GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-10-27 23:22:21
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT sptd.sys ZwCreateKey [0xF84BE0B0]
SSDT sptd.sys ZwEnumerateKey [0xF84C3A92]
SSDT sptd.sys ZwEnumerateValueKey [0xF84C3E20]
SSDT sptd.sys ZwOpenKey [0xF84BE090]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xF8C8A8AC]
SSDT sptd.sys ZwQueryKey [0xF84C3EF8]
SSDT sptd.sys ZwQueryValueKey [0xF84C3D78]
SSDT sptd.sys ZwSetValueKey [0xF84C3F8A]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xF8C8A812]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F81868AC 5 Bytes JMP 83176568
? System32\Drivers\aljrjanm.SYS The system cannot find the file specified. !
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F84D297E] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F84D292A] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F84EDB4E] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F84D297E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F84BEAB4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F84BEBFA] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F84BEB7C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F84BF728] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F84BF5FE] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F84D1C5A] sptd.sys
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 833D31E8
Device \FileSystem\Fastfat \FatCdrom 825411E8
Device \FileSystem\Udfs \UdfsCdRom 82FEA980
Device \FileSystem\Udfs \UdfsDisk 82FEA980
Device \Driver\NetBT \Device\NetBT_Tcpip_{385D0096-110C-4A30-ADB7-56097151D362} 82590490
Device \Driver\usbuhci \Device\USBPDO-0 83156980
Device \Driver\usbuhci \Device\USBPDO-1 83156980
Device \Driver\usbuhci \Device\USBPDO-2 83156980
Device \Driver\usbuhci \Device\USBPDO-3 83156980
Device \Driver\usbehci \Device\USBPDO-4 831771E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 833611E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 833611E8
Device \Driver\sysaudio \Device\sysaudio ED7840F7
Device \Driver\Cdrom \Device\CdRom0 830B91E8
Device \Driver\Cdrom \Device\CdRom1 830B91E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 833611E8
Device \Driver\Cdrom \Device\CdRom2 830B91E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 82590490
Device \Driver\NetBT \Device\NetbiosSmb 82590490
Device \Driver\PCI_NTPNP3820 \Device\0000005a sptd.sys
Device \Driver\USBSTOR \Device\00000089 825B21E8
Device \Driver\usbuhci \Device\USBFDO-0 83156980
Device \Driver\usbuhci \Device\USBFDO-1 83156980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 825801E8
Device \Driver\usbuhci \Device\USBFDO-2 83156980
Device \FileSystem\MRxSmb \Device\LanmanRedirector 825801E8
Device \Driver\usbuhci \Device\USBFDO-3 83156980
Device \Driver\usbehci \Device\USBFDO-4 831771E8
Device \Driver\Ftdisk \Device\FtControl 833611E8
Device \Driver\USBSTOR \Device\0000008b 825B21E8
Device \Driver\aljrjanm \Device\Scsi\aljrjanm1 830AB980
Device \Driver\aljrjanm \Device\Scsi\aljrjanm1Port2Path0Target0Lun0 830AB980
Device \FileSystem\Fastfat \Fat 825411E8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 82FDD1E8
Device \FileSystem\Cdfs \Cdfs ED7A5BCE
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0x5C 0x26 0x13 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x52 0xC9 0x45 0xA9 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x10 0xB1 0xDC 0xFD ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x15 0xF2 0x38 0x7F ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9C 0x06 0xD7 0xA3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSpxfe.sys
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSpxfe.sys
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitu.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtpe.dat
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSyoqm.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnpur.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxgp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSihyf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -726238967
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1683118007
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0x5C 0x26 0x13 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x52 0xC9 0x45 0xA9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x5D 0xE6 0x09 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x15 0xF2 0x38 0x7F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9C 0x06 0xD7 0xA3 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0x5C 0x26 0x13 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x52 0xC9 0x45 0xA9 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x10 0xB1 0xDC 0xFD ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x15 0xF2 0x38 0x7F ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9C 0x06 0xD7 0xA3 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0x5C 0x26 0x13 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x52 0xC9 0x45 0xA9 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x5D 0xE6 0x09 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x15 0xF2 0x38 0x7F ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9C 0x06 0xD7 0xA3 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocServer32@ C:\WINDOWS\System32\MFC42u.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocServer32@InprocServer32 DlIn'Z~ac@OcUSWt[Di'NortonAntiVirus>=3&5,B^pf(V%eqFgkW_B?ClWaQ6XiR?P}Amov]r)1AnimationShop3_TryAndBuy>=3&5,B^pf(V%eqFgkW_B?sa'XjJ2^n?t(dx_CVLkfPaintShopPhotoAlbum>=%YAYRcuf(mdaqF-Q9q.?sa'XjJ2^n?t(dx_CVLkfPaintShopPhotoAlbum>=3&5,B^pf(V%eqFgkW_B?$cCq9dWpp8H]DsMG=54JDellAlert>=3&5,B^pf(V%eqFgkW_B?nnPl(}XP9?_,O3?,aFS^>=3&5,B^pf(V%eqFgkW_B?
---- EOF - GMER 1.0.14 ----