GMER 1.0.15.15163 -
http://www.gmer.net
Rootkit scan 2009-10-24 16:01:49
Windows 5.1.2600 Service Pack 3
Running: gm-er.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\fweiipod.sys
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF750F87E]
SSDT \SystemRoot\System32\Drivers\Beep.SYS ZwQuerySystemInformation [0xF76011A2]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF750FBFE]
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) ZwCreateKey [0xF74C2C8E]
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) ZwEnumerateKey [0xF74C2D13]
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) ZwOpenKey [0xF74C2C10]
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) ZwQueryDirectoryFile [0xF74C2999]
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) IoCreateFile
Code 32ba6ee53eb113fe6f9cfec56b71c99f.sys (ckmd/Noves Inc) NtQueryDirectoryFile
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys (*** hidden *** ) [BOOT] 32ba6ee53eb113fe6f9cfec56b71c99f <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=32ba6ee53eb113fe6f9cfec56b71c99f&path=system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys&wmid=Dkx003&idate=2009-02-24 09:01:06:081&last_download_time=2009-10-24 11:42:14.984&first_skip=1&last_update_ip_pos=0
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Type 1
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Start 0
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Tag 6
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ImagePath system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@DisplayName 32ba6ee53eb113fe6f9cfec56b71c99f
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Group System Bus Extender
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=32ba6ee53eb113fe6f9cfec56b71c99f&path=system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys&wmid=Dkx003&idate=2009-02-24 09:01:06:081&last_download_time=2009-2-24 9:4:6.626&first_skip=1
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Tag 6
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ImagePath system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@DisplayName 32ba6ee53eb113fe6f9cfec56b71c99f
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Group System Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=32ba6ee53eb113fe6f9cfec56b71c99f&path=system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys&wmid=Dkx003&idate=2009-02-24 09:01:06:081&last_download_time=2009-2-24 9:4:6.626&first_skip=1
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Start 0
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Tag 6
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ImagePath system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@DisplayName 32ba6ee53eb113fe6f9cfec56b71c99f
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Group System Bus Extender
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\32ba6ee53eb113fe6f9cfec56b71c99f&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=32ba6ee53eb113fe6f9cfec56b71c99f&path=system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys&wmid=Dkx003&idate=2009-02-24 09:01:06:081&last_download_time=2009-2-24 9:4:6.626&first_skip=1
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Type 1
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Start 0
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Tag 6
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@ImagePath system32\32ba6ee53eb113fe6f9cfec56b71c99f.sys
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@DisplayName 32ba6ee53eb113fe6f9cfec56b71c99f
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f@Group System Bus Extender
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\32ba6ee53eb113fe6f9cfec56b71c99f\Security@Security 0x01 0x00 0x14 0x80 ...
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8GDVJZSU\base_grass[1].css 0 bytes
File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8GDVJZSU\jump1[1].htm 0 bytes
File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8GDVJZSU\index[1].htm 0 bytes
---- EOF - GMER 1.0.15 ----