Step 3: GMER
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-08 20:19:00
Windows 6.1.7600
Running: 2ubqn33q.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\services\LanmanServer\Linkage@Bind ???M?M??@%SystemRoot%\system32\drivers\fltmgr.sys,-10000????????????????????????????????????t??????????????g?????M?M?M?M?M?M?M?M?M???????M??????p???system32\DRIVERS\kbdhid.sys?\kbdhid.sys???????(??M?????????e????Keyboard Port??????????????g?????????????????????M?M?M?M?M?M?M?????????????????e?????????M??????p???Cryptography??????:??M????????h?????System32\Drivers\ksecpkg.sys????????????????????????????????????t??????????????g?????????????????????M?M?M?M?M?M?M?????????????????e??????0??M?????????e????Kernel Streaming Thunks??????????M??????p???PNP Filter????????R??M????????h?????\SystemRoot\system32\drivers\ksthunk.sys????????????????????????????????????t????????????????????M?M?M?M?M?M?????????????u???????????.???????????/???????M??? ??????????????????????????????system32\DRIVERS\intelppm.sys?ntelppm.sys???? ???????????????????J?;????????????&???????????????????????system32\DRIVERS\kbdclass.sys?bdclass.sys????????????????????????????????L???????.?????M?M??????????????????????????????????????????????????g??????
Reg HKLM\SYSTEM\ControlSet001\services\LanmanServer\Linkage@Route ???M?M???M???????????????????????????????????????????????????????M???????????????M?L?M?M?M?M?M?M????????????????????????????????FSFilter Bottom???????????????????????????<??M????????h???????&??M?????????e????system32\drivers\fltmgr.sys???????b??M?????????n?????????????????????????????v???????G???????????e?????????nab???????M???????????????????N?N?N?N?N??? B??M??????????????CSCFlags=2048?MaxUses=4294967295?Path=C:\Users?Permissions=0?Remark=?ShareName=Users?Type=0?????CSCFlags=768?MaxUses=4294967295?Path=C:\Windows\system32\spool\drivers?Permissions=0?Remark=Printer Drivers?ShareName=print$?Type=0?????CSCFlags=0?MaxUses=4294967295?Path=W:\Games\Steam\steamapps\common\killingfloor?Permissions=0?Remark=?ShareName=killingfloor?Type=0??????????M???????????????????M?M?M?M?M?M??????0?@??????????????????????? ?????????????????????d??M??????s?????8??N????????h?????????t?????????????????????^??M?????????n????@%SystemRoot%\system32\drivers\fvevol.sys,-100???????M?M?M?M?M?M?M?M?????? ??J???C?????eE1???????????B??4c???M?
Reg HKLM\SYSTEM\ControlSet001\services\LanmanServer\Linkage@Export ???M?M????8??M????????h?????@%SystemRoot%\system32\drivers\http.sys,-1????????V??M?????????n????@%SystemRoot%\system32\drivers\http.sys,-2???????????????????????????????????????????M?M?M?M?M?M??????b??M?????????e????????????????t?????<??M????????h?????system32\drivers\RTKVHD64.sys?????F??M??????????????Service for Realtek HD Audio (WDM)??????cpu.inf_amd64_neutral_ae5de2e1bf2793c3?????????????????g?????M?M?M?M?M?M?M?Mel??? ???S??????????e????????????????????????e???????????l???????????????????M???}??sT???M?M?M?N?????????????o???????????????????*???*??CSCFlags=0?MaxUses=4294967295?Path=C:\Users\X-25M-WT\Shared?Permissions=9?ShareName=Shared?Type=0????????????M???.???g????\??M???????????M?N?N?N?N????.??M?????????e????Intel Processor Driver???????????M??????p???????????????????????????????????????????????? J??M??????????s?????<??M????????h???????,??M?????????e????r???Extended Base???????????????t?????N??M???????????d???N?K?N?N?N???????????????????t??????????????????????????????t????????????????????????M??????p??
