GMER 1.0.15.15087 -
http://www.gmer.netRootkit scan 2009-09-27 17:54:27
Windows 5.1.2600 Service Pack 3
Running: 91ndnxp1.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pwddqpod.sys
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF931687E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF9316BFE]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[484] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 04561047 C:\WINDOWS\mark_32.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[484] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[484] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs naiavf5x.sys (Anti-Virus File System Filter Driver/Network Associates, Inc.)
Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\rotscxpfdbwwgi.sys (*** hidden *** ) [SYSTEM] rotscxnevmkost <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost@imagepath \systemroot\system32\drivers\rotscxpfdbwwgi.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main\injector@* rotscxwsp8x.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxpfdbwwgi.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxcmd.dll \systemroot\system32\rotscxsmcreexu.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxlog.dat \systemroot\system32\rotscxwqpuycbd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxwsp.dll \systemroot\system32\rotscxxteravqq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscx.dat \systemroot\system32\rotscxuxnrirfj.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxwsp8.dll \systemroot\system32\rotscxuyxexwkb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxnevmkost\modules@rotscxwsp8x.dll \systemroot\system32\rotscxovhkwnvd.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost@imagepath \systemroot\system32\drivers\rotscxpfdbwwgi.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main\injector@* rotscxwsp8x.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxpfdbwwgi.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxcmd.dll \systemroot\system32\rotscxsmcreexu.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxlog.dat \systemroot\system32\rotscxwqpuycbd.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxwsp.dll \systemroot\system32\rotscxxteravqq.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscx.dat \systemroot\system32\rotscxuxnrirfj.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxwsp8.dll \systemroot\system32\rotscxuyxexwkb.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxnevmkost\modules@rotscxwsp8x.dll \systemroot\system32\rotscxovhkwnvd.dll
---- EOF - GMER 1.0.15 ----