GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-06-02 04:55:41 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD2500JS-60MHB5 rev.10.02E04 Running: Gmer.exe; Driver: C:\DOCUME~1\ADMINI~1.001\USTAWI~1\Temp\pfgdrpob.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF73F80B0] SSDT sptd.sys ZwEnumerateKey [0xF73FD84E] SSDT sptd.sys ZwEnumerateValueKey [0xF73FDBEE] SSDT sptd.sys ZwOpenKey [0xF73F8090] SSDT sptd.sys ZwQueryKey [0xF73FDCC6] SSDT sptd.sys ZwQueryValueKey [0xF73FDB46] SSDT sptd.sys ZwSetValueKey [0xF73FDD58] ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text USBPORT.SYS!DllUnload F71968AC 5 Bytes JMP 86DFA960 ? System32\Drivers\a1h6f6mv.SYS System nie może odnaleźć określonej ścieżki. ! ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F740C480] sptd.sys IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F740C42C] sptd.sys IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7426AB8] sptd.sys IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F740C480] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73F8ABA] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73F8C00] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73F8B82] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73F972E] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73F9604] sptd.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F740BA9A] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 86F5C1D8 Device \FileSystem\Fastfat \FatCdrom 86BA2980 Device \FileSystem\Udfs \UdfsCdRom 86BA31D8 Device \FileSystem\Udfs \UdfsDisk 86BA31D8 Device \Driver\usbuhci \Device\USBPDO-0 86DF9980 Device \Driver\usbuhci \Device\USBPDO-1 86DF9980 Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F5E1D8 Device \Driver\dmio \Device\DmControl\DmConfig 86F5E1D8 Device \Driver\dmio \Device\DmControl\DmPnP 86F5E1D8 Device \Driver\dmio \Device\DmControl\DmInfo 86F5E1D8 Device \Driver\usbehci \Device\USBPDO-2 86DF71D8 Device \Driver\usbuhci \Device\USBPDO-3 86DF9980 Device \Driver\usbuhci \Device\USBPDO-4 86DF9980 Device \Driver\usbuhci \Device\USBPDO-5 86DF9980 Device \Driver\usbehci \Device\USBPDO-6 86DF71D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 86FD21D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 86FD21D8 Device \Driver\Cdrom \Device\CdRom0 86DCB980 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F734BB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F734BB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F734BB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F734BB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F734BB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Cdrom \Device\CdRom1 86DCB980 Device \Driver\Cdrom \Device\CdRom2 86DCB980 Device \Driver\00000500 \Device\0000004d sptd.sys Device \Driver\usbuhci \Device\USBFDO-0 86DF9980 Device \Driver\usbuhci \Device\USBFDO-1 86DF9980 Device \Driver\usbehci \Device\USBFDO-2 86DF71D8 Device \Driver\usbuhci \Device\USBFDO-3 86DF9980 Device \Driver\usbuhci \Device\USBFDO-4 86DF9980 Device \Driver\Ftdisk \Device\FtControl 86FD21D8 Device \Driver\usbuhci \Device\USBFDO-5 86DF9980 Device \Driver\usbehci \Device\USBFDO-6 86DF71D8 Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 86F5D1D8 Device \Driver\a1h6f6mv \Device\Scsi\a1h6f6mv1Port5Path0Target0Lun0 86D8F600 Device \Driver\a1h6f6mv \Device\Scsi\a1h6f6mv1 86D8F600 Device \Driver\JRAID \Device\Scsi\JRAID1 86F5D1D8 Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target1Lun0 86F5D1D8 Device \FileSystem\Fastfat \Fat 86BA2980 Device \FileSystem\Cdfs \Cdfs 86C331D8 ---- Processes - GMER 1.0.15 ---- Library c:\windows\system32\n (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [640] 0x45670000 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1190547817 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1583019703 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 F:\Program Files\deamon tools\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x66 0x8C 0x15 0xD1 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE1 0x4F 0x24 0xFB ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x6B 0x87 0xCE ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 F:\Program Files\deamon tools\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x66 0x8C 0x15 0xD1 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE1 0x4F 0x24 0xFB ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x6B 0x87 0xCE ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 F:\Program Files\deamon tools\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x66 0x8C 0x15 0xD1 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE1 0x4F 0x24 0xFB ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x6B 0x87 0xCE ... ---- EOF - GMER 1.0.15 ----