GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-06-15 20:42:52 Windows 5.1.2600 Dodatek Service Pack 2 Running: ktc5lq7t.exe; Driver: C:\DOCUME~1\KOLEGI~1\USTAWI~1\Temp\afkdiaob.sys ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\System32\svchost.exe[952] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 016154C0 .text C:\WINDOWS\System32\svchost.exe[952] NETAPI32.dll!NetpwPathCanonicalize 6FF4A3A9 5 Bytes JMP 01615460 .text C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 007D54C0 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\services.exe[696] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[696] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@DisplayName itdfn Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@Type 32 Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@Start 2 Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@ErrorControl 0 Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon@Description Dostarcza interfejs i model obiektowy w celu uzyskiwania dost?pu do informacji zarz?dzania o systemie operacyjnym, urz?dzeniach, aplikacjach i us?ugach. Je?li ta us?uga zostanie zatrzymana, wi?kszo?? oprogramowania opartego na systemie Windows nie b?dzie dzia?a? w?a?ciwie. Je?li ta us?uga zostanie wy??czona, uruchomienie us?ug od niej zale?nych nie powiedzie si?. Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\Eventmon\Parameters@ServiceDll C:\WINDOWS\system32\etaeww.dll Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 D:\bzyk 2\Program Files\deamon tools\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x56 0xFC 0xB7 0xA2 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6C 0x9B 0x6A 0xD2 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA8 0x28 0xA5 0xB8 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xA8 0x28 0xA5 0xB8 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x46 0x5C 0x7D 0xF9 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x56 0xFC 0xB7 0xA2 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6C 0x9B 0x6A 0xD2 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA8 0x28 0xA5 0xB8 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xA8 0x28 0xA5 0xB8 ... Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@DisplayName itdfn Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@Type 32 Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@Start 2 Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@ErrorControl 0 Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon@Description Dostarcza interfejs i model obiektowy w celu uzyskiwania dost?pu do informacji zarz?dzania o systemie operacyjnym, urz?dzeniach, aplikacjach i us?ugach. Je?li ta us?uga zostanie zatrzymana, wi?kszo?? oprogramowania opartego na systemie Windows nie b?dzie dzia?a? w?a?ciwie. Je?li ta us?uga zostanie wy??czona, uruchomienie us?ug od niej zale?nych nie powiedzie si?. Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\Eventmon\Parameters@ServiceDll C:\WINDOWS\system32\etaeww.dll Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x46 0x5C 0x7D 0xF9 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x56 0xFC 0xB7 0xA2 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6C 0x9B 0x6A 0xD2 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA8 0x28 0xA5 0xB8 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xA8 0x28 0xA5 0xB8 ... ---- EOF - GMER 1.0.15 ----