GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2011-03-02 22:30:39 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-10 ST3250410AS rev.3.AAC Running: lrd2f3l8.exe; Driver: C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\uwncaaob.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF773CEB0] SSDT sptd.sys ZwEnumerateKey [0xF7771018] SSDT sptd.sys ZwEnumerateValueKey [0xF77713A6] SSDT sptd.sys ZwOpenKey [0xF773CE90] SSDT sptd.sys ZwQueryKey [0xF777147E] SSDT sptd.sys ZwQueryValueKey [0xF77712FE] SSDT sptd.sys ZwSetValueKey [0xF7771510] INT 0x62 ? 867A1CB8 INT 0x63 ? 865C8CB8 INT 0x73 ? 865C8CB8 INT 0x73 ? 865C8CB8 INT 0x82 ? 867A1CB8 INT 0x83 ? 867A1CB8 INT 0x83 ? 867A1CB8 INT 0x83 ? 865C8CB8 INT 0x83 ? 867A1CB8 INT 0xB4 ? 865C8CB8 ---- Kernel code sections - GMER 1.0.15 ---- .sptd2 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd2" section [0xF77ACB0B] ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6310380, 0x550AF5, 0xE8000020] .text USBPORT.SYS!DllUnload F62F08AC 5 Bytes JMP 865C81C8 ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1464] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 1040C35B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3744] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 867D12F8 IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_ULONG] [F770221E] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!READ_PORT_UCHAR] [F770171C] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_UCHAR] [F7701EFE] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F770171C] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7701900] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F7701842] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F77020DC] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F7701EFE] sptd.sys IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 865C82F8 IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7715EFA] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 867A01E8 AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset ) Device \Driver\usbuhci \Device\USBPDO-0 8647F1E8 Device \Driver\NetBT \Device\NetBT_Tcpip_{3B733141-A108-4F96-A1C5-3503566469F1} 8640F430 Device \Driver\usbuhci \Device\USBPDO-1 8647F1E8 Device \Driver\usbuhci \Device\USBPDO-2 8647F1E8 Device \Driver\usbuhci \Device\USBPDO-3 8647F1E8 Device \Driver\usbehci \Device\USBPDO-4 864681E8 Device \Driver\Cdrom \Device\CdRom0 863A0430 Device \Driver\atapi \Device\Ide\IdePort0 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1b [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 [F7653B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 8640F430 Device \Driver\usbuhci \Device\USBFDO-0 8647F1E8 Device \Driver\usbuhci \Device\USBFDO-1 8647F1E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86261430 Device \Driver\usbuhci \Device\USBFDO-2 8647F1E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 86261430 Device \Driver\usbuhci \Device\USBFDO-3 8647F1E8 Device \Driver\usbehci \Device\USBFDO-4 864681E8 Device \FileSystem\Cdfs \Cdfs 86423430 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -2073862318 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1628398185 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3D 0x9B 0x3E 0x4E ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3D 0x9B 0x3E 0x4E ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3D 0x9B 0x3E 0x4E ... ---- EOF - GMER 1.0.15 ----