Reg HKLM\SYSTEM\ControlSet001\services\LanmanWorkstation\Linkage@Bind ???M?M??????????????????????????????????????????????????g????????M???????????????????????M?M?M?M?M?M?M?M?M?M?M?M?M?M?.???????M???-???????M??%SystemRoot%\System32\srvsvc.dll???????M?M????????????????e?????? ???J???p?????"{1????b??M?????????n????@%SystemRoot%\system32\drivers\fileinfo.sys,-101????????????????t??????????????????????????????????e??????????????????????????8??M????????h?????System32\DRIVERS\fvevol.sys?????????????????t??????????????g????\??\C:\Windows\gdrv.sys?-D??@%systemroot%\system32\drivers\hwpolicy.sys,-101??????<??M????????h?????System32\drivers\hwpolicy.sys?????b??M?????????n????@%systemroot%\system32\drivers\hwpolicy.sys,-102?????????????????????????????????????????M?M?M?M?M?M????????????????????????Network?????@%SystemRoot%\system32\drivers\fltmgr.sys,-10001??????0??M??????p???FSFilter Infrastructure???????8??M????????h?????File System??????????????????????????????M????????????????H?X??????4?????????? ????????????????? ?????????????H?X??????4???????????????????? ??????? ??????? ?????????t
Reg HKLM\SYSTEM\ControlSet001\services\LanmanWorkstation\Linkage@Route ???M?M????????????????e?????? ???J???p?????"{1????b??M?????????n????@%SystemRoot%\system32\drivers\fileinfo.sys,-101????????????????t??????????????????????????????????e??????????????????????????8??M????????h?????System32\DRIVERS\fvevol.sys?????????????????t??????????????g????\??\C:\Windows\gdrv.sys?-D??@%systemroot%\system32\drivers\hwpolicy.sys,-101??????<??M????????h?????System32\drivers\hwpolicy.sys?????b??M?????????n????@%systemroot%\system32\drivers\hwpolicy.sys,-102?????????????????????????????????????????M?M?M?M?M?M????????????????????????Network?????@%SystemRoot%\system32\drivers\fltmgr.sys,-10001??????0??M??????p???FSFilter Infrastructure???????8??M????????h?????File System??????????????????????????????M????????????????H?X??????4?????????? ????????????????? ?????????????H?X??????4???????????????????? ??????? ??????? ?????????t??M????????????????H?X??????4?????????? ????????????????? ????????????????????????M????????????H?d??????4?????????? ????????????????????????????????????????? #???????M?????????
Reg HKLM\SYSTEM\ControlSet001\services\LanmanWorkstation\Linkage@Export ???M??????8??M????????h?????Keyboard HID Driver??????????M??????p???????????????t???????????????t?????8??M????????h????????????????????g?????M?M?M?M?M?M?M?Mb5??System32\Drivers\ksecdd.sys?????????????????????????????????????????????t????M????????????????<??M????????h???????b??M?????????n??????`??M?????????e????@%SystemRoot%\system32\drivers\partmgr.sys,-100???????$??M??????p???Boot Bus Extender?????:??M????????h?????System32\drivers\partmgr.sys??????`??N?????????n????pcmcia.inf_amd64_neutral_1678e66e0cbb04b2????????M?????????e????PCI Bus Driver??????????????????t?????$??M??????p???Boot Bus Extender??????????????g?????N?N?N?M?M?M?M?Mb0????????????????????????????????????????8??M????????h??????M????2??M????????h?????system32\DRIVERS\pci.sys??????T??M???????????d??system32\DRIVERS\pciide.sys???????(??M??????p???System Bus Extender???????R??M???????????d??mshdc.inf_amd64_neutral_a69a58a4286f0b22?????M?M?M?M?M?M?M????????????????????P??M?????????e????Performance Counters for Windows Driver??????? ??J??????p?????2
Reg HKLM\SYSTEM\ControlSet003\services\LanmanServer\Linkage@Bind ????????@%SystemRoot%\system32\FirewallAPI.dll,-23093???????????????????????@%systemroot%\system32\wkssvc.dll,-1004?????system32\DRIVERS\mrxsmb20.sys?????P????????????n????????????????????????????????????t???NDIS?2???????????????????? ?????????p???????D???Network???????\????????????n??????6???????????h?????? ??D????:?????:?:??? ??????????????????????????????????????? ???????E?????B2C??@%systemroot%\system32\wkssvc.dll,-1003?????Base?$????8???????????h?????? ???????????????????????????.???.??????????????t???Network?????????????????????????????????????????Base?#??_tcp????Network???????R??????????????d??????????????????????????????p?????????????????????N????????????e????system32\DRIVERS\mrxsmb.sys?????system32\DRIVERS\msahci.sys?\msahci.sys?????????????????????????Tcpip???????@%systemroot%\system32\wkssvc.dll,-1006?????????????????p?????<???????????h?????????????????????????A??????g????File system?????system32\DRIVERS\msisadrv.sys??????????????g??????X????????????e??????X????????????e??????<???????????h???????P
Reg HKLM\SYSTEM\ControlSet003\services\LanmanServer\Linkage@Route ????????????????????????ServiceMain?????????????????????????????????????????t?????<???????????h?????System32\DRIVERS\srv.sys????????????????t???C:\ProgramData\Microsoft\MF?????????????????????*6to4mp??????????????????2??@%SystemRoot%\system32\drivers\mountmgr.sys,-100????network?????????W???????????????????SCSI Miniport???Security Driver???????2???????????h?????Microsoft???????????????????????????PnkBstrA?5??????????????p?????????????????????????&????????????e??????????????????????????????????????????????????????????????????????????????????????????????????????V????????????e????????????????t???Boot File System????????????????????@%systemroot%\system32\drivers\luafv.sys,-100???????????????t?????????????????????????N????????????n??????????????????????????????????????????????????????????????N????????????n?????????????v???????G???????????????????????z??????????????????{9??????????????????pci\cc_0101?c.??? R??????8??????????Standard Dual Channel PCI IDE Controller?8??????????????????????? ?????????????????????????
