GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-01-16 07:36:17 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-5 ST9250315AS rev.0002SDM1 232,89GB Running: l1jl01lg.exe; Driver: C:\DOCUME~1\madzia\USTAWI~1\Temp\pgliakoc.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x9ED21AC4] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwAllocateVirtualMemory [0x9F0730BA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x9ED225A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwClose [0x9ED685A0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x9ED2E63C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x9ED2E688] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x9ED2E822] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateKey [0x9ED67F54] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x9ED2E5AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSection [0x9ED2E6CC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9ED2E5F2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x9ED22AD8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x9ED2E7DC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x9ED23390] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x9ED21B2A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteKey [0x9ED68C66] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteValueKey [0x9ED68F1C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x9ED26B86] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateKey [0x9ED68AD1] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0x9ED6893C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x9ED21716] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x9F073574] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x9ED21B90] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x9ED26F7C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x9ED23E78] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x9ED2E666] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x9ED2E6AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x9ED2E846] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenKey [0x9ED682B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x9ED2E5D0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x9ED2647E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x9ED2E75A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x9ED2E61A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x9ED2686A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x9ED2E800] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x9F073312] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryKey [0x9ED687B7] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x9ED23CEC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryValueKey [0x9ED68609] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0x9ED23842] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwRenameKey [0x9F081358] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwReplaceKey [0x9F081CC4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwRestoreKey [0x9ED67597] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x9ED21BF6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x9ED21C5C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetContextThread [0x9ED2320A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x9ED217B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x9ED21982] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetValueKey [0x9ED68D6D] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x9ED21910] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x9ED2355A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x9ED236BC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x9ED21A0A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateProcess [0x9ED23048] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x9ED231EA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x9ED21CC2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x9ED225FE] INT 0x62 ? 8A540CB8 INT 0x83 ? 8A540CB8 INT 0x94 ? 8A309F00 INT 0xA4 ? 8A309F00 INT 0xB4 ? 8A309F00 ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 23FC 80501C24 4 Bytes [22, E8, D2, 9E] .text ntkrnlpa.exe!ZwCallbackReturn + 2538 80501D60 4 Bytes [46, E8, D2, 9E] .text ntkrnlpa.exe!ZwCallbackReturn + 2570 80501D98 4 Bytes [00, E8, D2, 9E] .text ntkrnlpa.exe!ZwCallbackReturn + 26B0 80501ED8 12 Bytes [F6, 1B, D2, 9E, 5C, 1C, D2, ...] .text ntkrnlpa.exe!ZwCallbackReturn + 2758 80501F80 12 Bytes [5A, 35, D2, 9E, BC, 36, D2, ...] {POP EDX; XOR EAX, 0x36bc9ed2; RCR [ESI-0x612de5f6], CL} PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 8059B7C0 4 Bytes CALL 9ED24549 \SystemRoot\system32\drivers\aswSnx.sys .sptd1 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd1" section [0xBA78B774] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1512] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtCreateFile 7C90D090 5 Bytes JMP 018A9E90 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtFlushBuffersFile 7C90D310 5 Bytes JMP 01890AB4 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtQueryFullAttributesFile 7C90D790 5 Bytes JMP 018907D0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtReadFile 7C90D9B0 5 Bytes JMP 018909B0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtReadFileScatter 7C90D9C0 5 Bytes JMP 022AFB4B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtWriteFile 7C90DF60 5 Bytes JMP 018AAD50 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!NtWriteFileGather 7C90DF70 5 Bytes JMP 022AFAFA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00881F42 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 003003FC .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] KERNEL32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 021D4F01 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] KERNEL32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 021D4EDE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] KERNEL32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 018A6805 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] user32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 020CBB9D C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 021D4E5F C:\Program Files\Mozilla Firefox\xul.dll ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\system32\services.exe[828] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[828] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8A53F1F8 AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{E58FC092-7B69-4679-87EA-5F0BD2BA34EC} 8A33E440 Device \Driver\usbohci \Device\USBPDO-0 8A26D440 Device \Driver\usbohci \Device\USBPDO-1 8A26D440 Device \Driver\usbehci \Device\USBPDO-2 8A26A440 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.sys Device \Driver\Cdrom \Device\CdRom0 8A35F440 Device \Driver\atapi \Device\Ide\IdePort0 [BA642B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [BA642B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [BA642B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-5 [BA642B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 [BA642B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 8A33E440 Device \Driver\NetBT \Device\NetbiosSmb 8A33E440 AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{97384133-8B0A-4B7B-B0E0-04A1F9BB315C} 8A33E440 AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.sys Device \Driver\usbohci \Device\USBFDO-0 8A26D440 Device \Driver\usbohci \Device\USBFDO-1 8A26D440 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A336440 Device \Driver\usbehci \Device\USBFDO-2 8A26A440 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A336440 Device \FileSystem\Cdfs \Cdfs 8A324440 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x70 0x1D 0xB6 0x49 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x70 0xBC 0xCE 0x45 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCF 0x63 0x45 0x59 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xFF 0x96 0x7D 0xF2 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x70 0x1D 0xB6 0x49 ... ---- EOF - GMER 2.1 ----