GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2010-12-11 14:55:16 Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Maxtor_6E040L0 rev.NAR61590 Running: dknudpv0.exe; Driver: C:\DOCUME~1\adamss\USTAWI~1\Temp\ugnyypob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF3C04C56] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF3C04B12] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF3C050C6] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF3C04FF0] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF3C046E8] SSDT spzt.sys ZwEnumerateKey [0xF8433DA4] SSDT spzt.sys ZwEnumerateValueKey [0xF8434132] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF3C04BEC] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF3C04628] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF3C0468C] SSDT spzt.sys ZwQueryKey [0xF843420A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF3C04D0C] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF3C05194] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF3C04CCC] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF3C04E4C] INT 0x62 ? 82372BF8 INT 0x73 ? 82068BF8 INT 0x73 ? 82068BF8 INT 0x73 ? 82068BF8 INT 0x73 ? 82068BF8 INT 0x73 ? 82068BF8 INT 0x82 ? 82372BF8 Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3C114FE] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3C11322] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3C1145C] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 15F 804E2E30 4 Bytes CALL 7841EE7B PAGE ntoskrnl.exe!ObInsertObject 805648A3 5 Bytes JMP F3C0E972 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) PAGE ntoskrnl.exe!NtCreateSection 80564B1B 7 Bytes JMP F3C11326 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) PAGE ntoskrnl.exe!ZwCreateProcessEx 805885D3 7 Bytes JMP F3C11502 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) PAGE ntoskrnl.exe!ObMakeTemporaryObject 805A2BF9 5 Bytes JMP F3C0D4BA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) PAGE ntoskrnl.exe!ZwLoadDriver 805A6B26 7 Bytes JMP F3C11460 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ? spzt.sys Nie można odnaleźć określonego pliku. ! .text USBPORT.SYS!DllUnload F801362C 5 Bytes JMP 820681D8 ---- User code sections - GMER 1.0.15 ---- .text E:\Program\update\realsched.exe[1936] kernel32.dll!SetUnhandledExceptionFilter 7C810386 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4} .text E:\Mozilla Firefox\firefox.exe[2756] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 004013F0 E:\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 823E02D8 IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8446D4C] spzt.sys IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8446DA0] spzt.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8416042] spzt.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F841613E] spzt.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F84160C0] spzt.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8416800] spzt.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F84166D6] spzt.sys IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 820682D8 IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8425E9C] spzt.sys ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\services.exe[580] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003C0002 IAT C:\WINDOWS\system32\services.exe[580] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003C0000 ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software) Device \FileSystem\Ntfs \Ntfs 823711F8 AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software) Device \FileSystem\Fastfat \FatCdrom 81EB61F8 AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) Device \Driver\usbuhci \Device\USBPDO-0 821131F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{9949E236-6304-4396-A137-595C8EBBC4E7} 82150500 Device \Driver\dmio \Device\DmControl\DmIoDaemon 823DE1F8 Device \Driver\dmio \Device\DmControl\DmConfig 823DE1F8 Device \Driver\dmio \Device\DmControl\DmPnP 823DE1F8 Device \Driver\dmio \Device\DmControl\DmInfo 823DE1F8 Device \Driver\usbuhci \Device\USBPDO-1 821131F8 Device \Driver\usbuhci \Device\USBPDO-2 821131F8 Device \Driver\usbehci \Device\USBPDO-3 820591F8 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) Device \Driver\Ftdisk \Device\HarddiskVolume1 823731F8 Device \Driver\Ftdisk \Device\HarddiskVolume2 823731F8 Device \Driver\Cdrom \Device\CdRom0 820F61F8 Device \Driver\atapi \Device\Ide\IdePort0 823721F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 823721F8 Device \Driver\atapi \Device\Ide\IdePort1 823721F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 823721F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 823721F8 Device \Driver\Ftdisk \Device\HarddiskVolume3 823731F8 Device \Driver\Ftdisk \Device\HarddiskVolume4 823731F8 Device \Driver\Ftdisk \Device\HarddiskVolume5 823731F8 Device \Driver\NetBT \Device\NetBt_Wins_Export 82150500 Device \Driver\NetBT \Device\NetbiosSmb 82150500 AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) Device \Driver\usbuhci \Device\USBFDO-0 821131F8 Device \Driver\usbuhci \Device\USBFDO-1 821131F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8212A500 Device \Driver\usbuhci \Device\USBFDO-2 821131F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8212A500 Device \Driver\usbehci \Device\USBFDO-3 820591F8 Device \Driver\Ftdisk \Device\FtControl 823731F8 Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software) Device \FileSystem\Fastfat \Fat 81EB61F8 AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) Device \FileSystem\Cdfs \Cdfs 8201A408 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x68 0x42 0x04 0xA8 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 F:\Program\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x83 0xAB 0x77 0x0A ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB1 0x29 0xF9 0xA4 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE3 0x38 0xC6 0x21 ... ---- EOF - GMER 1.0.15 ----