Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 1.0.15.15281 - http://www.gmer.net
- Rootkit scan 2010-02-18 11:24:12
- Windows 5.1.2600 Dodatek Service Pack 3
- Running: qfeld61r.exe; Driver: C:\DOCUME~1\Raven\USTAWI~1\Temp\kwnyyfow.sys
- ---- System - GMER 1.0.15 ----
- SSDT spov.sys ZwCreateKey [0xB7EA80E0]
- SSDT spov.sys ZwEnumerateKey [0xB7EC6CA2]
- SSDT spov.sys ZwEnumerateValueKey [0xB7EC7030]
- SSDT spov.sys ZwOpenKey [0xB7EA80C0]
- SSDT spov.sys ZwQueryKey [0xB7EC7108]
- SSDT spov.sys ZwQueryValueKey [0xB7EC6F88]
- SSDT spov.sys ZwSetValueKey [0xB7EC719A]
- INT 0x62 ? 8A708BF8
- INT 0x63 ? 8A708BF8
- INT 0x63 ? 8A708BF8
- INT 0x63 ? 8A32EBF8
- INT 0x83 ? 8A708BF8
- INT 0x83 ? 8A708BF8
- INT 0x83 ? 8A32EBF8
- INT 0x83 ? 8A708BF8
- INT 0x84 ? 8A32EBF8
- INT 0xA4 ? 8A32EBF8
- INT 0xA4 ? 8A32EBF8
- INT 0xA4 ? 8A32EBF8
- INT 0xA4 ? 8A32EBF8
- INT 0xB4 ? 8A32EBF8
- ---- Kernel code sections - GMER 1.0.15 ----
- ? spov.sys Nie można odnaleźć określonego pliku. !
- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6E1F360, 0x3D46A5, 0xE8000020]
- .text USBPORT.SYS!DllUnload B6C7C8AC 5 Bytes JMP 8A32E1D8
- .text az293g63.SYS B6B43386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
- .text az293g63.SYS B6B433AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
- .text az293g63.SYS B6B433C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
- .text az293g63.SYS B6B433C9 1 Byte [2E]
- .text az293g63.SYS B6B433C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
- .text ...
- .text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB3404300, 0x3B6D8, 0xE8000020]
- .text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB8398300, 0x1BEE, 0xE8000020]
- ---- User code sections - GMER 1.0.15 ----
- .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1376] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 4 Bytes [C2, 04, 00, 00]
- ---- Kernel IAT/EAT - GMER 1.0.15 ----
- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EA9040] spov.sys
- IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EA913C] spov.sys
- IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EA90BE] spov.sys
- IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EA97FC] spov.sys
- IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EA96D2] spov.sys
- IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EB9048] spov.sys
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KeGetCurrentIrql] CB033043
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KfRaiseIrql] 0673C13B
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KfLowerIrql] C13B0003
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!READ_PORT_USHORT] 83660000
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
- IAT \SystemRoot\System32\Drivers\az293g63.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
- ---- Devices - GMER 1.0.15 ----
- Device \FileSystem\Ntfs \Ntfs 8A6971F8
- AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
- Device \FileSystem\Udfs \UdfsCdRom 89A73500
- Device \FileSystem\Udfs \UdfsDisk 89A73500
- Device \Driver\usbuhci \Device\USBPDO-0 8A45C1F8
- Device \Driver\PCI_PNP6450 \Device\00000051 spov.sys
- Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A6991F8
- Device \Driver\dmio \Device\DmControl\DmConfig 8A6991F8
- Device \Driver\dmio \Device\DmControl\DmPnP 8A6991F8
- Device \Driver\dmio \Device\DmControl\DmInfo 8A6991F8
- Device \Driver\usbuhci \Device\USBPDO-1 8A45C1F8
- Device \Driver\usbuhci \Device\USBPDO-2 8A45C1F8
- Device \Driver\usbehci \Device\USBPDO-3 8A4501F8
- Device \Driver\usbuhci \Device\USBPDO-4 8A45C1F8
- AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys
- Device \Driver\usbuhci \Device\USBPDO-5 8A45C1F8
- Device \Driver\NetBT \Device\NetBT_Tcpip_{33E9807A-512A-4204-B7CD-5E890D495CFD} 8A134500
- Device \Driver\usbuhci \Device\USBPDO-6 8A45C1F8
- Device \Driver\Ftdisk \Device\HarddiskVolume1 8A7091F8
- Device \Driver\usbehci \Device\USBPDO-7 8A4501F8
- Device \Driver\Ftdisk \Device\HarddiskVolume2 8A7091F8
- Device \Driver\Cdrom \Device\CdRom0 8A44C1F8
- Device \Driver\Cdrom \Device\CdRom1 8A44C1F8
- Device \Driver\atapi \Device\Ide\IdePort0 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdePort1 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdePort2 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdePort3 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdePort4 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort4 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdePort5 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdePort5 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-5 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-5 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 [B7DFBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
- Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\sptd \Device\4067440200 spov.sys
- Device \Driver\NetBT \Device\NetBt_Wins_Export 8A134500
- Device \Driver\NetBT \Device\NetbiosSmb 8A134500
- Device \Driver\usbuhci \Device\USBFDO-0 8A45C1F8
- Device \Driver\usbuhci \Device\USBFDO-1 8A45C1F8
- Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A19B500
- Device \Driver\usbuhci \Device\USBFDO-2 8A45C1F8
- Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A19B500
- Device \Driver\usbehci \Device\USBFDO-3 8A4501F8
- Device \Driver\usbuhci \Device\USBFDO-4 8A45C1F8
- Device \Driver\Ftdisk \Device\FtControl 8A7091F8
- Device \Driver\usbuhci \Device\USBFDO-5 8A45C1F8
- Device \Driver\usbuhci \Device\USBFDO-6 8A45C1F8
- Device \Driver\usbehci \Device\USBFDO-7 8A4501F8
- Device \Driver\az293g63 \Device\Scsi\az293g631Port6Path0Target0Lun0 8A2DA1F8
- Device \Driver\az293g63 \Device\Scsi\az293g631Port6Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \Driver\az293g63 \Device\Scsi\az293g631 8A2DA1F8
- Device \Driver\az293g63 \Device\Scsi\az293g631 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
- Device \FileSystem\Cdfs \Cdfs 8A214500
- ---- Registry - GMER 1.0.15 ----
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB1 0xFF 0x9E 0x5B ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD4 0x32 0xA6 0xEC ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x11 0x9F 0x5A 0xDA ...
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB1 0xFF 0x9E 0x5B ...
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD4 0x32 0xA6 0xEC ...
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x11 0x9F 0x5A 0xDA ...
- ---- EOF - GMER 1.0.15 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement