
Problem jak w temacie, proszę o przeglądnięcie logów... Usunięty Deamon i sptd.sys.
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-22 12:16:13
Windows 5.1.2600 Dodatek Service Pack 3
Running: cz3gv60o.exe; Driver: C:\DOCUME~1\ja\USTAWI~1\Temp\pgayrpod.sys
---- System - GMER 1.0.15 ----
SSDT 82643580 ZwAssignProcessToJobObject
SSDT 82644100 ZwDebugActiveProcess
SSDT 82643B30 ZwDuplicateObject
SSDT 82642CC0 ZwOpenProcess
SSDT 82642FC0 ZwOpenThread
SSDT 826439C0 ZwProtectVirtualMemory
SSDT 82643860 ZwSetContextThread
SSDT 826436E0 ZwSetInformationThread
SSDT 82640700 ZwSetSecurityObject
SSDT 82643420 ZwSuspendProcess
SSDT 826432C0 ZwSuspendThread
SSDT 82642E50 ZwTerminateProcess
SSDT 82643150 ZwTerminateThread
SSDT 82643F50 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
_LTEXT C:\WINDOWS\system32\DRIVERS\sntie.sys entry point in "_LTEXT" section [0xAA08CF50]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1096] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text D:\Programy\Mozilla Firefox\firefox.exe[2668] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 D:\Programy\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x51 0xE5 0xD4 0xFB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x51 0xE5 0xD4 0xFB ...
---- EOF - GMER 1.0.15 ----
OTL: http://wklej.org/id/320698/
Extras: http://wklej.org/id/320702/