GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2010-12-27 00:24:41 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_SP2014N rev.VC100-33 Running: i0cesme4.exe; Driver: C:\DOCUME~1\ROUTIE~1.ROU\USTAWI~1\Temp\pwldrpow.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF74ED0D0] SSDT sptd.sys ZwEnumerateKey [0xF74F2FB2] SSDT sptd.sys ZwEnumerateValueKey [0xF74F3340] SSDT sptd.sys ZwOpenKey [0xF74ED0B0] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB41626C0] SSDT sptd.sys ZwQueryKey [0xF74F3418] SSDT sptd.sys ZwQueryValueKey [0xF74F3298] SSDT sptd.sys ZwSetValueKey [0xF74F34AA] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB4162770] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB4162810] SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB41628B0] ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .xreloc C:\WINDOWS\system32\drivers\ps6ajjab.sys unknown last section [0xF7886000, 0x8F0, 0x40000040] .xreloc C:\WINDOWS\system32\drivers\ps6ajjac.sys unknown last section [0xF7875000, 0x8DA, 0x40000040] .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB722B360, 0x3CEED5, 0xE8000020] .text USBPORT.SYS!DllUnload B720B8AC 5 Bytes JMP 899CB1C8 init C:\WINDOWS\system32\drivers\p17filt.sys entry point in "init" section [0xB6F39180] ---- User code sections - GMER 1.0.15 ---- ? C:\Program Files\AVG\AVG10\avgwdsvc.exe[520] C:\WINDOWS\system32\SHLWAPI.dll IMAGE_DOS_SIGNATURE not found; .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1180] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 10402342 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3880] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F750406C] sptd.sys IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7504018] sptd.sys IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75269AE] sptd.sys IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F750406C] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74EDAD4] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74EDC1A] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74EDB9C] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74EE748] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74EE61E] sptd.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F750329A] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 89C091E8 AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. ) Device \FileSystem\Udfs \UdfsCdRom 89730408 Device \FileSystem\Udfs \UdfsDisk 89730408 Device \Driver\usbuhci \Device\USBPDO-0 899CA1E8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 89C0B1E8 Device \Driver\dmio \Device\DmControl\DmConfig 89C0B1E8 Device \Driver\dmio \Device\DmControl\DmPnP 89C0B1E8 Device \Driver\dmio \Device\DmControl\DmInfo 89C0B1E8 Device \Driver\usbuhci \Device\USBPDO-1 899CA1E8 Device \Driver\usbuhci \Device\USBPDO-2 899CA1E8 Device \Driver\usbuhci \Device\USBPDO-3 899CA1E8 Device \Driver\usbehci \Device\USBPDO-4 8999D1E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 89B9A1E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 89B9A1E8 Device \Driver\Cdrom \Device\CdRom0 8995C1E8 Device \Driver\atapi \Device\Ide\IdePort0 [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F7837B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Ftdisk \Device\HarddiskVolume3 89B9A1E8 Device \Driver\Ftdisk \Device\HarddiskVolume4 89B9A1E8 Device \Driver\NetBT \Device\NetBt_Wins_Export 88EC9790 Device \Driver\NetBT \Device\NetbiosSmb 88EC9790 Device \Driver\usbuhci \Device\USBFDO-0 899CA1E8 Device \Driver\usbuhci \Device\USBFDO-1 899CA1E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88EB5518 Device \Driver\NetBT \Device\NetBT_Tcpip_{03D01164-A0C7-4BCC-A419-1D55826A317A} 88EC9790 Device \Driver\usbuhci \Device\USBFDO-2 899CA1E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 88EB5518 Device \Driver\usbuhci \Device\USBFDO-3 899CA1E8 Device \Driver\usbehci \Device\USBFDO-4 8999D1E8 Device \Driver\Ftdisk \Device\FtControl 89B9A1E8 Device \Driver\iteatapi \Device\Scsi\iteatapi1 89C0A1E8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF3 0x7A 0xFB 0x18 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x67 0x9C 0x32 0x69 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x94 0x1D 0x8F 0x76 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x6A 0x0E 0x75 0x89 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x6A 0x0E 0x75 0x89 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF3 0x7A 0xFB 0x18 ...