GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-08-23 13:32:16
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT sptd.sys ZwCreateKey [0xF862B0D0]
SSDT sptd.sys ZwEnumerateKey [0xF8630FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF8631340]
SSDT sptd.sys ZwOpenKey [0xF862B0B0]
SSDT sptd.sys ZwQueryKey [0xF8631418]
SSDT sptd.sys ZwQueryValueKey [0xF8631298]
SSDT sptd.sys ZwSetValueKey [0xF86314AA]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F78D062C 5 Bytes JMP 828F6360
? System32\Drivers\afc8yqub.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!SetScrollInfo 7E419056 7 Bytes JMP 0496A68D C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!GetScrollInfo 7E420DA2 7 Bytes JMP 0496A615 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!ShowScrollBar 7E42F2B3 5 Bytes JMP 0496A711 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!GetScrollPos 7E42F6C4 5 Bytes JMP 0496A63D C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!SetScrollPos 7E42F710 5 Bytes JMP 0496A6B8 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!GetScrollRange 7E42F747 5 Bytes JMP 0496A662 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!SetScrollRange 7E42F95B 5 Bytes JMP 0496A6E3 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3720] USER32.dll!EnableScrollBar 7E467DDD 7 Bytes JMP 0496A5ED C:\Program Files\Winamp\Plugins\gen_jumpex.dll
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F864206C] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8642018] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F86649AE] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F864206C] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F862BAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F862BC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F862BB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F862C748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F862C61E] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F864129A] sptd.sys
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 833D41E8
AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
Device \FileSystem\Fastfat \FatCdrom 8286C790
Device \Driver\NetBT \Device\NetBT_Tcpip_{727510F2-F1ED-4193-99C6-8BC6D9EC4B36} 829196E8
Device \Driver\usbohci \Device\USBPDO-0 828F5588
Device \Driver\dmio \Device\DmControl\DmIoDaemon 833D61E8
Device \Driver\dmio \Device\DmControl\DmConfig 833D61E8
Device \Driver\dmio \Device\DmControl\DmPnP 833D61E8
Device \Driver\dmio \Device\DmControl\DmInfo 833D61E8
Device \Driver\usbohci \Device\USBPDO-1 828F5588
Device \Driver\USBSTOR \Device\00000070 827B9790
Device \Driver\Ftdisk \Device\HarddiskVolume1 833561E8
Device \Driver\USBSTOR \Device\00000071 827B9790
Device \Driver\Ftdisk \Device\HarddiskVolume2 833561E8
Device \Driver\Cdrom \Device\CdRom0 828DD1E8
Device \Driver\USBSTOR \Device\00000072 827B9790
Device \Driver\Ftdisk \Device\HarddiskVolume3 833561E8
Device \Driver\Cdrom \Device\CdRom1 828DD1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-22 833551E8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-c 833551E8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-4 833551E8
Device \Driver\atapi \Device\Ide\IdePort0 833551E8
Device \Driver\atapi \Device\Ide\IdePort1 833551E8
Device \Driver\atapi \Device\Ide\IdePort2 833551E8
Device \Driver\atapi \Device\Ide\IdePort3 833551E8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-2e 833551E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-17 833551E8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T1L0-36 833551E8
Device \Driver\USBSTOR \Device\00000073 827B9790
Device \Driver\Ftdisk \Device\HarddiskVolume4 833561E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 833561E8
Device \Driver\Ftdisk \Device\HarddiskVolume6 833561E8
Device \Driver\Ftdisk \Device\HarddiskVolume7 833561E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 829196E8
Device \Driver\NetBT \Device\NetbiosSmb 829196E8
Device \Driver\PCI_NTPNP8372 \Device\0000004c sptd.sys
Device \Driver\usbohci \Device\USBFDO-0 828F5588
Device \Driver\usbohci \Device\USBFDO-1 828F5588
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82861790
Device \FileSystem\MRxSmb \Device\LanmanRedirector 82861790
Device \Driver\USBSTOR \Device\0000006f 827B9790
Device \Driver\Ftdisk \Device\FtControl 833561E8
Device \Driver\afc8yqub \Device\Scsi\afc8yqub1 828FE790
Device \FileSystem\Fastfat \Fat 8286C790
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
Device \FileSystem\Cdfs \Cdfs 82995790
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 684275809
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -1670869367
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xD3 0x4F 0x74 0x39 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEC 0x46 0x36 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xD3 0x4F 0x74 0x39 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xEC 0x46 0x36 0xF3 ...
Reg HKLM\SOFTWARE\Classes\.tpr@ tpr_auto_file
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\Conversion\Readable
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\Conversion\Readable\Main
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\Conversion\Readable\Main@ 8
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\MiscStatus@ 512
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\Ole1Class@ PBrush
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\ProgID@ PBrush
Reg HKLM\SOFTWARE\Classes\CLSID\{BA3BADF2-98D1-5396-1511-F1D768CA74BA}\TreatAs@ {D3E34B21-9D75-101A-8C3D-00AA001A1652}
Reg HKLM\SOFTWARE\Classes\tpr_auto_file@
Reg HKLM\SOFTWARE\Classes\tpr_auto_file\shell
Reg HKLM\SOFTWARE\Classes\tpr_auto_file\shell\Play
Reg HKLM\SOFTWARE\Classes\tpr_auto_file\shell\Play@ Play with VLC
Reg HKLM\SOFTWARE\Classes\tpr_auto_file\shell\Play\command
Reg HKLM\SOFTWARE\Classes\tpr_auto_file\shell\Play\command@ C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file "%1"
---- EOF - GMER 1.0.14 ----