GMER 1.0.15.15163 -
http://www.gmer.netRootkit scan 2010-01-03 06:22:46
Windows 5.1.2600 Service Pack 2
Running: l0pjcpp9.exe; Driver: C:\DOCUME~1\MALEKA~1\LOCALS~1\Temp\fwrcyaog.sys
---- Kernel code sections - GMER 1.0.15 ----
PAGE Ntfs.sys F9C20E88 4 Bytes CALL 80DE7E81
INIT amdk7.sys F859A000 40 Bytes [E1, 80, 1B, 04, 76, A3, 1F, ...]
INIT amdk7.sys F859A03C 2 Bytes [1A, 77]
INIT amdk7.sys F859A040 6 Bytes [FE, 23, E3, B4, 90, 71]
INIT amdk7.sys F859A048 2 Bytes [9E, 71]
INIT amdk7.sys F859A04C 2 Bytes [B0, 71] {MOV AL, 0x71}
INIT ...
.pak2 C:\WINDOWS\system32\DRIVERS\amdk7.sys entry point in ".pak2" section [0xF8601509]
? C:\WINDOWS\system32\DRIVERS\amdk7.sys A device attached to the system is not functioning.
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 80DF53A0
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\DRIVERS\amdk7.sys (*** hidden *** ) [SYSTEM] AmdK7 <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@Tag 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@ImagePath system32\DRIVERS\amdk7.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@DisplayName AMD K7 Processor Driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7@Group Extended Base
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\AmdK7\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK7@EventMessageFile %SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\amdk7.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK7@TypesSupported 7
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@Start 1
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@Tag 3
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@ImagePath system32\DRIVERS\amdk7.sys
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@DisplayName AMD K7 Processor Driver
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7@Group Extended Base
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\AmdK7\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\System\AmdK7@EventMessageFile %SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\amdk7.sys
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\System\AmdK7@TypesSupported 7
---- EOF - GMER 1.0.15 ----