Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 1.0.15.15281 - http://www.gmer.net
- Rootkit scan 2010-01-30 23:55:59
- Windows 6.1.7600
- Running: 7phuoutr.exe; Driver: C:\Users\Kacper\AppData\Local\Temp\ufryipoc.sys
- ---- System - GMER 1.0.15 ----
- INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2BAF8
- INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B104
- INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B3F4
- INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C142D8
- INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B1DC
- INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B958
- INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B6F8
- INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2BF2C
- INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2C1A8
- ---- Kernel code sections - GMER 1.0.15 ----
- .text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82844579 1 Byte [06]
- .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82868F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
- ? System32\Drivers\spve.sys System nie może odnaleźć określonej ścieżki. !
- .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8D606000, 0x2D5378, 0xE8000020]
- .text USBPORT.SYS!DllUnload 8D0CACA0 5 Bytes JMP 857CF1D8
- .text a4fwdq06.SYS 8D163000 12 Bytes [44, 68, C1, 82, EE, 66, C1, ...]
- .text a4fwdq06.SYS 8D16300D 9 Bytes [47, C1, 82, 48, 6B, C1, 82, ...]
- .text a4fwdq06.SYS 8D163017 115 Bytes [00, DE, 17, D1, 87, E6, 15, ...]
- .text a4fwdq06.SYS 8D16308B 54 Bytes [82, 3C, 7F, 86, 82, 5C, 80, ...]
- .text a4fwdq06.SYS 8D1630C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
- .text ...
- .text peauth.sys 9EA2AC9D 28 Bytes [1E, 00, 76, F2, A4, 5D, 54, ...]
- .text peauth.sys 9EA2ACC1 28 Bytes [1E, 00, 76, F2, A4, 5D, 54, ...]
- .text autochk.exe 004011D1 10 Bytes [FC, 8B, 42, 04, 50, FF, 15, ...]
- .text autochk.exe 004011DC 5 Bytes [8B, E5, 5D, C2, 08]
- .text autochk.exe 004011E2 41 Bytes [CC, CC, CC, CC, CC, CC, CC, ...]
- .text autochk.exe 0040120C 5 Bytes [8B, E5, 5D, C2, 08]
- .text autochk.exe 00401212 47 Bytes [CC, CC, CC, CC, CC, CC, CC, ...]
- .text ...
- ---- User code sections - GMER 1.0.15 ----
- .text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3188] USER32.dll!CharToOemA + 3A 75FEB1DE 7 Bytes JMP 10031D10 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
- .text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3188] USER32.dll!PostMessageW + 2CE 75FF64F3 7 Bytes JMP 10031C80 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
- .text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3188] USER32.dll!SetDlgItemTextA + 25 76008FF6 7 Bytes JMP 10031CF0 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
- .text C:\Program Files\Mozilla Firefox\firefox.exe[3348] ntdll.dll!LdrLoadDll 7782F585 5 Bytes JMP 012E13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
- ---- Kernel IAT/EAT - GMER 1.0.15 ----
- IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [87C07042] \SystemRoot\System32\Drivers\spve.sys
- IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [87C076D6] \SystemRoot\System32\Drivers\spve.sys
- IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [87C07800] \SystemRoot\System32\Drivers\spve.sys
- IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [87C0713E] \SystemRoot\System32\Drivers\spve.sys
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortNotification] 000003E3
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortQuerySystemTime] 8B24568B
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortReadPortUchar] 50522046
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortStallExecution] FFEC9FE8
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortWritePortUchar] 08C483FF
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortWritePortUlong] 0874FF85
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortGetPhysicalAddress] FF53006A
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 08C483D7
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortGetScatterGatherList] 81107D8B
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortGetParentBusType] 0003E5FF
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortRequestCallback] 0F840F00
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 81000001
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0003E3FF
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortCompleteRequest] EC840F00
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortCopyMemory] 8B000000
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortEtwTraceLog] 0001F88E
