Gars
Posts: 506 +98
Hello and thanks for your help,
My neighbor running DualCore/2gb on fully patched XP SP3
MSE is on the front of defense and the Windows firewall is running.
We have a problem with the update of MSE, also Skype refusing to sign in.
Here is the logs of MBAM, GMER and DDs:
MBAM log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5376
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
22.12.2010 г. 19:53:44
mbam-log-2010-12-22 (19-53-44).txt
Scan type: Quick scan
Objects scanned: 134345
Time elapsed: 2 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
_____________________________
GMER log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-22 19:59:19
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 SAMSUNG_HD321KJ rev.CP100-10
Running: echdjhfk.exe; Driver: C:\DOCUME~1\Mim's\LOCALS~1\Temp\pxtdypob.sys
---- System - GMER 1.0.15 ----
SSDT spda.sys ZwCreateKey [0xB7EA80E0]
SSDT spda.sys ZwEnumerateKey [0xB7EC6CA2]
SSDT spda.sys ZwEnumerateValueKey [0xB7EC7030]
SSDT spda.sys ZwOpenKey [0xB7EA80C0]
SSDT spda.sys ZwQueryKey [0xB7EC7108]
SSDT spda.sys ZwQueryValueKey [0xB7EC6F88]
SSDT spda.sys ZwSetValueKey [0xB7EC719A]
INT 0x62 ? 89E54BF8
INT 0x63 ? 89E54BF8
INT 0x63 ? 89E54BF8
INT 0x63 ? 89BB1BF8
INT 0x63 ? 89BB1BF8
INT 0x63 ? 89E54BF8
INT 0x73 ? 89DE5BF8
INT 0x82 ? 89E54BF8
INT 0x84 ? 89BB1BF8
INT 0xA4 ? 89BB1BF8
INT 0xB4 ? 89BB1BF8
---- Kernel code sections - GMER 1.0.15 ----
? spda.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6B2D3A0, 0x59FFE5, 0xE8000020]
.text USBPORT.SYS!DllUnload B6B0D8AC 5 Bytes JMP 89BB11D8
.rsrc C:\WINDOWS\system32\DRIVERS\cdrom.sys entry point in ".rsrc" section [0xB81F6394]
.text ajffjo66.SYS B69FB386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ajffjo66.SYS B69FB3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ajffjo66.SYS B69FB3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ajffjo66.SYS B69FB3C9 1 Byte [2E]
.text ajffjo66.SYS B69FB3C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DD000A
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DE000A
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00DC000C
.text C:\WINDOWS\System32\svchost.exe[1188] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E6000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0139000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 013A000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00FF000C
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EA9040] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EA913C] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EA90BE] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EA97FC] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EA96D2] spda.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EB9048] spda.sys
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfAcquireSpinLock] C0840CEC
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_UCHAR] 053C0D74
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KeGetCurrentIrql] 57B80974
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfRaiseIrql] 8B000000
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfLowerIrql] 56C35DE5
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!HalGetInterruptVector] 8D08758B
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!HalTranslateBusAddress] 8D51FC4D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KeStallExecutionProcessor] 8D52FD55
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfReleaseSpinLock] 8D51FE4D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 8D52FF55
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_USHORT] 8D51F84D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 5052F455
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!WRITE_PORT_UCHAR] EACAE856
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[WMILIB.SYS!WmiSystemControl] 0FC08520
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[WMILIB.SYS!WmiCompleteRequest] 0001B185
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89DE11F8
Device \FileSystem\Fastfat \FatCdrom 89C30500
Device \Driver\sptd \Device\170484184 spda.sys
Device \Driver\usbuhci \Device\USBPDO-0 89BB01F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89DE31F8
Device \Driver\dmio \Device\DmControl\DmConfig 89DE31F8
Device \Driver\dmio \Device\DmControl\DmPnP 89DE31F8
Device \Driver\dmio \Device\DmControl\DmInfo 89DE31F8
Device \Driver\usbuhci \Device\USBPDO-1 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-2 89BB01F8
Device \Driver\PCI_PNP7934 \Device\00000046 spda.sys
Device \Driver\usbehci \Device\USBPDO-3 89B8A1F8
Device \Driver\usbuhci \Device\USBPDO-4 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-5 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-6 89BB01F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89E551F8
