GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-07-06 18:06:32 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-1b WDC_WD1600JB-32EVA0 rev.15.05R15 149,05GB Running: hpicl0i0.exe; Driver: G:\DOCUME~1\Pc\USTAWI~1\Temp\awliqpod.sys ---- System - GMER 2.1 ---- SSDT spav.sys ZwCreateKey [0xB9EB50E0] SSDT spav.sys ZwEnumerateKey [0xB9ECDDA4] SSDT spav.sys ZwEnumerateValueKey [0xB9ECE132] SSDT spav.sys ZwOpenKey [0xB9EB50C0] SSDT spav.sys ZwQueryKey [0xB9ECE20A] SSDT spav.sys ZwQueryValueKey [0xB9ECE08A] SSDT spav.sys ZwSetValueKey [0xB9ECE29C] INT 0x62 ? 8A708BF8 INT 0x63 ? 8A425BF8 INT 0x63 ? 8A425BF8 INT 0x63 ? 8A425BF8 INT 0x73 ? 8A708BF8 INT 0x83 ? 8A425BF8 INT 0x83 ? 8A425BF8 INT 0x83 ? 8A425BF8 INT 0xA4 ? 8A425BF8 INT 0xB4 ? 8A425BF8 ---- Kernel code sections - GMER 2.1 ---- ? spav.sys Nie można odnaleźć określonego pliku. ! .text G:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB6F5A000, 0x235F87, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 018BB8D0 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 018B7B07 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 018B7820 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 018B7A00 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 0210CCC0 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 018BBFE0 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 0210CC6F G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001EAE G:\Program Files\Mozilla Firefox\mozglue.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 020D9E88 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 020D9E65 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 018B8236 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 020D9DE6 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\firefox.exe[1544] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 01FE7585 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\plugin-container.exe[3272] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 105189BD G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\plugin-container.exe[3272] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 10518A2E G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\plugin-container.exe[3272] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1051C714 G:\Program Files\Mozilla Firefox\xul.dll .text G:\Program Files\Mozilla Firefox\plugin-container.exe[3272] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 105160A5 G:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8A7071F8 Device \FileSystem\Fastfat \FatCdrom 8A491500 Device \FileSystem\Udfs \UdfsCdRom 8A490500 Device \FileSystem\Udfs \UdfsDisk 8A490500 AttachedDevice \Driver\Tcpip \Device\Ip {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{748514DC-E955-4044-B0F5-42DC469CF715} 89B371F8 Device \Driver\usbohci \Device\USBPDO-0 8A4231F8 Device \Driver\usbohci \Device\USBPDO-1 8A4231F8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A6981F8 Device \Driver\dmio \Device\DmControl\DmConfig 8A6981F8 Device \Driver\dmio \Device\DmControl\DmPnP 8A6981F8 Device \Driver\dmio \Device\DmControl\DmInfo 8A6981F8 Device \Driver\usbehci \Device\USBPDO-2 8A4211F8 Device \Driver\usbohci \Device\USBPDO-3 8A4231F8 Device \Driver\usbohci \Device\USBPDO-4 8A4231F8 AttachedDevice \Driver\Tcpip \Device\Tcp {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys Device \Driver\usbehci \Device\USBPDO-5 8A4211F8 Device \Driver\usbohci \Device\USBPDO-6 8A4231F8 Device \Driver\Ftdisk \Device\HarddiskVolume1 8A7091F8 Device \Driver\Cdrom \Device\CdRom0 8A4371F8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A7091F8 Device \Driver\atapi \Device\Ide\IdePort0 [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-1b [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B9E08B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Ftdisk \Device\HarddiskVolume3 8A7091F8 Device \Driver\Ftdisk \Device\HarddiskVolume4 8A7091F8 Device \Driver\PCI_PNP4964 \Device\0000003e spav.sys Device \Driver\NetBT \Device\NetBt_Wins_Export 89B371F8 Device \Driver\NetBT \Device\NetbiosSmb 89B371F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{E3F40742-A55E-4A7D-ADBF-B43015DE7D4D} 89B371F8 AttachedDevice \Driver\Tcpip \Device\Udp {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys AttachedDevice \Driver\Tcpip \Device\RawIp {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys Device \Driver\usbohci \Device\USBFDO-0 8A4231F8 Device \Driver\usbohci \Device\USBFDO-1 8A4231F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89A9D1F8 Device \Driver\usbehci \Device\USBFDO-2 8A4211F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 89A9D1F8 Device \Driver\usbohci \Device\USBFDO-3 8A4231F8 Device \Driver\Ftdisk \Device\FtControl 8A7091F8 Device \Driver\usbohci \Device\USBFDO-4 8A4231F8 Device \Driver\sptd \Device\1800449964 spav.sys Device \Driver\usbehci \Device\USBFDO-5 8A4211F8 Device \Driver\usbohci \Device\USBFDO-6 8A4231F8 Device \Driver\aut4kj6j \Device\Scsi\aut4kj6j1 8A3DD1F8 Device \FileSystem\Fastfat \Fat 8A491500 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys ---- Trace I/O - GMER 2.1 ---- Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spav.sys >>UNKNOWN [0x8a6b8938]<< 8a6b8938 Trace 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8a5ffab8] 8a5ffab8 Trace 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000063[0x8a6f79e8] 8a6f79e8 Trace 5 ACPI.sys[b9e73620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-1b[0x8a602d98] 8a602d98 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 G:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x43 0xEA 0x4C 0xCC ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6B 0xDE 0x00 0x21 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x18 0x8C 0x47 0x57 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 G:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x43 0xEA 0x4C 0xCC ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6B 0xDE 0x00 0x21 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x18 0x8C 0x47 0x57 ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo -724382870 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30382344 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo -724382870 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30382344 ---- EOF - GMER 2.1 ----