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] FC8E0B00
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 0F000001
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 0000DA84
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortReadPortBufferUshort] ECD8E800
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortInitialize] 8E8BFFFF
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortGetDeviceBase] 000001F8
- IAT \SystemRoot\System32\Drivers\a4fwdq06.SYS[ataport.SYS!AtaPortDeviceStateChange] 01E08E01
- ---- User IAT/EAT - GMER 1.0.15 ----
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74562494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74545624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [745456E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7456250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74558573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74554D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [745550CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [745551A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [745566D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [745582CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74558819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7455907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7455E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- IAT C:\Windows\Explorer.EXE[3016] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74554C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
- ---- Devices - GMER 1.0.15 ----
- Device \FileSystem\Ntfs \Ntfs 846D21F8
- Device \Driver\volmgr \Device\VolMgrControl 846CE1F8
- Device \Driver\usbohci \Device\USBPDO-0 857D21F8
- Device \Driver\usbohci \Device\USBPDO-1 857D21F8
- Device \Driver\usbehci \Device\USBPDO-2 857CD1F8
- Device \Driver\usbohci \Device\USBPDO-3 857D21F8
- Device \Driver\usbohci \Device\USBPDO-4 857D21F8
- Device \Driver\PCI_PNP5274 \Device\00000055 spve.sys
- AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
- Device \Driver\usbehci \Device\USBPDO-5 857CD1F8
- Device \Driver\usbohci \Device\USBPDO-6 857D21F8
- Device \Driver\NetBT \Device\NetBT_Tcpip_{537002E4-CB07-405C-B814-65584BED4FE3} 857641F8
- Device \Driver\volmgr \Device\HarddiskVolume1 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\volmgr \Device\HarddiskVolume2 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\cdrom \Device\CdRom0 856AB1F8
- Device \Driver\cdrom \Device\CdRom1 856AB1F8
- Device \Driver\volmgr \Device\HarddiskVolume3 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 846D01F8
- Device \Driver\atapi \Device\Ide\IdePort0 846D01F8
- Device \Driver\atapi \Device\Ide\IdePort1 846D01F8
- Device \Driver\atapi \Device\Ide\IdePort2 846D01F8
- Device \Driver\atapi \Device\Ide\IdePort3 846D01F8
- Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 846D01F8
- Device \Driver\volmgr \Device\HarddiskVolume4 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\volmgr \Device\HarddiskVolume5 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\volmgr \Device\HarddiskVolume6 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\volmgr \Device\HarddiskVolume7 846CE1F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- Device \Driver\NetBT \Device\NetBt_Wins_Export 857641F8
- Device \Driver\sptd \Device\4283470274 spve.sys
- Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
- AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
- Device \Driver\usbohci \Device\USBFDO-0 857D21F8
- Device \Driver\usbohci \Device\USBFDO-1 857D21F8
- Device \Driver\usbehci \Device\USBFDO-2 857CD1F8
- Device \Driver\NetBT \Device\NetBT_Tcpip_{1B3B1EC3-9181-4972-8C99-EBE542CAA90F} 857641F8
- Device \Driver\usbohci \Device\USBFDO-3 857D21F8
- Device \Driver\usbohci \Device\USBFDO-4 857D21F8
- Device \Driver\usbehci \Device\USBFDO-5 857CD1F8
- Device \Driver\usbohci \Device\USBFDO-6 857D21F8
- Device \Driver\a4fwdq06 \Device\Scsi\a4fwdq061 857AC1F8
- Device \Driver\a4fwdq06 \Device\Scsi\a4fwdq061Port4Path0Target0Lun0 857AC1F8
- ---- Registry - GMER 1.0.15 ----
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1E 0x00 0xA5 0x96 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x00 0xB8 0xB0 0xBC ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xC6 0xA4 0x0C 0x84 ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1E 0x00 0xA5 0x96 ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x00 0xB8 0xB0 0xBC ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xC6 0xA4 0x0C 0x84 ...
- ---- EOF - GMER 1.0.15 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement