GMER 1.0.15.14966 -
http://www.gmer.net
Rootkit scan 2009-04-24 06:30:31
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwClose [0xF871A818]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreateKey [0xF871A7D0]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xF870EA20]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF870F2A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF871A910]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xF871A794]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xF870F2C8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryValueKey [0xF871A866]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xF871A0B0]
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 12A 804E4964 4 Bytes JMP 9A0CF870
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 82F6E228
Device \FileSystem\Fastfat \FatCdrom 82B51A10
Device \Driver\ACPI \Device\00000043 82C965A0
Device \Driver\ACPI \Device\00000044 82C965A0
Device \Driver\ACPI \Device\00000053 82C965A0
Device \Driver\ACPI \Device\00000054 82C965A0
Device \Driver\ACPI \Device\00000060 82C965A0
Device \Driver\ACPI \Device\00000055 82C965A0
Device \Driver\ACPI \Device\00000061 82C965A0
Device \Driver\ACPI \Device\00000062 82C965A0
Device \Driver\ACPI \Device\00000049 82C965A0
Device \Driver\ACPI \Device\00000058 82C965A0
Device \Driver\Cdrom \Device\CdRom0 82E29E08
Device \Driver\Cdrom \Device\CdRom1 82E29E08
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 82E29198
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 82E29198
Device \Driver\atapi \Device\Ide\IdePort0 82E29198
Device \Driver\atapi \Device\Ide\IdePort1 82E29198
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f 82E29198
Device \Driver\Cdrom \Device\CdRom2 82E29E08
Device \Driver\ACPI \Device\0000004a 82C965A0
Device \Driver\ACPI \Device\0000004b 82C965A0
Device \Driver\ACPI \Device\0000004c 82C965A0
Device \Driver\ACPI \Device\0000004d 82C965A0
Device \Driver\ACPI \Device\0000004e 82C965A0
Device \Driver\ACPI \Device\0000005d 82C965A0
Device \Driver\ACPI \Device\0000005e 82C965A0
Device \FileSystem\Npfs \Device\NamedPipe 82D9A388
Device \FileSystem\Msfs \Device\Mailslot 82D9B740
Device \Driver\d347prt \Device\Scsi\d347prt1Port2Path0Target0Lun0 82E03D50
Device \Driver\d347prt \Device\Scsi\d347prt1 82E03D50
Device \FileSystem\Fastfat \Fat 82B51A10
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 82D9E030
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 82D9E030
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 82D9E030
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 82D9E030
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 82D9E030
Device \FileSystem\Cdfs \Cdfs 82D96280
---- Modules - GMER 1.0.15 ----
Module _________ F86C5000-F86DD000 (98304 bytes)
---- Threads - GMER 1.0.15 ----
Thread System [4:220] 82C7D137
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] icvhhpb <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@DisplayName Center Boot
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb@Description Protects your computer from spyware
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb\Parameters
Reg HKLM\SYSTEM\ControlSet001\Services\icvhhpb\Parameters@ServiceDll C:\WINDOWS\system32\xqatbn.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z0 0xA6 0xDC 0xFA 0xC3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@DisplayName Center Boot
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb@Description Protects your computer from spyware
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\icvhhpb\Parameters@ServiceDll C:\WINDOWS\system32\xqatbn.dll
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@DisplayName Center Boot
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb@Description Protects your computer from spyware
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb\Parameters
Reg HKLM\SYSTEM\ControlSet004\Services\icvhhpb\Parameters@ServiceDll C:\WINDOWS\system32\xqatbn.dll
---- EOF - GMER 1.0.15 ----