GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-10-20 18:42:17 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0 Running: 2q7ybemp.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\kwdyikog.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF74FEA50] SSDT sptd.sys ZwEnumerateKey [0xF7532FFE] SSDT sptd.sys ZwEnumerateValueKey [0xF753338C] SSDT sptd.sys ZwOpenKey [0xF74FEA30] SSDT sptd.sys ZwQueryKey [0xF7533464] SSDT sptd.sys ZwQueryValueKey [0xF75332E4] SSDT sptd.sys ZwSetValueKey [0xF75334F6] INT 0x63 ? 8AB5BCC8 INT 0x63 ? 89C6FCC8 INT 0x63 ? 89C6FCC8 INT 0x63 ? 89C6FCC8 INT 0x63 ? 8AB5BCC8 INT 0x73 ? 89C6FCC8 INT 0x94 ? 89C6FCC8 INT 0xA4 ? 89C6FCC8 ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!ZwYieldExecution + 11A 804E4974 4 Bytes JMP E7D7F74F .text ntoskrnl.exe!ZwYieldExecution + 252 804E4AAC 4 Bytes [30, EA, 4F, F7] .sptd2 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd2" section [0xF75BBD38] ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text USBPORT.SYS!DllUnload BA1B68AC 5 Bytes JMP 89C6F1D8 ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[640] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0149A650 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[640] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 016D7E1A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[640] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 016D7DF7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[640] kernel32.dll!ValidateLocale + B130 7C844958 7 Bytes JMP 0149EDB3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[640] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 016D7D78 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8AB5F308 IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_ULONG] [F74C5574] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!READ_PORT_UCHAR] [F74C50C0] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_UCHAR] [F74C5FE0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74C50C0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74C5362] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74C52A4] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74C61BC] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74C5FE0] sptd.sys IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89C6F308 IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74DA312] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8AB011F8 AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) Device \Driver\usbuhci \Device\USBPDO-0 89C6E1F8 Device \Driver\usbuhci \Device\USBPDO-1 89C6E1F8 Device \Driver\usbehci \Device\USBPDO-2 89C4C1F8 Device \Driver\usbuhci \Device\USBPDO-3 89C6E1F8 Device \Driver\usbuhci \Device\USBPDO-4 89C6E1F8 AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET) Device \Driver\usbehci \Device\USBPDO-5 89C4C1F8 Device \Driver\usbuhci \Device\USBPDO-6 89C6E1F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{779D079F-0CF6-4A32-BA0A-620F040C40EC} 866F61F8 Device \Driver\usbuhci \Device\USBPDO-7 89C6E1F8 Device \Driver\Cdrom \Device\CdRom0 89C3F1F8 Device \Driver\iaStor \Device\Ide\iaStor0 [BA777EB0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [BA777EB0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [BA777EB0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 866F61F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{4022BDC5-1C55-495E-A330-288FA07EED72} 866F61F8 Device \Driver\NetBT \Device\NetbiosSmb 866F61F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{3B812E74-DA4C-4E3E-A71C-C2A91ACDFB39} 866F61F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{FCB04168-9170-45AF-A2CB-8434817A0D88} 866F61F8 AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET) AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET) Device \Driver\usbuhci \Device\USBFDO-0 89C6E1F8 Device \Driver\usbuhci \Device\USBFDO-1 89C6E1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 866F01F8 Device \Driver\usbuhci \Device\USBFDO-2 89C6E1F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 866F01F8 Device \Driver\usbehci \Device\USBFDO-3 89C4C1F8 Device \Driver\usbuhci \Device\USBFDO-4 89C6E1F8 Device \Driver\usbuhci \Device\USBFDO-5 89C6E1F8 Device \Driver\usbuhci \Device\USBFDO-6 89C6E1F8 Device \Driver\usbehci \Device\USBFDO-7 89C4C1F8 Device \FileSystem\Cdfs \Cdfs 863DC1F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3acdc5a1 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269d9e718 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x13 0x88 0x4B 0x2E ... Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001f3acdc5a1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269d9e718 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x13 0x88 0x4B 0x2E ... ---- EOF - GMER 1.0.15 ----