Log 2 of 4
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-08-28 14:46:09
Windows 5.1.2600 Service Pack 3
Running: 1le6bgmg.exe; Driver: C:\DOCUME~1\Claire\LOCALS~1\Temp\kgwyifow.sys
---- System - GMER 1.0.15 ----
SSDT 823C2DD0 ZwAlertResumeThread
SSDT 823C2EB0 ZwAlertThread
SSDT 823AC700 ZwAllocateVirtualMemory
SSDT 823C2578 ZwAssignProcessToJobObject
SSDT 82C6FAC8 ZwConnectPort
SSDT F8CCF83E ZwCreateKey
SSDT 823C2B20 ZwCreateMutant
SSDT 823C2398 ZwCreateSymbolicLinkObject
SSDT F8CCF834 ZwCreateThread
SSDT 823C2658 ZwDebugActiveProcess
SSDT F8CCF843 ZwDeleteKey
SSDT F8CCF84D ZwDeleteValueKey
SSDT 823AC8D0 ZwDuplicateObject
SSDT 823AC520 ZwFreeVirtualMemory
SSDT 823C2C10 ZwImpersonateAnonymousToken
SSDT 823C2CF0 ZwImpersonateThread
SSDT 82C6F838 ZwLoadDriver
SSDT F8CCF852 ZwLoadKey
SSDT 823AC420 ZwMapViewOfSection
SSDT 823C2A40 ZwOpenEvent
SSDT F8CCF820 ZwOpenProcess
SSDT 823AC7F0 ZwOpenProcessToken
SSDT 823C2880 ZwOpenSection
SSDT F8CCF825 ZwOpenThread
SSDT 823C2488 ZwProtectVirtualMemory
SSDT F8CCF85C ZwReplaceKey
SSDT F8CCF857 ZwRestoreKey
SSDT 823AFB38 ZwResumeThread
SSDT 823AC170 ZwSetContextThread
SSDT 823AC250 ZwSetInformationProcess
SSDT 823C2738 ZwSetSystemInformation
SSDT F8CCF848 ZwSetValueKey
SSDT 823C2960 ZwSuspendProcess
SSDT 823C2F90 ZwSuspendThread
SSDT 823ACBE8 ZwTerminateProcess
SSDT 823AC090 ZwTerminateThread
SSDT 823AC340 ZwUnmapViewOfSection
SSDT 823AC610 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 98 804E2704 1 Byte [78]
.text ntoskrnl.exe!_abnormal_termination + 450 804E2ABC 8 Bytes CALL 10D0658C
? SYMEFA.SYS The system cannot find the file specified. !
.rsrc C:\WINDOWS\System32\DRIVERS\redbook.sys entry point in ".rsrc" section [0xF88DEF94]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0132000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0133000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0131000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 02B0003A
.text C:\WINDOWS\Explorer.EXE[348] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[348] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[348] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1216] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1044721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\WINDOWS\System32\svchost.exe[1732] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0092000A
.text C:\WINDOWS\System32\svchost.exe[1732] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0093000A
.text C:\WINDOWS\System32\svchost.exe[1732] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0091000C
.text C:\WINDOWS\System32\svchost.exe[1732] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 029A000A
.text C:\WINDOWS\System32\svchost.exe[1732] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00AF000A
.text C:\WINDOWS\system32\SearchIndexer.exe[2248] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device -> \Driver\atapi \Device\Harddisk0\DR0 82D0BEC5
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\System32\DRIVERS\redbook.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----