GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-04-29 09:45:13 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e Hitachi_HTS542525K9SA00 rev.BBFOC31P 0,00MB Running: ro7cn67w.exe; Driver: C:\DOCUME~1\tomek\USTAWI~1\Temp\awqcrpog.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwAssignProcessToJobObject [0xA802B4B0] SSDT \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ZwCreateSection [0xBA5DA7EE] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwCreateThread [0xA802B7F0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDebugActiveProcess [0xA802BAB0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDuplicateObject [0xA802B5D0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwLoadDriver [0xA802B8B0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenProcess [0xA802B350] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenThread [0xA802B410] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwProtectVirtualMemory [0xA802B570] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwQueueApcThread [0xA802B630] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetContextThread [0xA802B530] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetInformationThread [0xA802B4F0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSecurityObject [0xA802B670] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSystemInformation [0xA802B870] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendProcess [0xA802B3B0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendThread [0xA802B430] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSystemDebugControl [0xA802B830] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateProcess [0xA802B370] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateThread [0xA802B470] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwWriteVirtualMemory [0xA802B5F0] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2818 80502074 12 Bytes [B0, B3, 02, A8, 30, B4, 02, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 74, 85, 00] {SUB [EBP+EAX*4+0x0], DH} .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 77, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 74, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 75, 85, 00] {TEST AL, 0x75; TEST [EAX], EAX} .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B915B8E .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 76, 85, 00] {TEST AL, 0x76; TEST [EAX], EAX} .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 75, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 76, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B915BFF .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 74, 85, 00] {TEST AL, 0x74; TEST [EAX], EAX} .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B915D2D .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 75, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 76, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 77, 85, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[516] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe[1816] kernel32.dll!SetUnhandledExceptionFilter 7C8449CD 4 Bytes [C2, 04, 00, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 40, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 43, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 40, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 41, D1, 00] {TEST AL, 0x41; ROL DWORD [EAX], 0x1} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91A75A .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 42, D1, 00] {TEST AL, 0x42; ROL DWORD [EAX], 0x1} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 41, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 42, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91A7CB .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 40, D1, 00] {TEST AL, 0x40; ROL DWORD [EAX], 0x1} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B91A8F9 .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 41, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 42, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 43, D1, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2060] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 80, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 83, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 80, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 81, B7, 00] {TEST AL, 0x81; MOV BH, 0x0} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B918D9A .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 82, B7, 00] {TEST AL, 0x82; MOV BH, 0x0} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 81, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 82, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B918E0B .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 80, B7, 00] {TEST AL, 0x80; MOV BH, 0x0} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B918F39 .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 81, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 82, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 83, B7, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, F0, 8D, 00] {SUB AL, DH; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, F3, 8D, 00] {SUB BL, DH; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, F0, 8D, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, F1, 8D, 00] {TEST AL, 0xf1; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91640A .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, F2, 8D, 00] {TEST AL, 0xf2; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, F1, 8D, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, F2, 8D, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91647B .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, F0, 8D, 00] {TEST AL, 0xf0; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B9165A9 .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, F1, 8D, 00] {SUB CL, DH; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, F2, 8D, 00] {SUB DL, DH; LEA EAX, [EAX]} .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, F3, 8D, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2440] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[3364] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [18, 00, C3, 01] .text C:\Program Files\Google\Chrome\Application\chrome.exe[3364] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys AttachedDevice \FileSystem\Fastfat \Fat eamon.sys AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys ---- EOF - GMER 2.1 ----