log gmer:
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-11-07 12:52:05
Windows 5.1.2600 Service Pack 3
Running: 93u6mjwb.exe; Driver: C:\DOCUME~1\Acer\LOCALS~1\Temp\awloqfoc.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [614AAE77] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [614AADA9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [614AA7A3] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [614AADE9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!GetStockObject] [614A9CEC] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [614AAE77] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [614AADA9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [614AA7A3] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [614AADE9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [614A9CEC] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [614AAE29] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [614AAE77] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [614AADE9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [614AADA9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [614AA7A3] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [614AA3BA] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [614AA3BA] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [614A9C27] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [614A9B56] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [614A9B94] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetStockObject] [614A9CEC] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [614AADA9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [614AADE9] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [614AA7A3] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [614AAE77] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [614AAE29] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [614A9D87] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [614A9B94] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [614AA3BA] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [614A9C27] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [614AA3BA] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [614A9CF2] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
IAT C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe[1260] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [614A9B56] C:\PROGRA~1\Yahoo!\Messenger\yui.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] nhceg <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] qjwcfy <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] ruszqlm <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@DisplayName Shell Manager
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\nhceg\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@DisplayName Driver Config
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\qjwcfy\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@DisplayName Shell Network
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ruszqlm\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@DisplayName Shell Manager
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\nhceg\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@DisplayName Driver Config
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\qjwcfy\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@DisplayName Shell Network
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\ruszqlm\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@DisplayName Shell Manager
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\nhceg\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@DisplayName Driver Config
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\qjwcfy\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@DisplayName Shell Network
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ruszqlm\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@DisplayName Shell Manager
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\nhceg\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@DisplayName Driver Config
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\qjwcfy\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@DisplayName Shell Network
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\ruszqlm\Parameters@ServiceDll C:\WINDOWS\system32\lglajlt.dll
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 61: malicious code @ sector 0x6fc3dbf size 0x194
---- EOF - GMER 1.0.15 ----