Reg HKLM\SYSTEM\ControlSet003\services\LanmanServer\Linkage@Export ?????????????????????????????????????????????????????*???*???????????????????0??0???? B?????????????????????????????%SystemRoot%\system32\srvsvc.dll?????????????:???:??????????????t????????????o???????????????????s??ep?????????????????g????@%systemroot%\system32\drivers\luafv.sys,-101???FltMgr??????????????????????System Bus Extender?????system32\DRIVERS\mouclass.sys?ouclass.sys?????b????????????e??????\????????????e????????????????????????\Device\{42DA8D02-5161-478E-A6C3-750FE767DBF7}?\Device\{DEE2C8CD-EB78-4377-870A-2F72F813D6BF}?\Device\{265F1749-DF60-4A90-AC91-1BD5FDD482E3}?\Device\{5169FA04-9A9E-4C73-81A5-5B57695D73AE}?\Device\{1AB45A29-DE57-4A64-A6C1-366EE12BFB2C}?\Device\{646B663C-842D-4E8D-92D9-DD4CBEC24B7F}??12B???????????2???????????????????????????n??\SystemRoot\system32\drivers\luafv.sys??????????????????t?????????????????????\????????????e????????????????????????PNP_TDI?????Mouse Class Driver??????????????????????????System32\drivers\mpsdrv.sys???????P????????????e????NDIS?~????????????????????<
Reg HKLM\SYSTEM\ControlSet003\services\LanmanWorkstation\Linkage@Bind ?????????????????????*???*???????????????????0??0???? B?????????????????????????????%SystemRoot%\system32\srvsvc.dll?????????????:???:??????????????t????????????o???????????????????s??ep?????????????????g????@%systemroot%\system32\drivers\luafv.sys,-101???FltMgr??????????????????????System Bus Extender?????system32\DRIVERS\mouclass.sys?ouclass.sys?????b????????????e??????\????????????e????????????????????????\Device\{42DA8D02-5161-478E-A6C3-750FE767DBF7}?\Device\{DEE2C8CD-EB78-4377-870A-2F72F813D6BF}?\Device\{265F1749-DF60-4A90-AC91-1BD5FDD482E3}?\Device\{5169FA04-9A9E-4C73-81A5-5B57695D73AE}?\Device\{1AB45A29-DE57-4A64-A6C1-366EE12BFB2C}?\Device\{646B663C-842D-4E8D-92D9-DD4CBEC24B7F}??12B???????????2???????????????????????????n??\SystemRoot\system32\drivers\luafv.sys??????????????????t?????????????????????\????????????e????????????????????????PNP_TDI?????Mouse Class Driver??????????????????????????System32\drivers\mpsdrv.sys???????P????????????e????NDIS?~????????????????????<???????????h?????udfs??????8????
