ecowan
Sorry I haven't gotten back sooner but here is the results of the latest scan.
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-31 22:32:06
Windows 6.0.6000
—- System - GMER 1.0.14 —-
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateProcess [0x8D5A8C26]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateProcessEx [0x8D5A8C40]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateThread [0x8D5A7DE4]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwLoadDriver [0x8D5A810C]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwMapViewOfSection [0x8D5A7B30]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwOpenSection [0x8D5A853E]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwRenameKey [0x8D5A97DC]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSetSystemInformation [0x8D5A838E]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSuspendProcess [0x8D5A79B6]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSuspendThread [0x8D5A7E18]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSystemDebugControl [0x8D5A7F92]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwTerminateProcess [0x8D5A7916]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwTerminateThread [0x8D5A7A6C]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwWriteVirtualMemory [0x8D5A7EDC]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateThreadEx [0x8D5A7DFE]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateUserProcess [0x8D5A8C5A]
—- Kernel code sections - GMER 1.0.14 —-
.text ntkrnlpa.exe!ZwCallbackReturn + 7E0 82080CEC 12 Bytes [ B6, 79, 5A, 8D, 18, 7E, 5A, … ]
—- User code sections - GMER 1.0.14 —-
.text C:\Users\EDDIE\Desktop\gmer.exe[4596] ntdll.dll!NtCreateFile + 3 7791F417 2 Bytes [ 73, FA ]
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74A1FD78] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [749EBBF1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [749DA31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [749DCBFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [749D8AB2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [749ED168] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [749D7D98] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [749D7CFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749D6A54] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74A6C1BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749F80FE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [749D90CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [749E223C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [749E2267] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [749E771C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [749E753E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74A18585] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.14 —-
AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Services - GMER 1.0.14 —-
Service system32\drivers\gaopdxbpajxvdo.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.14 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxaahenfgi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxaahenfgi.dll
—- EOF - GMER 1.0.14 —-
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-31 22:32:06
Windows 6.0.6000
—- System - GMER 1.0.14 —-
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateProcess [0x8D5A8C26]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateProcessEx [0x8D5A8C40]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateThread [0x8D5A7DE4]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwLoadDriver [0x8D5A810C]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwMapViewOfSection [0x8D5A7B30]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwOpenSection [0x8D5A853E]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwRenameKey [0x8D5A97DC]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSetSystemInformation [0x8D5A838E]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSuspendProcess [0x8D5A79B6]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSuspendThread [0x8D5A7E18]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwSystemDebugControl [0x8D5A7F92]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwTerminateProcess [0x8D5A7916]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwTerminateThread [0x8D5A7A6C]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwWriteVirtualMemory [0x8D5A7EDC]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateThreadEx [0x8D5A7DFE]
SSDT \??\C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys ZwCreateUserProcess [0x8D5A8C5A]
—- Kernel code sections - GMER 1.0.14 —-
.text ntkrnlpa.exe!ZwCallbackReturn + 7E0 82080CEC 12 Bytes [ B6, 79, 5A, 8D, 18, 7E, 5A, … ]
—- User code sections - GMER 1.0.14 —-
.text C:\Users\EDDIE\Desktop\gmer.exe[4596] ntdll.dll!NtCreateFile + 3 7791F417 2 Bytes [ 73, FA ]
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74A1FD78] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [749EBBF1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [749DA31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [749DCBFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [749D8AB2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [749ED168] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [749D7D98] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [749D7CFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749D6A54] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74A6C1BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749F80FE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [749D90CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [749E223C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [749E2267] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [749E771C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [749E753E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1956] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74A18585] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.14 —-
AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Services - GMER 1.0.14 —-
Service system32\drivers\gaopdxbpajxvdo.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.14 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxaahenfgi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxbpajxvdo.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxaahenfgi.dll
—- EOF - GMER 1.0.14 —-