GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-09-08 21:40:14 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6 SAMSUNG_HD250HJ rev.FH100-06 232,76GB Running: ebbsb4i1.exe; Driver: C:\DOCUME~1\Asia\USTAWI~1\Temp\pwqoqfow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0xADF58BA6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0xADF59684] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwClose [0xADF9DD80] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0xADF656F8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0xADF65744] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0xADF658DE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateKey [0xADF9D734] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0xADF65666] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSection [0xADF65788] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0xADF656AE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0xADF59BBA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0xADF65898] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0xADF5A472] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0xADF58C0C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteKey [0xADF9E446] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteValueKey [0xADF9E6FC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0xADF5DC68] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateKey [0xADF9E2B1] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0xADF9E11C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0xADF587F8] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0xAE206ED0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0xADF58C72] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0xADF5E05E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0xADF5AF5A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0xADF65722] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0xADF65766] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0xADF65902] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenKey [0xADF9DA90] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0xADF6568C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0xADF5D560] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0xADF65816] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0xADF656D6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0xADF5D94C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0xADF658BC] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0xAE206C6E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryKey [0xADF9DF97] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0xADF5ADCE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryValueKey [0xADF9DDE9] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0xADF5A924] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwRenameKey [0xAE214E1A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwRestoreKey [0xADF9CD77] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0xADF58CD8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0xADF58D3E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetContextThread [0xADF5A2EC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0xADF58892] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0xADF58A64] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetValueKey [0xADF9E54D] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0xADF589F2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0xADF5A63C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0xADF5A79E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0xADF58AEC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateProcess [0xADF5A12A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0xADF5A2CC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0xADF58DA4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0xADF596E0] ---- Kernel code sections - GMER 2.1 ---- .text ntoskrnl.exe!ZwYieldExecution + 33A 804E4B64 4 Bytes JMP CAFC4546 .text ntoskrnl.exe!ZwYieldExecution + 3C2 804E4BEC 12 Bytes [D8, 8C, F5, AD, 3E, 8D, F5, ...] .text ntoskrnl.exe!ZwYieldExecution + 46A 804E4C94 12 Bytes [3C, A6, F5, AD, 9E, A7, F5, ...] {CMP AL, 0xa6; CMC ; LODSD ; SAHF ; CMPSD ; CMC ; LODSD ; IN AL, DX; MOV DH, CH; LODSD } PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 80575B10 4 Bytes CALL ADF5B62B \SystemRoot\system32\drivers\aswSnx.sys ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF60A4000, 0x1E2E7A, 0xE8000020] ? System32\Drivers\a12noxke.SYS System nie może odnaleźć określonej ścieżki. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[200] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[200] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[200] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\sizlsearch\bin\sizlsearch.PurBrowse.exe[296] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\sizlsearch\bin\sizlsearch.PurBrowse.exe[296] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect\ProtectWindowsManager.exe[404] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect\ProtectWindowsManager.exe[404] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[484] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[484] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\acs.exe[532] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\acs.exe[532] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\sizlsearch\bin\utilsizlsearch.exe[856] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\sizlsearch\bin\utilsizlsearch.exe[856] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\PLAY ONLINE\OnlineUpdate\ouc.exe[868] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\PLAY ONLINE\OnlineUpdate\ouc.exe[868] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\System32\smss.exe[1012] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1068] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1068] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\csrss.exe[1092] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\csrss.exe[1092] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[1144] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[1144] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\services.exe[1188] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\services.exe[1188] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\wscntfy.exe[1352] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\wscntfy.exe[1352] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\Ati2evxx.exe[1400] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\Ati2evxx.exe[1400] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1484] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1484] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1580] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1596] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1596] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1616] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1616] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe[1640] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe[1640] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1660] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1660] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1752] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1752] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1776] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1776] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1792] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1792] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Java\jre7\bin\jqs.exe[1796] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Java\jre7\bin\jqs.exe[1796] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1840] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1840] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1920] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\Ati2evxx.exe[1992] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\Ati2evxx.exe[1992] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\sizlsearch\bin\sizlsearch.BrowserAdapter.exe[2128] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\sizlsearch\bin\sizlsearch.BrowserAdapter.exe[2128] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[2168] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[2168] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[2220] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[2220] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtCreateFile 7C90D090 5 Bytes JMP 019D3D20 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtFlushBuffersFile 7C90D310 5 Bytes JMP 019BC661 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtQueryFullAttributesFile 7C90D790 5 Bytes JMP 019D3820 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtReadFile 7C90D9B0 5 Bytes JMP 019BC750 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtReadFileScatter 7C90D9C0 5 Bytes JMP 0225E1FF C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtWriteFile 7C90DF60 5 Bytes JMP 019D43D0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!NtWriteFileGather 7C90DF70 5 Bytes JMP 0225E1AE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00461F4C C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 004503FC .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] KERNEL32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 021FF582 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] KERNEL32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 021FF55F C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] KERNEL32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 019D06F3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] user32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0210E5A9 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2332] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 021FF4E0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 105244B6 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 10524527 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1052825D C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2428] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 10521BFA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\sizlsearch\updatesizlsearch.exe[2696] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\sizlsearch\updatesizlsearch.exe[2696] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\wbem\unsecapp.exe[2736] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\wbem\unsecapp.exe[2736] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\RTHDCPL.EXE[2740] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\RTHDCPL.EXE[2740] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2776] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2776] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[2808] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[2808] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[2816] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[2816] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[2828] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[2828] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2832] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2832] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2832] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2852] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2852] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Samsung\Kies\Kies.exe[2884] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Samsung\Kies\Kies.exe[2884] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\ScsiCommandService2.exe[3504] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\ScsiCommandService2.exe[3504] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[3540] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[3540] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[3640] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[3640] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[3744] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[3744] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3976] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3976] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] .text C:\Documents and Settings\Asia\Moje dokumenty\Pobrane\do logów\ebbsb4i1.exe[6092] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9171AA 1 Byte [62] .text C:\Documents and Settings\Asia\Moje dokumenty\Pobrane\do logów\ebbsb4i1.exe[6092] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62] ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\system32\services.exe[1188] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[1188] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8A69A1E8 Device \FileSystem\Fastfat \FatCdrom 88C701E8 AttachedDevice \Driver\Tcpip \Device\Ip {9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys Device \Driver\usbuhci \Device\USBPDO-0 8A3ED1E8 Device \Driver\usbuhci \Device\USBPDO-1 8A3ED1E8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A62B1E8 Device \Driver\dmio \Device\DmControl\DmConfig 8A62B1E8 Device \Driver\dmio \Device\DmControl\DmPnP 8A62B1E8 Device \Driver\dmio \Device\DmControl\DmInfo 8A62B1E8 Device \Driver\usbuhci \Device\USBPDO-2 8A3ED1E8 Device \Driver\usbuhci \Device\USBPDO-3 8A3ED1E8 Device \Driver\usbehci \Device\USBPDO-4 8A3C01E8 AttachedDevice \Driver\Tcpip \Device\Tcp {9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys Device \Driver\PCI_NTPNP3782 \Device\00000057 sptd.sys Device \Driver\Ftdisk \Device\HarddiskVolume1 8A69C1E8 Device \Driver\Cdrom \Device\CdRom0 8A3AE1E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A69C1E8 Device \Driver\atapi \Device\Ide\IdePort0 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-6 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-e [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-19 [F72D0B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Ftdisk \Device\HarddiskVolume3 8A69C1E8 Device \Driver\Ftdisk \Device\HarddiskVolume4 8A69C1E8 Device \Driver\Ftdisk \Device\HarddiskVolume5 8A69C1E8 Device \Driver\dtsoftbus01 \Device\DTSoftBusCtl 8A1E41E8 Device \Driver\NetBT \Device\NetBt_Wins_Export 8A370790 Device \Driver\NetBT \Device\NetbiosSmb 8A370790 Device \Driver\usbstor \Device\00000085 8A2B65D8 Device \Driver\usbstor \Device\00000086 8A2B65D8 Device \Driver\usbstor \Device\00000087 8A2B65D8 Device \Driver\usbstor \Device\00000088 8A2B65D8 AttachedDevice \Driver\Tcpip \Device\Udp {9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys Device \Driver\usbstor \Device\00000089 8A2B65D8 AttachedDevice \Driver\Tcpip \Device\RawIp {9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys Device \Driver\usbuhci \Device\USBFDO-0 8A3ED1E8 Device \Driver\usbuhci \Device\USBFDO-1 8A3ED1E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A33D700 Device \Driver\usbuhci \Device\USBFDO-2 8A3ED1E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A33D700 Device \Driver\usbuhci \Device\USBFDO-3 8A3ED1E8 Device \Driver\usbehci \Device\USBFDO-4 8A3C01E8 Device \Driver\Ftdisk \Device\FtControl 8A69C1E8 Device \Driver\NetBT \Device\NetBT_Tcpip_{39843515-6625-42AD-A80C-A877A02A0E59} 8A370790 Device \Driver\a12noxke \Device\Scsi\a12noxke1 8A384618 Device \FileSystem\Fastfat \Fat 88C701E8 AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys Device \FileSystem\Cdfs \Cdfs 8A210790 ---- Trace I/O - GMER 2.1 ---- Trace ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys sptd.sys hal.dll >>UNKNOWN [0x8a64c8ac]<< 8a64c8ac Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a5ffab8] 8a5ffab8 Trace 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-6[0x8a588b00] 8a588b00 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF3 0xE5 0x52 0xC9 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCE 0x3D 0xA3 0x3A ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x35 0x0E 0xDA 0xDF ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x87 0xB8 0x63 0x45 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xF3 0x0C 0xD9 0x2A ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x35 0x0E 0xDA 0xDF ... ---- EOF - GMER 2.1 ----