Reg HKLM\SYSTEM\ControlSet003\services\LanmanWorkstation\Linkage@Route ????????@%SystemRoot%\system32\drivers\ndis.sys,-201????Network?????????????????????????????????????????t???srvnet??????????????????t???????????????p??????????????? ??????g??????????????????????z?????????????tcpip???????????????????????????????base?????? ?????????p???File system?????4&1a1c9fdc&0?d??192.168.1.75????????????B3????????????????????????????????????????????????????????????????(??? ?????????????????? ????????????????????????V?????????&???????????????????????? ??????????????????????????????????????P7??? ??????????????????????????????????????????? ???????????????????????????????????????A??? ???????6??????d3??? ????????????????????????????????????????b5DB??? ??????????????????????????????????+??????????????????????0A6????????????????????????}"?"NetB??? ?????????????????????,????????????&????????????????????????????????????:??????????????p?????????????"?????????p???? ???????C??????\D??????????????????????????????t?????????????8??????????????????????????????????????????m????<????????????e???????????????
Reg HKLM\SYSTEM\ControlSet003\services\LanmanWorkstation\Linkage@Export ?????????????????????????????e???????????u???????????.????0?@??????????????????????? ????????????????????? ???????????????\????????????n??????<?????????????????Network?????????????????????????????????Pointer Class??????????????????????g????????????????????FSFilter Virtualization?????system32\DRIVERS\mouhid.sys?\mouhid.sys?????????????????????????????????????????????????????????????????????????????ServiceMain?????????????????????????????????????????t?????<???????????h?????System32\DRIVERS\srv.sys????????????????t???C:\ProgramData\Microsoft\MF?????????????????????*6to4mp??????????????????2??@%SystemRoot%\system32\drivers\mountmgr.sys,-100????network?????????W???????????????????SCSI Miniport???Security Driver???????2???????????h?????Microsoft???????????????????????????PnkBstrA?5??????????????p?????????????????????????&????????????e??????????????????????????????????????????????????????????????????????????????????????????????????????V????????????e????????????????t???Boot File System????????????????????@%systemroo
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ??? ? ??????????????t?????????????????????????????????????????<?? ????????h?????system32\DRIVERS\kbdclass.sys?bdclass.sys??????????????g????? ? ? ? ? ? ? ? ??????8?? ????????h?????System32\Drivers\ksecdd.sys???????????????????????????? ? ??? ?????????????g????????????????????? ? ? ? ? ? ? ?????????????????e????????? ??????p???p???????????????t???????????????????????? ???:??????? ????????????????????????????????????8?? ????????h???????(?? ?????????e????Cryptography??????:?? ????????h?????System32\Drivers\ksecpkg.sys????????????????????????????????????t??????????????g????????????????????? ? ? ? ? ? ? ?????????????????e??????0?? ?????????e????Kernel Streaming Thunks?????????? ??????p???PNP Filter????????R?? ????????h?????\SystemRoot\system32\drivers\ksthunk.sys????????????????????????????????????t???????????????????? ? ? ? ? ? tr??????? ???s??eF??????? ??? ? ? ??????? ???????:????? ? ??????????? ??????????????????HdAudModel????????? ?#??????????????????????????g??????/?7????????? ? ???0?4? ??????? ???-??????CSC
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ??? ? ??? ?????????????g????????????????????? ? ? ? ? ? ? ?????????????????e????????? ??????p???p???????????????t???????????????????????? ???:??????? ????????????????????????????????????8?? ????????h???????(?? ?????????e????Cryptography??????:?? ????????h?????System32\Drivers\ksecpkg.sys????????????????????????????????????t??????????????g????????????????????? ? ? ? ? ? ? ?????????????????e??????0?? ?????????e????Kernel Streaming Thunks?????????? ??????p???PNP Filter????????R?? ????????h?????\SystemRoot\system32\drivers\ksthunk.sys????????????????????????????????????t???????????????????? ? ? ? ? ? tr??????? ???s??eF??????? ??? ? ? ??????? ???????:????? ? ??????????? ??????????????????HdAudModel????????? ?#??????????????????????????g??????/?7????????? ? ???0?4? ??????? ???-??????CSCFlags=0?MaxUses=4294967295?Path=C:\Users\X-25M-WT\Shared?Permissions=9?ShareName=Shared?Type=0????????????#???}??sT???????#???????????????#??????????????????? ???:???:??????????? ???????????o???????????????????v???????G????????