GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-03-20 13:21:10 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 ST3500418AS rev.CC38 465,76GB Running: 9be9i8hb.exe; Driver: C:\DOCUME~1\MM\USTAWI~1\Temp\pwtdykoc.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0xA9DB0AC4] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwAllocateVirtualMemory [0xAA0CB0BA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0xA9DB15A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwClose [0xA9DF75A0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0xA9DBD63C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0xA9DBD688] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0xA9DBD822] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateKey [0xA9DF6F54] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0xA9DBD5AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSection [0xA9DBD6CC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0xA9DBD5F2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0xA9DB1AD8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0xA9DBD7DC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0xA9DB2390] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0xA9DB0B2A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteKey [0xA9DF7C66] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteValueKey [0xA9DF7F1C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0xA9DB5B86] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateKey [0xA9DF7AD1] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0xA9DF793C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0xA9DB0716] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0xAA0CB574] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0xA9DB0B90] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0xA9DB5F7C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0xA9DB2E78] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0xA9DBD666] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0xA9DBD6AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0xA9DBD846] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenKey [0xA9DF72B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0xA9DBD5D0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0xA9DB547E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0xA9DBD75A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0xA9DBD61A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0xA9DB586A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0xA9DBD800] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0xAA0CB312] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryKey [0xA9DF77B7] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0xA9DB2CEC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryValueKey [0xA9DF7609] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0xA9DB2842] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwRenameKey [0xAA0D9358] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwReplaceKey [0xAA0D9CC4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwRestoreKey [0xA9DF6597] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0xA9DB0BF6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0xA9DB0C5C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetContextThread [0xA9DB220A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0xA9DB07B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0xA9DB0982] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetValueKey [0xA9DF7D6D] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0xA9DB0910] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0xA9DB255A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0xA9DB26BC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0xA9DB0A0A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateProcess [0xA9DB2048] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0xA9DB21EA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0xA9DB0CC2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0xA9DB15FE] INT 0x62 ? 865D8BF8 INT 0x74 ? 863B2F00 INT 0x82 ? 865D8BF8 INT 0x84 ? 863B2F00 INT 0x94 ? 863B2F00 INT 0xA4 ? 863B2F00 ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2FD4 805048BC 12 Bytes [F6, 0B, DB, A9, 5C, 0C, DB, ...] .text ntkrnlpa.exe!ZwCallbackReturn + 307C 80504964 12 Bytes [5A, 25, DB, A9, BC, 26, DB, ...] {POP EDX; AND EAX, 0x26bca9db; FLD TBYTE [ECX-0x5624f5f6]} PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 805A64DC 4 Bytes CALL A9DB3549 \SystemRoot\system32\drivers\aswSnx.sys ? spfy.sys Nie można odnaleźć określonego pliku. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[496] kernel32.dll!SetUnhandledExceptionFilter 7C844EE5 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1380] kernel32.dll!SetUnhandledExceptionFilter 7C844EE5 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 011CD441 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 011CD181 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 011CD2B9 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 011CD1BB C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 015B3D7D C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 011CD5E5 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 015B3DCD C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0087900C C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 003003FC .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] KERNEL32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 015A041B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] KERNEL32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 0159ECDA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] KERNEL32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 0135497B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] user32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0208FA10 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2064] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 0159D492 C:\Program Files\Mozilla Firefox\xul.dll ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\system32\services.exe[788] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[788] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 865661F8 AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.sys Device \Driver\usbuhci \Device\USBPDO-0 863AE4D8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 865681F8 Device \Driver\dmio \Device\DmControl\DmConfig 865681F8 Device \Driver\dmio \Device\DmControl\DmPnP 865681F8 Device \Driver\dmio \Device\DmControl\DmInfo 865681F8 Device \Driver\usbuhci \Device\USBPDO-1 863AE4D8 Device \Driver\usbuhci \Device\USBPDO-2 863AE4D8 Device \Driver\usbuhci \Device\USBPDO-3 863AE4D8 Device \Driver\usbehci \Device\USBPDO-4 863BD500 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.sys Device \Driver\USBSTOR \Device\00000070 85E6C500 Device \Driver\Ftdisk \Device\HarddiskVolume1 865D91F8 Device \Driver\Ftdisk \Device\HarddiskVolume2 865D91F8 Device \Driver\Cdrom \Device\CdRom0 8633D1F8 Device \Driver\atapi \Device\Ide\IdePort0 [F731CB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F731CB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [F731CB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 [F731CB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\USBSTOR \Device\00000075 85E6C500 Device \Driver\NetBT \Device\NetBt_Wins_Export 85EBD1F8 Device \Driver\NetBT \Device\NetbiosSmb 85EBD1F8 AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.sys AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.sys Device \Driver\usbuhci \Device\USBFDO-0 863AE4D8 Device \Driver\usbuhci \Device\USBFDO-1 863AE4D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{6BB95FC4-D6F4-45E4-A8F8-24E1D2011EA3} 85EBD1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85EB81F8 Device \Driver\usbuhci \Device\USBFDO-2 863AE4D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 85EB81F8 Device \Driver\usbuhci \Device\USBFDO-3 863AE4D8 Device \Driver\usbehci \Device\USBFDO-4 863BD500 Device \Driver\Ftdisk \Device\FtControl 865D91F8 Device \FileSystem\Cdfs \Cdfs 85E3A500 ---- Trace I/O - GMER 2.1 ---- Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spfy.sys >>UNKNOWN [0x86588938]<< 86588938 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x864fbab8] 864fbab8 Trace 3 CLASSPNP.SYS[f760cfd7] -> nt!IofCallDriver -> \Device\00000061[0x8652bf18] 8652bf18 Trace 5 ACPI.sys[f7387620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-3[0x8654e940] 8654e940 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBE 0xDA 0x7A 0xDC ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBE 0xDA 0x7A 0xDC ... ---- EOF - GMER 2.1 ----