GMER log
GMER 1.0.15.15077 [4nrkg1h5.exe] -
http://www.gmer.net
Rootkit scan 2009-08-26 15:11:29
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
Code 861916D8 ZwEnumerateKey
Code 861906D8 ZwFlushInstructionCache
Code 861936D6 ZwSaveKey
Code 861926D6 ZwSaveKeyEx
Code 861946D6 IofCallDriver
Code 861956D6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 861946DB
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 861956DB
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.exe[504] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 00A1000A
.text C:\WINDOWS\system32\svchost.exe[944] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[944] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[944] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1044] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1044] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1044] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\System32\svchost.exe[1148] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\System32\svchost.exe[1148] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\System32\svchost.exe[1148] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1220] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1220] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1220] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[1504] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[1504] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[1504] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\spoolsv.exe[1592] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\spoolsv.exe[1592] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\spoolsv.exe[1592] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1720] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1720] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1720] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[1736] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[1736] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[1736] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1768] USER32.dll!TrackMouseEvent + 94 7E41DD7A 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1768] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\77748A8C.x86.dll
.text C:\WINDOWS\system32\svchost.exe[1768] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\77748A8C.x86.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\svchost.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1044] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1044] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\System32\svchost.exe[1148] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\System32\svchost.exe[1148] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1220] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1220] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\iTunes\iTunesHelper.exe[1504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\iTunes\iTunesHelper.exe[1504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\spoolsv.exe[1592] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\spoolsv.exe[1592] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1720] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1720] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\Bonjour\mDNSResponder.exe[1736] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\Program Files\Bonjour\mDNSResponder.exe[1736] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[1768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\77748A8C.x86.dll
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [944] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1044] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1148] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1220] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1460] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [1504] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1592] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [1720] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [1736] 0x35670000
Library \\?\globalroot\Device\__max++>\77748A8C.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1768] 0x35670000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kbiwkmsswuypdw.sys (*** hidden *** ) [SYSTEM] kbiwkmlnmbftko <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko@imagepath \systemroot\system32\drivers\kbiwkmsswuypdw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main@aid 20029
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmsswuypdw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmqipyviyq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmxfubsdnq.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmwbkfceep.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmlnmbftko\modules@kbiwkm.dat \systemroot\system32\kbiwkmphqbyexm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko@imagepath \systemroot\system32\drivers\kbiwkmsswuypdw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main@aid 20029
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmsswuypdw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmqipyviyq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmxfubsdnq.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmwbkfceep.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmlnmbftko\modules@kbiwkm.dat \systemroot\system32\kbiwkmphqbyexm.dat
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
---- Files - GMER 1.0.15 ----
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\Dark 0 bytes
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\LIGHT 0 bytes
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\Pattern 0 bytes
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\PlainLrgGrout 0 bytes
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\PlainSm45 0 bytes
File C:\Old Hard Drive July 2004\Program Files\Common Files\Microsoft Shared\Artgalry\PlainSmGrout 0 bytes
File C:\old_hard_drive_April_2008\Documents and Settings\SAYER\Application Data\Microsoft\Common 0 bytes
File C:\old_hard_drive_April_2008\Documents and Settings\SAYER\Application Data\Microsoft\Dreamweaver MX 2004 0 bytes
File C:\old_hard_drive_April_2008\Documents and Settings\SAYER\Application Data\Microsoft\Flash Player 0 bytes
File C:\old_hard_drive_April_2008\Documents and Settings\SAYER\Application Data\Microsoft\Shockwave Player 0 bytes
---- EOF - GMER 1.0.15 ----