vGMER 1.0.15.15087 -
http://www.gmer.netRootkit scan 2009-09-21 13:17:29
Windows 6.0.6001 Service Pack 1
Running: cbhhrtmt.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\kweyruod.sys
---- System - GMER 1.0.15 ----
Code 835B63B8 ZwEnumerateKey
Code 835D5330 ZwFlushInstructionCache
Code 835B73FD IofCallDriver
Code 835D236E IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 81A49FE2 5 Bytes JMP 835D2373
.text ntkrnlpa.exe!IofCallDriver 81ACBF6F 5 Bytes JMP 835B7402
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81BC230B 5 Bytes JMP 835D5334
PAGE ntkrnlpa.exe!ZwEnumerateKey 81C17BA2 5 Bytes JMP 835B63BC
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1588] WS2_32.dll!closesocket 76AB330C 5 Bytes JMP 100129A0 \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1588] WS2_32.dll!connect 76AB40D9 5 Bytes JMP 100127E0 \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1588] WS2_32.dll!send 76AB659B 5 Bytes JMP 100127C0 \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [700] 0x01390000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [780] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [812] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [908] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [936] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [964] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1016] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1040] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1268] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1500] 0x10000000
Library \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [1588] 0x10000000
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\drivers\UACyeilbbrcju.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACcpynivsapk.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACmxvicnnpwf.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACcrvsyksoeq.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACcpynivsapk.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACmxvicnnpwf.dat
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACcrvsyksoeq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACcpynivsapk.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACmxvicnnpwf.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACcrvsyksoeq.dll
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACyeilbbrcju.sys
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACcpynivsapk.dll
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UAChtwlqpxreb.dll
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACmxvicnnpwf.dat
Reg HKLM\SYSTEM\ControlSet004\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACcrvsyksoeq.dll
---- Files - GMER 1.0.15 ----
File C:\Users\Administrator\AppData\Local\Temp\UACe41f.tmp 680448 bytes executable
File C:\Windows\Temp\UACc6e9.tmp 74240 bytes executable
File C:\Windows\System32\drivers\UACyeilbbrcju.sys 50176 bytes executable <-- ROOTKIT !!!
File C:\Windows\System32\UACcpynivsapk.dll 24064 bytes executable
File C:\Windows\System32\UACcrvsyksoeq.dll 19968 bytes executable
File C:\Windows\System32\UAChtwlqpxreb.dll 74240 bytes executable
File C:\Windows\System32\uacinit.dll 6563 bytes
File C:\Windows\System32\UACmxvicnnpwf.dat 174 bytes
---- EOF - GMER 1.0.15 ----