GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-02-19 10:14:17 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_HD503HI rev.1AJ100E4 Running: uo0sxrg2.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pwkirpow.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB362C380, 0x3DF295, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\System32\svchost.exe[1128] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 01FD9DC2 .text C:\WINDOWS\System32\svchost.exe[1128] NETAPI32.dll!NetpwPathCanonicalize 6FF4A3A9 5 Bytes JMP 01FD9D62 .text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 00829DC2 .text C:\Program Files\Mozilla Firefox\firefox.exe[2468] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01261B30 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2748] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1044A4E7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2748] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 1044AABD C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Services - GMER 1.0.15 ---- Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] fsoum <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] lkcuh <-- ROOTKIT !!! ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@DisplayName Installer Network Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@Type 32 Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@ErrorControl 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@ObjectName LocalSystem Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum@Description Us?uga wykrywa i monitoruje urz?dzenia CUE w systemie. Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum\Parameters Reg HKLM\SYSTEM\CurrentControlSet\Services\fsoum\Parameters@ServiceDll C:\WINDOWS\system32\sbdae.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@DisplayName Image Update Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@Type 32 Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@ErrorControl 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@ObjectName LocalSystem Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh@Description ?aduje pliki do pami?ci w celu p??niejszego wydrukowania. Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh\Parameters Reg HKLM\SYSTEM\CurrentControlSet\Services\lkcuh\Parameters@ServiceDll C:\WINDOWS\system32\sbdae.dll Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@DisplayName Installer Network Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@Type 32 Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@Start 2 Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@ErrorControl 0 Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet002\Services\fsoum@Description Us?uga wykrywa i monitoruje urz?dzenia CUE w systemie. Reg HKLM\SYSTEM\ControlSet002\Services\fsoum\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\fsoum\Parameters@ServiceDll C:\WINDOWS\system32\sbdae.dll Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@DisplayName Image Update Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@Type 32 Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@Start 2 Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@ErrorControl 0 Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh@Description ?aduje pliki do pami?ci w celu p??niejszego wydrukowania. Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\lkcuh\Parameters@ServiceDll C:\WINDOWS\system32\sbdae.dll ---- EOF - GMER 1.0.15 ----