GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-09-09 10:35:59 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-d SAMSUNG_HD642JJ rev.1AA01110 Running: vpns31t8.exe; Driver: C:\DOCUME~1\admn\USTAWI~1\Temp\kxryipob.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xB9EC00D0] SSDT sptd.sys ZwEnumerateKey [0xB9EC5E2C] SSDT sptd.sys ZwEnumerateValueKey [0xB9EC61BA] SSDT sptd.sys ZwOpenKey [0xB9EC00B0] SSDT sptd.sys ZwQueryKey [0xB9EC6292] SSDT sptd.sys ZwQueryValueKey [0xB9EC6112] SSDT sptd.sys ZwSetValueKey [0xB9EC6324] SSDT \SystemRoot\system32\DRIVERS\PSINProc.sys (PSINProc Filter Driver for for XP32/Panda Security, S.L.) ZwTerminateProcess [0xA97506B0] ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB8D36000, 0x2AAE02, 0xE8000020] .text USBPORT.SYS!DllUnload B8CED8AC 5 Bytes JMP 8A2521C8 init C:\WINDOWS\system32\drivers\p17xfilt.sys entry point in "init" section [0xB8A0D130] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[3116] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 014958A0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3116] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 016D78AF C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3116] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 016D788C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3116] kernel32.dll!ValidateLocale + B130 7C844958 7 Bytes JMP 0149E590 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3116] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 016D780D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3224] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 10424489 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3224] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 10424ACF C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EC0AD4] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EC0C1A] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EC0B9C] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EC1748] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EC161E] sptd.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9ED5ACA] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8A4D41E8 Device \Driver\NetBT \Device\NetBT_Tcpip_{3F927FE0-92D0-4116-A24B-E94E2FFF256A} 89A647A0 Device \Driver\usbuhci \Device\USBPDO-0 8A2511E8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A4641E8 Device \Driver\dmio \Device\DmControl\DmConfig 8A4641E8 Device \Driver\dmio \Device\DmControl\DmPnP 8A4641E8 Device \Driver\dmio \Device\DmControl\DmInfo 8A4641E8 Device \Driver\usbuhci \Device\USBPDO-1 8A2511E8 Device \Driver\usbehci \Device\USBPDO-2 8A23A1E8 Device \Driver\usbuhci \Device\USBPDO-3 8A2511E8 Device \Driver\usbuhci \Device\USBPDO-4 8A2511E8 Device \Driver\usbuhci \Device\USBPDO-5 8A2511E8 Device \Driver\usbehci \Device\USBPDO-6 8A23A1E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 8A4D61E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A4D61E8 Device \Driver\atapi \Device\Ide\IdePort0 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort4 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort5 [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-d [B9E13B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Ftdisk \Device\HarddiskVolume3 8A4D61E8 Device \Driver\Ftdisk \Device\HarddiskVolume4 8A4D61E8 Device \Driver\usbstor \Device\00000080 8A1507A0 Device \Driver\Ftdisk \Device\HarddiskVolume5 8A4D61E8 Device \Driver\NetBT \Device\NetBt_Wins_Export 89A647A0 Device \Driver\usbstor \Device\00000084 8A1507A0 Device \Driver\usbstor \Device\00000085 8A1507A0 Device \Driver\NetBT \Device\NetbiosSmb 89A647A0 Device \Driver\usbstor \Device\00000086 8A1507A0 Device \Driver\usbuhci \Device\USBFDO-0 8A2511E8 Device \Driver\usbuhci \Device\USBFDO-1 8A2511E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 896411E8 Device \Driver\usbehci \Device\USBFDO-2 8A23A1E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 896411E8 Device \Driver\usbuhci \Device\USBFDO-3 8A2511E8 Device \Driver\usbuhci \Device\USBFDO-4 8A2511E8 Device \Driver\Ftdisk \Device\FtControl 8A4D61E8 Device \Driver\usbuhci \Device\USBFDO-5 8A2511E8 Device \Driver\usbehci \Device\USBFDO-6 8A23A1E8 Device \FileSystem\Cdfs \Cdfs 8A3177A0 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG10.00.00.01WORKSTATION 88243979DC22A5F6B55C1CDB7A49E49746973015AAF4A2A4AE93887BB392F065A0143A34EF96560F916AB99AB8D0D7B202178AA615D0CF2A1DEC416E45549AA19F4F52B58E4E86351C79378C6775A78B815FD7F96869E5947A10D0BF9162EA4E9AB7FEA65EF55C9A55A3E7D92AEB5E26D262DFD9651AF1DB05E8927B185E97F1995251713C994FFA342730EE59C8590D78377DD480A3D4FA6A8779EF0CD1A4181C486EC7372A2911A2658D7E0286C84E6A191FBBE3A84670511F87AFD12A6F5190678EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98085D575E7D6A3B9808FEBC9E127BECC74CA6171C11EC38DE3DAC6E5AF28236E2F6EFA4A0AD42D7CEF11D9BB80F511A3F081E79875CF5532C47CBA47F45139437DF6DC894053113DEEFC7AEBCDF9067CC2A3AD804E8521730C3ED7D2D1E2F72A531934DE6C93D43B3BBB27F8A44C5C4D5E10B40F373AEF41604FC5DDEAA6C2CB7E70BCE5BCF0D1070886A8A5052CAC736349E298E76B410150428D7F26E66139F1545A199BDCC17E019BD7F9DF7F9F971BC44BF6DC592FE09D360B7AEBDBC692FDAF3CB300E2CE97048C141697336DA2CA812E38F83F84E70165E79B84210E760F40F880E0F5F0D3082CE670C59E3DAB13AE0AB56299DFAED8298CF1C7B093BCDACD14508659 ---- EOF - GMER 1.0.15 ----