Hello.
Thank you for help.
Below, the requested log.
Only some informations please, maybe are important:
1. First scan: computer interrupted; I don't know where.
2. Second scan: computer interrupted again; to some movies on the hard C.; I have deleted the movies.
3. Third scan: at last, it works; but he didn't gave me notice about rootkit activity.
4. In the log, before saving in txt format, the last sentence (about pciide.sys) was colourfull in red.
5. Maybe is relevant: when I give Start / Windows Update, IE cannot display the webpage (of course, hi,hi, I am connected to the net, he works fine).
Best regards,
Spandau
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-11-09 20:05:49
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort3 WDC_WD6400AACS-00G8B1 rev.05.04C05
Running: gmer.exe; Driver: C:\DOCUME~1\a\LOCALS~1\Temp\fgxoipoc.sys
---- System - GMER 1.0.15 ----
SSDT 892ED580 ZwAssignProcessToJobObject
SSDT spgc.sys ZwCreateKey [0xB9EA80E0]
SSDT 892EE100 ZwDebugActiveProcess
SSDT 892EDB30 ZwDuplicateObject
SSDT spgc.sys ZwEnumerateKey [0xB9EC6CA2]
SSDT spgc.sys ZwEnumerateValueKey [0xB9EC7030]
SSDT spgc.sys ZwOpenKey [0xB9EA80C0]
SSDT 892ECCC0 ZwOpenProcess
SSDT 892ECFC0 ZwOpenThread
SSDT 892ED9C0 ZwProtectVirtualMemory
SSDT spgc.sys ZwQueryKey [0xB9EC7108]
SSDT spgc.sys ZwQueryValueKey [0xB9EC6F88]
SSDT 892ED860 ZwSetContextThread
SSDT 892ED6E0 ZwSetInformationThread
SSDT 892EA700 ZwSetSecurityObject
SSDT spgc.sys ZwSetValueKey [0xB9EC719A]
SSDT 892ED420 ZwSuspendProcess
SSDT 892ED2C0 ZwSuspendThread
SSDT 892ECE50 ZwTerminateProcess
SSDT 892ED150 ZwTerminateThread
SSDT 892EDF50 ZwWriteVirtualMemory
INT 0x63 ? 89E56BF8
INT 0x63 ? 89E56BF8
INT 0x63 ? 89E56BF8
INT 0x63 ? 89E56BF8
INT 0x63 ? 89E56BF8
INT 0x83 ? 89E56BF8
INT 0x83 ? 89E56BF8
INT 0x83 ? 89BA0BF8
INT 0x83 ? 89E56BF8
INT 0x84 ? 89BA0BF8
INT 0x94 ? 89BA0BF8
INT 0xA4 ? 89BA0BF8
INT 0xA4 ? 89BA0BF8
INT 0xA4 ? 89BA0BF8
INT 0xA4 ? 89BA0BF8
INT 0xB4 ? 89BA0BF8
---- Kernel code sections - GMER 1.0.15 ----
? spgc.sys The system cannot find the file specified. !
