GMER 1.0.15.15640 - http://www.gmer.net Rootkit scan 2011-07-12 11:44:59 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500325AS rev.0002SDM1 Running: jfnkdt99.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\kxriafoc.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKey + 13C1 8384D339 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83886D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9B9B1300, 0x1B7E, 0xE8000020] PAGE spsys.sys!?SPRevision@@3PADA + 4F90 B3C52000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...] PAGE spsys.sys!?SPRevision@@3PADA + 50B3 B3C52123 486 Bytes [D5, C4, B3, FE, 05, 34, D5, ...] PAGE spsys.sys!?SPRevision@@3PADA + 529A B3C5230A 142 Bytes [C4, B3, 3B, 08, 77, 04, 3B, ...] PAGE spsys.sys!?SPRevision@@3PADA + 5329 B3C52399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...] PAGE spsys.sys!?SPRevision@@3PADA + 538F B3C523FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...] PAGE ... ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1660] kernel32.dll!SetUnhandledExceptionFilter 76D93D01 4 Bytes [C2, 04, 00, 00] ---- Devices - GMER 1.0.15 ---- Device \Driver\ACPI_HAL \Device\000001ca halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) Device \Driver\BTHUSB \Device\000001f7 bthport.sys (Driver til Bluetooth-bus/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) Device \Driver\BTHUSB \Device\000001f9 bthport.sys (Driver til Bluetooth-bus/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filsystem Filterstyring/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind ????ab????????????X??????d??????6-21-2006???????DE??Net??????????????.???e???????????????????????????&??Net?????????????????????11???????????????????????????????????????????????h?????? ,??????Root\*6TO4MP\0018???????????????????????????????????????? ???????????????????3????????"???a?????????????????????????????????????????????Root\*6TO4MP\0017???????????????Microsoft???Microsoft???????????? P??????4?????50???11??????? ???????0???????????d??????????????????\\?\Root#*6TO4MP#0016#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{E98D48A6-11B5-48A3-9BEB-2AB571121589}??????????????????????????????????????????????f????????????????????????????????????????`?????????????*6to4mp??????????????}???e??????AP??????????????????????????????????????????????ls????$??????????????????????%??????????11?FD ??\\?\Root#*6TO4MP#0015#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{2E088C97-76D1-4730-A5FE-46A6C7B6E6D1}???????????????X??????n??????????????????????????????t???????????????s?????$?????????????????Root\*6TO4MP\0019???????tunnel???????????y? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Route ????????? ?????????????????????1????????????????????????????? "?????????????????ndis5_ip6_tunnel????????????????????????????????6.1.7600.16385???????????????????????????????????F??????2F??????????????????????????? ?????????????????????,?????????????????f????N??????8?????D?"??{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?{5A??? ???????1?????????????,????????$???? ???????B????????k???0???????l??? ???????k???????????k?,????????P????????????????????l????N??k????????D??????l?????k?&??{8ECC055D-047F-11D1-A537-0000F8753ED1}??????Security Processor Loader Driver??????b??s?????????e????LegacyDriver?e???????p???????k??????????????????????LegacyDriver?1??TCP/IP Registry Compatibility???y????l??? ???????k?????k?????k?,?????????????????????0??LegacyDriver?????l??? ???????k???????????k?,????????P???????????LegacyDriver??????N???????????Dyst?????k?&??LegacyDriver????Tcpip????????????l???????~???????????-??????Network?????Volume?etB??WinUsb?????????? ??????????s????{8ECC055D-047F-11D1-A537-0000F8753ED1}???????????o??volsnap?2C???????o??????p????l?????l?&??? ???????k?????k?????k?,??????????@??????????0??? ??k?????????0????? ???????k???????????k?,????????P?????????????N Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route ???t?????????z??????? ???????o???????????t??????????L????????????????o?????????e????????????????t?????????????????????????????????????????????????2??v????????h???????6???????????h??????????????y???????????????????????t??? ???????o???????????t?,????????^???????M????????u??????????????t????????????????????y?????????????g????????????? ???????o???????????t??????????\???????????@%systemroot%\system32\wkssvc.dll,-1007??????????????????????????????y????`????????????e??????