
tu jest log ze scanu, ale nie wiem czym to usunac. Moze ktos pomóc?

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-20 15:56:16
Windows 5.1.2600 Dodatek Service Pack 2
Running: zisfz1dg.exe; Driver: C:\DOCUME~1\user\USTAWI~1\Temp\pgtdqpob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAA619618]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAA6194D4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAA6199B2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAA6190AC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAA6195AE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAA618FEC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAA619050]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAA6196CE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAA61968E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAA61980E]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 23D0 805010D4 2 Bytes [D4, 94] {AAM 0x94}
.text ntkrnlpa.exe!ZwCallbackReturn + 2430 80501134 2 Bytes [B2, 99] {MOV DL, 0x99}
.text ntkrnlpa.exe!ZwCallbackReturn + 2508 8050120C 2 Bytes [AE, 95] {SCASB ; XCHG EBP, EAX}
.text ntkrnlpa.exe!ZwCallbackReturn + 25F0 805012F4 2 Bytes [CE, 96] {INTO ; XCHG ESI, EAX}
.text ntkrnlpa.exe!ZwCallbackReturn + 265C 80501360 2 Bytes [8E, 96]
.text ...
---- User code sections - GMER 1.0.15 ----
? C:\DOCUME~1\user\USTAWI~1\Temp\svchost.exe[3324] time/date stamp mismatch;
UPX1 C:\DOCUME~1\user\USTAWI~1\Temp\svchost.exe[3324] C:\DOCUME~1\user\USTAWI~1\Temp\svchost.exe entry point in "UPX1" section [0x00419940]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[632] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003C0002
IAT C:\WINDOWS\system32\services.exe[632] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003C0000
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Processes - GMER 1.0.15 ----
Library C:\Documents (*** hidden *** ) @ C:\Documents [608] 0x00400000
Library C:\Documents (*** hidden *** ) @ C:\Documents [1996] 0x00400000
Library C:\Documents (*** hidden *** ) @ C:\Documents [2716] 0x00400000
---- EOF - GMER 1.0.15 ----
File::
c:\windows\system32\drivers\bgdglcb.sys
c:\windows\system32\dllcache\lbrtfdc.sys
c:\windows\system32\drivers\lbrtfdc.sys
c:\windows\system32\dllcache\i2omgmt.sys
c:\windows\system32\drivers\i2omgmt.sys
c:\windows\system32\dllcache\changer.sys
c:\windows\system32\drivers\changer.sys
c:\windows\system32\drivers\OLD*.tmp
c:\documents and settings\user\Dane aplikacji\qcopjv.dat
Driver::
bgdglcb
FCopy::
c:\aec.sys | c:\windows\system32\dllcache\aec.sys
c:\aec.sys | c:\windows\system32\drivers\aec.sys
c:\Sfloppy.sys | c:\windows\system32\dllcache\Sfloppy.sys
c:\Sfloppy.sys | c:\windows\system32\drivers\Sfloppy.sys
c:\windows\system32\drivers\aec.sys
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 18 gości