.rsrc C:\WINDOWS\system32\drivers\pciide.sys entry point in ".rsrc" section [0xBA670814]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB7F6A360, 0x35483F, 0xE8000020]
.text USBPORT.SYS!DllUnload B7F4A8AC 5 Bytes JMP 89BA01D8
.text ay3b6lfo.SYS B7BEF386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ay3b6lfo.SYS B7BEF3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ay3b6lfo.SYS B7BEF3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ay3b6lfo.SYS B7BEF3C9 1 Byte [2E]
.text ay3b6lfo.SYS B7BEF3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[260] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\WINDOWS\Explorer.EXE[320] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F6000A
.text C:\WINDOWS\Explorer.EXE[320] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00F7000A
.text C:\WINDOWS\Explorer.EXE[320] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00D4000C
.text C:\WINDOWS\System32\svchost.exe[1660] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00EE000A
.text C:\WINDOWS\System32\svchost.exe[1660] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00EF000A
.text C:\WINDOWS\System32\svchost.exe[1660] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00D9000C
.text C:\WINDOWS\System32\svchost.exe[1660] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 010D000A
.text C:\WINDOWS\system32\wuauclt.exe[2432] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F9000A
.text C:\WINDOWS\system32\wuauclt.exe[2432] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00FA000A
.text C:\WINDOWS\system32\wuauclt.exe[2432] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00F8000C
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] spgc.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] spgc.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] spgc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] spgc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] spgc.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] spgc.sys
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\ay3b6lfo.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89E551F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \Driver\PCI_PNP5630 \Device\00000043 spgc.sys
Device \Driver\usbuhci \Device\USBPDO-0 89B9F1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89DE31F8
Device \Driver\dmio \Device\DmControl\DmConfig 89DE31F8
Device \Driver\dmio \Device\DmControl\DmPnP 89DE31F8
Device \Driver\dmio \Device\DmControl\DmInfo 89DE31F8
Device \Driver\usbuhci \Device\USBPDO-1 89B9F1F8
Device \Driver\usbuhci \Device\USBPDO-2 89B9F1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{892781EA-94A8-4939-B829-BD66217FEE7D} 894321F8
Device \Driver\usbehci \Device\USBPDO-3 89B701F8
Device \Driver\usbuhci \Device\USBPDO-4 89B9F1F8
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \Driver\usbuhci \Device\USBPDO-5 89B9F1F8
Device \Driver\usbuhci \Device\USBPDO-6 89B9F1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89E571F8
Device \Driver\usbehci \Device\USBPDO-7 89B701F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89E571F8
Device \Driver\Cdrom \Device\CdRom0 89B521F8
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort0 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 89CDBAEA
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort1 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort2 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort3 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort4 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort4 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort5 89CDBAEA
Device \Driver\atapi \Device\Ide\IdePort5 [B9DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 89E571F8
Device \Driver\Cdrom \Device\CdRom1 89B521F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 894321F8
Device \Driver\NetBT \Device\NetbiosSmb 894321F8
Device \Driver\sptd \Device\2056155630 spgc.sys
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \Driver\usbuhci \Device\USBFDO-0 89B9F1F8
Device \Driver\usbstor \Device\0000007a 89A08500
Device \Driver\usbuhci \Device\USBFDO-1 89B9F1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8911C1F8
Device \Driver\usbuhci \Device\USBFDO-2 89B9F1F8
Device \Driver\usbstor \Device\0000007c 89A08500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8911C1F8
Device \Driver\usbehci \Device\USBFDO-3 89B701F8
Device \Driver\usbstor \Device\0000007d 89A08500
Device \Driver\usbuhci \Device\USBFDO-4 89B9F1F8
Device \Driver\Ftdisk \Device\FtControl 89E571F8
Device \Driver\usbstor \Device\0000007e 89A08500
Device \Driver\usbuhci \Device\USBFDO-5 89B9F1F8
Device \Driver\usbstor \Device\0000007f 89A08500
Device \Driver\usbuhci \Device\USBFDO-6 89B9F1F8
Device \Driver\usbehci \Device\USBFDO-7 89B701F8
Device \Driver\ay3b6lfo \Device\Scsi\ay3b6lfo1Port6Path0Target0Lun0 89A641F8
Device \Driver\ay3b6lfo \Device\Scsi\ay3b6lfo1 89A641F8
Device \FileSystem\Cdfs \Cdfs 89A09500
Device \Device\Ide\IdeDeviceP3T0L0-12 -> \??\IDE#DiskWDC_WD6400AACS-00G8B1___________________05.04C05#5&643f929&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7A 0xE9 0x89 0x07 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x03 0x43 0x4E 0x64 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0xE2 0xC5 0xB1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7A 0xE9 0x89 0x07 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x03 0x43 0x4E 0x64 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0xE2 0xC5 0xB1 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E18336E1-CC46-01E8-0635-1D16F4E8C193}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E18336E1-CC46-01E8-0635-1D16F4E8C193}@iaikjpapngokmnajhc 0x6A 0x61 0x6E 0x6F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E18336E1-CC46-01E8-0635-1D16F4E8C193}@haclppjemnmphfjm 0x6A 0x61 0x6E 0x6F ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sectors 1250263472 (+254): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\pciide.sys suspicious modification; TDL3 <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----