GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-05-13 16:01:13 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.892C Running: nwkr6gqs.exe; Driver: C:\DOCUME~1\Wiesia\USTAWI~1\Temp\kxldrpog.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF73EEA50] SSDT sptd.sys ZwEnumerateKey [0xF7422FFE] SSDT sptd.sys ZwEnumerateValueKey [0xF742338C] SSDT sptd.sys ZwOpenKey [0xF73EEA30] SSDT sptd.sys ZwQueryKey [0xF7423464] SSDT sptd.sys ZwQueryValueKey [0xF74232E4] SSDT sptd.sys ZwSetValueKey [0xF74234F6] INT 0x62 ? 86B9CCC8 INT 0x73 ? 86BCDCC8 INT 0x73 ? 86109F00 INT 0x73 ? 86BCDCC8 INT 0xA4 ? 86109F00 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2C80 80504538 4 Bytes JMP 91B0F73E .text ntkrnlpa.exe!ZwCallbackReturn + 2DB8 80504670 4 Bytes [30, EA, 3E, F7] PAGE sptd.sys F7412000 1 Byte [74] PAGE sptd.sys F7412004 5 Bytes [40, 23, 41, F7, A3] PAGE sptd.sys F741200C 5 Bytes [50, 24, 41, F7, 98] PAGE sptd.sys F7412014 5 Bytes [B8, 23, 41, F7, 59] {MOV EAX, 0x59f74123} PAGE sptd.sys F741201C 5 Bytes [78, 22, 41, F7, 61] PAGE ... .sptd2 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd2" section [0xF74ABD38] ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text USBPORT.SYS!DllUnload F58E08AC 5 Bytes JMP 86109410 ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!GetSysColor 7E368E78 5 Bytes JMP 00418ED0 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!GetSysColorBrush 7E368EAB 5 Bytes JMP 00418F40 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!SetScrollInfo 7E369056 7 Bytes JMP 00418DC0 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!GetScrollInfo 7E37DFE2 7 Bytes JMP 00418D10 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!ShowScrollBar 7E37F2F2 5 Bytes JMP 00418E90 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!GetScrollPos 7E37F704 5 Bytes JMP 00418D50 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!SetScrollPos 7E37F750 5 Bytes JMP 00418E00 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!GetScrollRange 7E37F787 5 Bytes JMP 00418D80 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!SetScrollRange 7E37F99B 5 Bytes JMP 00418E40 C:\WINDOWS\SMINST\Scheduler.exe .text C:\WINDOWS\SMINST\Scheduler.exe[2828] USER32.dll!EnableScrollBar 7E3B8005 7 Bytes JMP 00418CD0 C:\WINDOWS\SMINST\Scheduler.exe .text C:\Program Files\Mozilla Firefox\firefox.exe[3140] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0126C930 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3140] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 0149E0AA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3140] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0149E083 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3140] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 0149E00D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_ULONG] [F73B5574] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!READ_PORT_UCHAR] [F73B50C0] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_UCHAR] [F73B5FE0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73B50C0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73B5362] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73B52A4] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73B61BC] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73B5FE0] sptd.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73CA312] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 86BCC1F8 Device \FileSystem\Fastfat \FatCdrom 8513C430 Device \FileSystem\Udfs \UdfsCdRom 85154430 Device \FileSystem\Udfs \UdfsCdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions) Device \FileSystem\Udfs \UdfsDisk 85154430 Device \FileSystem\Udfs \UdfsDisk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.) Device \Driver\NetBT \Device\NetBT_Tcpip_{81526A82-5199-490F-ADEF-C08A079057A0} 8535D1F8 Device \Driver\usbuhci \Device\USBPDO-0 861111F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{0A62625E-5B87-4686-949A-90427C2D718F} 8535D1F8 Device \Driver\usbuhci \Device\USBPDO-1 861111F8 Device \Driver\usbuhci \Device\USBPDO-2 861111F8 Device \Driver\usbuhci \Device\USBPDO-3 861111F8 Device \Driver\usbehci \Device\USBPDO-4 861191F8 Device \Driver\Cdrom \Device\CdRom0 861071F8 Device \Driver\iaStor \Device\Ide\iaStor0 [F72717B0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F730FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F730FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F72717B0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Cdrom \Device\CdRom1 861071F8 Device \Driver\Cdrom \Device\CdRom2 861071F8 Device \Driver\dtsoftbus01 \Device\DTSoftBusCtl 860741F8 Device \Driver\NetBT \Device\NetBt_Wins_Export 8535D1F8 Device \Driver\NetBT \Device\NetbiosSmb 8535D1F8 Device \Driver\usbuhci \Device\USBFDO-0 861111F8 Device \Driver\usbuhci \Device\USBFDO-1 861111F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 852D61F8 Device \Driver\usbuhci \Device\USBFDO-2 861111F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 852D61F8 Device \Driver\usbuhci \Device\USBFDO-3 861111F8 Device \Driver\usbehci \Device\USBFDO-4 861191F8 Device \Driver\dtsoftbus01 \Device\0000008c 860741F8 Device \FileSystem\Fastfat \Fat 8513C430 Device \FileSystem\Cdfs \Cdfs 85E8D1F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 ---- EOF - GMER 1.0.15 ----