GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-07-01 14:59:28 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\0000006d WDC_WD2500AAKS-00L9A0 rev.01.03E01 232,88GB Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\ffadapoc.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0xB63CEACC] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwAllocateVirtualMemory [0xB688F31C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0xB63CF5AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwClose [0xB6415600] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0xB63DB67A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0xB63DB6C6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0xB63DB860] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateKey [0xB6414FB4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0xB63DB5E8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSection [0xB63DB70A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0xB63DB630] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0xB63CFAE0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0xB63DB81A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0xB63D0398] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0xB63CEB32] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteKey [0xB6415CC6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteValueKey [0xB6415F7C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0xB63D3BEA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateKey [0xB6415B31] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0xB641599C] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwFreeVirtualMemory [0xB688F3F4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0xB63CE71E] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0xB688F7D6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0xB63CEB98] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0xB63D3FE0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0xB63D0EDC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0xB63DB6A4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0xB63DB6E8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0xB63DB884] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenKey [0xB6415310] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0xB63DB60E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0xB63D34E2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0xB63DB798] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0xB63DB658] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0xB63D38CE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0xB63DB83E] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0xB688F574] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryKey [0xB6415817] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0xB63D0CF4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryValueKey [0xB6415669] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0xB63D084A] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwRenameKey [0xB689CD24] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwReplaceKey [0xB689D690] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwRestoreKey [0xB64145F7] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0xB63CEBFE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0xB63CEC64] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetContextThread [0xB63D0212] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0xB63CE7B8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0xB63CE98A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetValueKey [0xB6415DCD] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0xB63CE918] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0xB63D0562] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0xB63D06C4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0xB63CEA12] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateProcess [0xB63D0050] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0xB63D01F2] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwUnloadDriver [0xB688C7BE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0xB63CECCA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0xB63CF606] INT 0x62 ? 8B039CB8 INT 0x83 ? 8B008CB8 INT 0xA4 ? 8ADB6E70 INT 0xB4 ? 8ADB6E70 ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2BE8 80504474 4 Bytes JMP BEDAB63C .text ntkrnlpa.exe!ZwCallbackReturn + 2C70 805044FC 4 Bytes [E8, B5, 3D, B6] .text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504560 4 Bytes JMP 88B63D3B .text ntkrnlpa.exe!ZwCallbackReturn + 2F10 8050479C 12 Bytes [FE, EB, 3C, B6, 64, EC, 3C, ...] .text ntkrnlpa.exe!ZwCallbackReturn + 2FA8 80504834 4 Bytes JMP E7A8FE75 .text ... PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 805A648C 4 Bytes CALL B63D15AD \SystemRoot\system32\drivers\aswSnx.sys .sptd1 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd1" section [0xBA783B2E] .sfrelocÿÿÿÿsfsync03unknown last section [0xBA8E5000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xBA8E5000, 0xA20, 0x40000040] .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9204360, 0x37388D, 0xE8000020] .text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB5C86300, 0x3AF78, 0xE8000020] .text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xBABD8300, 0x1BCE, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[972] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1280] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtCreateFile 7C90D090 5 Bytes JMP 012C0BCB C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtFlushBuffersFile 7C90D310 5 Bytes JMP 012C0916 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtQueryFullAttributesFile 7C90D790 5 Bytes JMP 012C0A43 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtReadFile 7C90D9B0 5 Bytes JMP 012C0950 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtReadFileScatter 7C90D9C0 5 Bytes JMP 015D9BCE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtWriteFile 7C90DF60 5 Bytes JMP 012C0D6F C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!NtWriteFileGather 7C90DF70 5 Bytes JMP 015D9C1E C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0087921C C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 003003FC .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] KERNEL32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 015C6DFA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] KERNEL32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 015C5622 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] KERNEL32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 01366358 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] user32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 01FD8E4A C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2848] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 015C3E16 C:\Program Files\Mozilla Firefox\xul.dll ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8B0071E8 Device \FileSystem\Fastfat \FatCdrom 8AA88430 Device \Driver\NetBT \Device\NetBT_Tcpip_{D8A6DD57-39DB-4229-9337-F1A6AC70A2F6} 8AA97430 AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.sys Device \Driver\usbohci \Device\USBPDO-0 8AE84430 Device \Driver\usbehci \Device\USBPDO-1 8AE7B1E8 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.sys Device \Driver\Cdrom \Device\CdRom0 8AE711E8 Device \Driver\atapi \Device\Ide\IdePort0 [BA5F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 sfsync03.sys Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [BA5F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync03.sys Device \Driver\atapi \Device\Ide\IdePort1 [BA5F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 sfsync03.sys Device \Driver\NetBT \Device\NetBt_Wins_Export 8AA97430 Device \Driver\NetBT \Device\NetbiosSmb 8AA97430 AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.sys AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.sys Device \Driver\usbohci \Device\USBFDO-0 8AE84430 Device \Driver\nvata \Device\0000006d 8B0081E8 Device \Driver\nvata \Device\0000006d sfsync03.sys Device \Driver\usbehci \Device\USBFDO-1 8AE7B1E8 Device \Driver\nvata \Device\NvAta0 8B0081E8 Device \Driver\nvata \Device\NvAta0 sfsync03.sys Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89B6A1E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 89B6A1E8 Device \FileSystem\Fastfat \Fat 8AA88430 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys Device \FileSystem\Cdfs \Cdfs 8ADC5430 ---- Trace I/O - GMER 2.1 ---- Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync03.sys sfsync02.sys >>UNKNOWN [0x8b0081e8]<< 8b0081e8 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8af2aab8] 8af2aab8 Trace 3 CLASSPNP.SYS[ba908fd7] -> nt!IofCallDriver -> \Device\0000006e[0x8af60f18] 8af60f18 Trace 5 ACPI.sys[ba663620] -> nt!IofCallDriver -> \Device\0000006d[0x8af91030] 8af91030 Trace \Driver\nvata[0x8af62a08] -> IRP_MJ_CREATE -> 0x8b0081e8 8b0081e8 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE9 0x23 0x53 0x21 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0xB7 0xB5 0x82 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xBB 0x80 0x00 0x78 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x31 0xCD 0xC9 0xD7 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE9 0x23 0x53 0x21 ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\Program Files\LucasArts\LEGO\xae Indiana Jones\x2122 2\Audio\Audio.CFG 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\Program Files\LucasArts\LEGO\xae Indiana Jones\x2122 2\Audio\_CutScenes\AkatorHub_Intro.ogg 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\Program Files\LucasArts\LEGO\xae Indiana Jones\x2122 2\Audio\_Music\1_0_HUB_1Nepal_Qui.ogg 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\Program Files\LucasArts\LEGO\xae Indiana Jones\x2122 2\Movies\PC\attract.bik 1 ---- EOF - GMER 2.1 ----