*????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ??? ? ??????????? ??????????????????HdAudModel????????? ?#??????????????????????????g??????/?7????????? ? ???0?4? ??????? ???-??????CSCFlags=0?MaxUses=4294967295?Path=C:\Users\X-25M-WT\Shared?Permissions=9?ShareName=Shared?Type=0????????????#???}??sT???????#???????????????#??????????????????? ???:???:??????????? ???????????o???????????????????v???????G????????*??????????????e?????????nab???????????????????????e???????????*???*???????????l???????????????????????u???????????.??????????????????????????????? ???s??ep????? ?:??????????? B?? ??????????????%SystemRoot%\System32\srvsvc.dll????????????????????????????? ? ? ??????? ???0????????? ti???????????????????0??0???????????????t???NDIS???????????????????????????????????g????FltMgr????????8?? ????????h?????network?????system32\DRIVERS\lltdio.sys???????`?? ?????????e????Link-Layer Topology Discovery Mapper I/O Driver???????????????????????????0?? ??????p????? ?? ??????????????????????????????? ? ? ? ? ? ? ? ? ??FSFilter Virtualization???????N?? ????????h?????\Sy
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ??? ?#??????????????????????????g??????/?7????????? ? ???0?4? ??????? ???-??????CSCFlags=0?MaxUses=4294967295?Path=C:\Users\X-25M-WT\Shared?Permissions=9?ShareName=Shared?Type=0????????????#???}??sT???????#???????????????#??????????????????? ???:???:??????????? ???????????o???????????????????v???????G????????*??????????????e?????????nab???????????????????????e???????????*???*???????????l???????????????????????u???????????.??????????????????????????????? ???s??ep????? ?:??????????? B?? ??????????????%SystemRoot%\System32\srvsvc.dll????????????????????????????? ? ? ??????? ???0????????? ti???????????????????0??0???????????????t???NDIS???????????????????????????????????g????FltMgr????????8?? ????????h?????network?????system32\DRIVERS\lltdio.sys???????`?? ?????????e????Link-Layer Topology Discovery Mapper I/O Driver???????????????????????????0?? ??????p????? ?? ??????????????????????????????? ? ? ? ? ? ? ? ? ??FSFilter Virtualization???????N?? ????????h?????\SystemRoot\system32\drivers\luafv.sys????????\?? ?????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ??? ?:??????????? B?? ??????????????%SystemRoot%\System32\srvsvc.dll????????????????????????????? ? ? ??????? ???0????????? ti???????????????????0??0???????????????t???NDIS???????????????????????????????????g????FltMgr????????8?? ????????h?????network?????system32\DRIVERS\lltdio.sys???????`?? ?????????e????Link-Layer Topology Discovery Mapper I/O Driver???????????????????????????0?? ??????p????? ?? ??????????????????????????????? ? ? ? ? ? ? ? ? ??FSFilter Virtualization???????N?? ????????h?????\SystemRoot\system32\drivers\luafv.sys????????\?? ?????????n????@%systemroot%\system32\drivers\luafv.sys,-101???????????????????????????????????????????????????????????? ???????????e??????????????t???-1???????-????\?? ?????????e????????????????t???? ? ? ? ? ??????@%systemroot%\system32\drivers\luafv.sys,-100?????????????????????????:?? ????????h?????system32\DRIVERS\monitor.sys??????`?? ?????????e????Microsoft Monitor Class Function Driver Service?????????????????????????????????????????????????????????Network?????? ?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ??? ti???????????????????0??0???????????????t???NDIS???????????????????????????????????g????FltMgr????????8?? ????????h?????network?????system32\DRIVERS\lltdio.sys???????`?? ?????????e????Link-Layer Topology Discovery Mapper I/O Driver???????????????????????????0?? ??????p????? ?? ??????????????????????????????? ? ? ? ? ? ? ? ? ??FSFilter Virtualization???????N?? ????????h?????\SystemRoot\system32\drivers\luafv.sys????????\?? ?????????n????@%systemroot%\system32\drivers\luafv.sys,-101???????????????????????????????????????????????????????????? ???????????e??????????????t???-1???????-????\?? ?????????e????????????????t???? ? ? ? ? ??????@%systemroot%\system32\drivers\luafv.sys,-100?????????????????????????:?? ????????h?????system32\DRIVERS\monitor.sys??????`?? ?????????e????Microsoft Monitor Class Function Driver Service?????????????????????????????????????????????????????????Network?????? ??????????????Mouse Class Driver??????????? ??????????Pointer Class???????????????t?????V?? ??????????????machine.inf_amd
---- EOF - GMER 1.0.15 ----