Gmer: Code:
GMER 1.0.15.15020 [he1zmult.exe] - http://www.gmer.net
Rootkit scan 2009-08-11 09:56:35
Windows 6.0.6002 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT A0D1138C ZwCreateThread
SSDT A0D11378 ZwOpenProcess
SSDT A0D1137D ZwOpenThread
SSDT A0D11387 ZwTerminateProcess
INT 0x51 ? 86D0CDA0
INT 0x72 ? 86D0CDA0
INT 0x82 ? 86D0CDA0
INT 0x92 ? 85432BF8
INT 0x92 ? 86D0CDA0
INT 0x92 ? 86D0CDA0
INT 0x92 ? 86D0CDA0
INT 0x92 ? 85432BF8
INT 0xA2 ? 86D0CDA0
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInsertQueue + 411 820ABA48 4 Bytes [8C, 13, D1, A0]
.text ntoskrnl.exe!KeInsertQueue + 5E1 820ABC18 4 Bytes [78, 13, D1, A0]
.text ntoskrnl.exe!KeInsertQueue + 5FD 820ABC34 4 Bytes [7D, 13, D1, A0]
.text ntoskrnl.exe!KeInsertQueue + 811 820ABE48 4 Bytes [87, 13, D1, A0]
? system32\drivers\jyii.sys Das System kann den angegebenen Pfad nicht finden. !
? System32\Drivers\spna.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8FC3641B 5 Bytes JMP 86D0C380
.text aenk3gim.SYS 8FD3D000 22 Bytes [82, 23, 01, 82, 6C, 22, 01, ...]
.text aenk3gim.SYS 8FD3D017 81 Bytes [00, 32, 27, 76, 8A, 3D, 25, ...]
.text aenk3gim.SYS 8FD3D069 85 Bytes [4B, 09, 82, B0, 68, 08, 82, ...]
.text aenk3gim.SYS 8FD3D0BF 13 Bytes [82, 00, 00, 00, 00, 00, 00, ...] {ADD BYTE [EAX], 0x0; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text aenk3gim.SYS 8FD3D0CE 10 Bytes [00, 00, 00, 00, 00, 00, 66, ...]
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 84A962D8
IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice] [8A689C4C] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [8A689CA0] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8A6596D2] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8A659040] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8A6597FC] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [8A6590BE] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8A65913C] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\system32\drivers\ataport.SYS[ntoskrnl.exe!DbgBreakPoint] 84A972D8
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 86D0C480
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8A669048] \SystemRoot\System32\Drivers\spna.sys
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortNotification] 24488B66
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortWritePortUchar] E84D8966
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortWritePortUlong] 83E84D8B
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 896602C1
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 488BEA4D
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortGetScatterGatherList] 8DC80320
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortReadPortUchar] 57500845
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortStallExecution] F0458D57
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortGetParentBusType] 00006850
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortRequestCallback] 458DB002
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 35FF50E8
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortGetUnCachedExtension] [8FD62FBC] \SystemRoot\System32\Drivers\aenk3gim.SYS (ATAPI IDE Miniport Driver/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortCompleteRequest] 57EC4D89
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortMoveMemory] 01F045C7
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] E8000000
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 0001E4E4
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 4675C73B
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortReadPortUshort] D62FC8A1
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 8D526A8F
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortInitialize] 00009A88
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortGetDeviceBase] 48C08300
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[ataport.SYS!AtaPortDeviceStateChange] 8D076A50
IAT \SystemRoot\System32\Drivers\aenk3gim.SYS[NTOSKRNL.exe!KeTickCount] 840FF87D
IAT \SystemRoot\system32\DRIVERS\storport.sys[ntoskrnl.exe!DbgBreakPoint] 86F6A2D8
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 854351F8
Device \Driver\sptd \Device\1479516017 spna.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 854301F8
Device \Driver\usbuhci \Device\USBPDO-0 84B921F8
Device \Driver\usbuhci \Device\USBPDO-1 84B921F8
Device \Driver\usbuhci \Device\USBPDO-2 84B921F8
Device \Driver\usbehci \Device\USBPDO-3 84B911F8
Device \Driver\usbuhci \Device\USBPDO-4 84B921F8
Device \Driver\PCI_PNP8004 \Device\00000061 spna.sys
Device \Driver\usbuhci \Device\USBPDO-5 84B921F8
Device \Driver\usbuhci \Device\USBPDO-6 84B921F8
Device \Driver\volmgr \Device\HarddiskVolume1 854301F8
Device \Driver\netbt \Device\NetBT_Tcpip_{8ABBBC40-5F9B-4C7C-9BFA-57B09F350444} 88BB2500
Device \Driver\usbehci \Device\USBPDO-7 84B911F8
Device \Driver\volmgr \Device\HarddiskVolume2 854301F8
Device \Driver\netbt \Device\NetBT_Tcpip_{A966DD53-30E4-42A0-AA89-EDB075A7A7F9} 88BB2500
Device \Driver\cdrom \Device\CdRom0 86E4B1F8
Device \Driver\volmgr \Device\HarddiskVolume3 854301F8
Device \Driver\iaStor \Device\Ide\iaStor0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\cdrom \Device\CdRom1 86E4B1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{6FB0E75E-07A2-4AD7-8672-15D446A7A14C} 88BB2500
Device \Driver\netbt \Device\NetBt_Wins_Export 88BB2500
Device \Driver\Smb \Device\NetbiosSmb 89741500
Device \Driver\iScsiPrt \Device\RaidPort0 86F6B1F8
Device \Driver\usbuhci \Device\USBFDO-0 84B921F8
Device \Driver\usbuhci \Device\USBFDO-1 84B921F8
Device \Driver\usbuhci \Device\USBFDO-2 84B921F8
Device \Driver\usbehci \Device\USBFDO-3 84B911F8
Device \Driver\usbuhci \Device\USBFDO-4 84B921F8
Device \Driver\usbuhci \Device\USBFDO-5 84B921F8
Device \Driver\usbuhci \Device\USBFDO-6 84B921F8
Device \Driver\usbehci \Device\USBFDO-7 84B911F8
Device \Driver\aenk3gim \Device\Scsi\aenk3gim1 86E521F8
Device \Driver\aenk3gim \Device\Scsi\aenk3gim1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\aenk3gim \Device\Scsi\aenk3gim1Port2Path0Target0Lun0 86E521F8
Device \Driver\aenk3gim \Device\Scsi\aenk3gim1Port2Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\cdfs \Cdfs 89A651F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cd3e0d6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cd65b4f
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cd6642e
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6A 0xCE 0xD9 0xC6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x26 0x27 0x11 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEA 0xA6 0x42 0xC8 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001e4cd3e0d6 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001e4cd65b4f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001e4cd6642e (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6A 0xCE 0xD9 0xC6 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x26 0x27 0x11 0x75 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEA 0xA6 0x42 0xC8 ...
---- EOF - GMER 1.0.15 ---- |