GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-11-01 20:48:36 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 IC35L040AVVA07-0 rev.VA2OA51A 37,27GB Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pxtdqpow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwAssignProcessToJobObject [0xAC02CF20] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwCreateThread [0xAC02D260] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDebugActiveProcess [0xAC02D520] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDuplicateObject [0xAC02D040] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwLoadDriver [0xAC02D320] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenProcess [0xAC02CDC0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenThread [0xAC02CE80] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwProtectVirtualMemory [0xAC02CFE0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwQueueApcThread [0xAC02D0A0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwReplaceKey [0xAC02D6E0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwRestoreKey [0xAC02D6A0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetContextThread [0xAC02CFA0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetInformationThread [0xAC02CF60] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSecurityObject [0xAC02D0E0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSystemInformation [0xAC02D2E0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendProcess [0xAC02CE20] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendThread [0xAC02CEA0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSystemDebugControl [0xAC02D2A0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateProcess [0xAC02CDE0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateThread [0xAC02CEE0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwWriteVirtualMemory [0xAC02D060] INT 0x62 ? 89BD1CC8 INT 0x63 ? 89C11CC8 INT 0x82 ? 89BD1CC8 INT 0xA4 ? 89C11CC8 INT 0xB4 ? 89C11CC8 ---- Kernel code sections - GMER 2.1 ---- .text ntoskrnl.exe!_abnormal_termination + 440 804E2A14 12 Bytes [20, CE, 02, AC, A0, CE, 02, ...] {AND DH, CL; ADD CH, [EAX-0x5f53fd32]; ROL [EDX], CL; LODSB } .sptd1 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd1" section [0xF75BC346] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1568] kernel32.dll!SetUnhandledExceptionFilter 7C844EE5 4 Bytes [C2, 04, 00, 00] ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 89C101F8 Device \FileSystem\Fastfat \FatCdrom 89A1B430 Device \Driver\usbuhci \Device\USBPDO-0 89ACB1F8 Device \Driver\usbuhci \Device\USBPDO-1 89ACB1F8 Device \Driver\usbuhci \Device\USBPDO-2 89ACB1F8 Device \Driver\usbehci \Device\USBPDO-3 898D61F8 AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{F7838236-4C7B-4455-A67E-E288F312BC53} 897A8430 Device \Driver\USBSTOR \Device\00000058 899C7430 Device \Driver\USBSTOR \Device\00000059 899C7430 Device \Driver\Cdrom \Device\CdRom0 89AAC1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 897A8430 Device \Driver\NetBT \Device\NetbiosSmb 897A8430 Device \Driver\usbuhci \Device\USBFDO-0 89ACB1F8 Device \Driver\usbuhci \Device\USBFDO-1 89ACB1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8964E430 Device \Driver\usbuhci \Device\USBFDO-2 89ACB1F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8964E430 Device \Driver\usbehci \Device\USBFDO-3 898D61F8 Device \FileSystem\Fastfat \Fat 89A1B430 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys Device \FileSystem\Cdfs \Cdfs 899B6430 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE8 0xFC 0xE4 0x42 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE8 0xFC 0xE4 0x42 ... ---- EOF - GMER 2.1 ----