Device \Driver\usbehci \Device\USBPDO-7 89B8A1F8
Device \Driver\Cdrom \Device\CdRom0 89B211F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89E551F8
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort0 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort1 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort2 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort3 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-12 89AB7AEA
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 89B211F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8912B1F8
Device \Driver\NetBT \Device\NetbiosSmb 8912B1F8
Device \Driver\usbuhci \Device\USBFDO-0 89BB01F8
Device \Driver\usbuhci \Device\USBFDO-1 89BB01F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 891261F8
Device \Driver\usbuhci \Device\USBFDO-2 89BB01F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 891261F8
Device \Driver\usbehci \Device\USBFDO-3 89B8A1F8
Device \Driver\usbuhci \Device\USBFDO-4 89BB01F8
Device \Driver\Ftdisk \Device\FtControl 89E551F8
Device \Driver\usbuhci \Device\USBFDO-5 89BB01F8
Device \Driver\usbuhci \Device\USBFDO-6 89BB01F8
Device \Driver\usbehci \Device\USBFDO-7 89B8A1F8
Device \Driver\ajffjo66 \Device\Scsi\ajffjo661 89A651F8
Device \Driver\ajffjo66 \Device\Scsi\ajffjo661Port5Path0Target0Lun0 89A651F8
Device \Driver\JRAID \Device\Scsi\JRAID1 89DE21F8
Device \FileSystem\Fastfat \Fat 89C30500
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 899AC500
Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskSAMSUNG_HD321KJ_________________________CP100-10#3053514d314a5044303437313832202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x63 0x3D 0x91 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x11 0x38 0x8E 0x9A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x60 0x6A 0xE2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x63 0x3D 0x91 0xCA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x11 0x38 0x8E 0x9A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x60 0x6A 0xE2 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sectors 625142192 (+254): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\DRIVERS\cdrom.sys suspicious modification; TDL3 <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
______________________________
My neighbor running DualCore/2gb on fully patched XP SP3
MSE is on the front of defense and the Windows firewall is running.
We have a problem with the update of MSE, also Skype refusing to sign in.
Here is the logs of MBAM, GMER and DDs:
MBAM log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5376
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
22.12.2010 г. 19:53:44
mbam-log-2010-12-22 (19-53-44).txt
Scan type: Quick scan
Objects scanned: 134345
Time elapsed: 2 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
_____________________________
GMER log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-22 19:59:19
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 SAMSUNG_HD321KJ rev.CP100-10
Running: echdjhfk.exe; Driver: C:\DOCUME~1\Mim's\LOCALS~1\Temp\pxtdypob.sys
---- System - GMER 1.0.15 ----
SSDT spda.sys ZwCreateKey [0xB7EA80E0]
SSDT spda.sys ZwEnumerateKey [0xB7EC6CA2]
SSDT spda.sys ZwEnumerateValueKey [0xB7EC7030]
SSDT spda.sys ZwOpenKey [0xB7EA80C0]
SSDT spda.sys ZwQueryKey [0xB7EC7108]
SSDT spda.sys ZwQueryValueKey [0xB7EC6F88]
SSDT spda.sys ZwSetValueKey [0xB7EC719A]
INT 0x62 ? 89E54BF8
INT 0x63 ? 89E54BF8
INT 0x63 ? 89E54BF8
INT 0x63 ? 89BB1BF8
INT 0x63 ? 89BB1BF8
INT 0x63 ? 89E54BF8
INT 0x73 ? 89DE5BF8
INT 0x82 ? 89E54BF8
INT 0x84 ? 89BB1BF8
INT 0xA4 ? 89BB1BF8
INT 0xB4 ? 89BB1BF8
---- Kernel code sections - GMER 1.0.15 ----
? spda.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6B2D3A0, 0x59FFE5, 0xE8000020]
.text USBPORT.SYS!DllUnload B6B0D8AC 5 Bytes JMP 89BB11D8
.rsrc C:\WINDOWS\system32\DRIVERS\cdrom.sys entry point in ".rsrc" section [0xB81F6394]
.text ajffjo66.SYS B69FB386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ajffjo66.SYS B69FB3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ajffjo66.SYS B69FB3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ajffjo66.SYS B69FB3C9 1 Byte [2E]
.text ajffjo66.SYS B69FB3C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DD000A
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DE000A
.text C:\WINDOWS\System32\svchost.exe[1188] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00DC000C
.text C:\WINDOWS\System32\svchost.exe[1188] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E6000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0139000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 013A000A
.text C:\WINDOWS\Explorer.EXE[1980] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00FF000C
