- ROOTKIT !!! and this one
File C:\WINDOWS\SYSTEM32\gxvxccounter 4 bytes
File C:\WINDOWS\SYSTEM32\gxvxceenagdlvksblmkmuqxducvqsyufxceju.dll 14336 bytes executable
---- EOF - GMER 1.0.15 ----
Edited by wolfj, 29 April 2009 - 05:47 PM.