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EA9040] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EA913C] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EA90BE] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EA97FC] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EA96D2] spda.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EB9048] spda.sys
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfAcquireSpinLock] C0840CEC
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_UCHAR] 053C0D74
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KeGetCurrentIrql] 57B80974
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfRaiseIrql] 8B000000
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfLowerIrql] 56C35DE5
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!HalGetInterruptVector] 8D08758B
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!HalTranslateBusAddress] 8D51FC4D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KeStallExecutionProcessor] 8D52FD55
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!KfReleaseSpinLock] 8D51FE4D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 8D52FF55
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!READ_PORT_USHORT] 8D51F84D
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 5052F455
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[HAL.dll!WRITE_PORT_UCHAR] EACAE856
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[WMILIB.SYS!WmiSystemControl] 0FC08520
IAT \SystemRoot\System32\Drivers\ajffjo66.SYS[WMILIB.SYS!WmiCompleteRequest] 0001B185
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89DE11F8
Device \FileSystem\Fastfat \FatCdrom 89C30500
Device \Driver\sptd \Device\170484184 spda.sys
Device \Driver\usbuhci \Device\USBPDO-0 89BB01F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89DE31F8
Device \Driver\dmio \Device\DmControl\DmConfig 89DE31F8
Device \Driver\dmio \Device\DmControl\DmPnP 89DE31F8
Device \Driver\dmio \Device\DmControl\DmInfo 89DE31F8
Device \Driver\usbuhci \Device\USBPDO-1 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-2 89BB01F8
Device \Driver\PCI_PNP7934 \Device\00000046 spda.sys
Device \Driver\usbehci \Device\USBPDO-3 89B8A1F8
Device \Driver\usbuhci \Device\USBPDO-4 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-5 89BB01F8
Device \Driver\usbuhci \Device\USBPDO-6 89BB01F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89E551F8
Device \Driver\usbehci \Device\USBPDO-7 89B8A1F8
Device \Driver\Cdrom \Device\CdRom0 89B211F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89E551F8
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort0 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort1 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort2 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 89AB7AEA
Device \Driver\atapi \Device\Ide\IdePort3 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-12 89AB7AEA
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 [B7DFCB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 89B211F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8912B1F8
Device \Driver\NetBT \Device\NetbiosSmb 8912B1F8
Device \Driver\usbuhci \Device\USBFDO-0 89BB01F8
Device \Driver\usbuhci \Device\USBFDO-1 89BB01F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 891261F8
Device \Driver\usbuhci \Device\USBFDO-2 89BB01F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 891261F8
Device \Driver\usbehci \Device\USBFDO-3 89B8A1F8
Device \Driver\usbuhci \Device\USBFDO-4 89BB01F8
Device \Driver\Ftdisk \Device\FtControl 89E551F8
Device \Driver\usbuhci \Device\USBFDO-5 89BB01F8
Device \Driver\usbuhci \Device\USBFDO-6 89BB01F8
Device \Driver\usbehci \Device\USBFDO-7 89B8A1F8
Device \Driver\ajffjo66 \Device\Scsi\ajffjo661 89A651F8
Device \Driver\ajffjo66 \Device\Scsi\ajffjo661Port5Path0Target0Lun0 89A651F8
Device \Driver\JRAID \Device\Scsi\JRAID1 89DE21F8
Device \FileSystem\Fastfat \Fat 89C30500
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 899AC500
Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskSAMSUNG_HD321KJ_________________________CP100-10#3053514d314a5044303437313832202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x63 0x3D 0x91 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x11 0x38 0x8E 0x9A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x60 0x6A 0xE2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x63 0x3D 0x91 0xCA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x11 0x38 0x8E 0x9A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x60 0x6A 0xE2 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sectors 625142192 (+254): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\DRIVERS\cdrom.sys suspicious modification; TDL3 <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
______________________________