
Logi z GMER:
- Kod: Zaznacz wszystko
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-27 18:29:23
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-10 WDC_WD15EARS-00MVWB0 rev.51.0AB51
Running: mvuf2rjw.exe; Driver: C:\DOCUME~1\User\USTAWI~1\Temp\pxtdqpoc.sys
---- System - GMER 1.0.15 ----
SSDT B70ECDE4 ZwClose
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwCreateKey [0xF7751152]
SSDT B70ECDEE ZwCreateSection
SSDT B70ECD94 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwDeleteKey [0xF77513D6]
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwDeleteValueKey [0xF77513F8]
SSDT B70ECDDF ZwDuplicateObject
SSDT B70ECDB2 ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwOpenKey [0xF7751294]
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwOpenProcess [0xF775100E]
SSDT B70ECD85 ZwOpenThread
SSDT B70ECDBC ZwReplaceKey
SSDT B70ECDB7 ZwRestoreKey
SSDT B70ECDF3 ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\HookCentre.sys (Security Hook/G Data Software AG) ZwSetValueKey [0xF77513A8]
SSDT B70ECD8F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB72C4380, 0x566445, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[1900] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Pando Networks\Media Booster\PMB.exe[1948] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- Devices - GMER 1.0.15 ----
Device \Driver\Tcpip \Device\Ip GDTdiIcpt.sys (G Data Software AG)
Device \Driver\Tcpip \Device\Tcp GDTdiIcpt.sys (G Data Software AG)
Device \Driver\Tcpip \Device\Udp GDTdiIcpt.sys (G Data Software AG)
Device \Driver\Tcpip \Device\RawIp GDTdiIcpt.sys (G Data Software AG)
Device \Driver\Tcpip \Device\IPMULTICAST GDTdiIcpt.sys (G Data Software AG)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{51731e44-a6f7-4771-aa48-7733727a26c4}@Model 276
Reg HKLM\SOFTWARE\Classes\CLSID\{51731e44-a6f7-4771-aa48-7733727a26c4}@Therad 30
Reg HKLM\SOFTWARE\Classes\CLSID\{51731e44-a6f7-4771-aa48-7733727a26c4}@MData 0x2B 0x8F 0x78 0x29 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}@scansk 0x13 0xFB 0x46 0x86 ...
---- EOF - GMER 1.0.15 ----
Wiem, że log jest z 27.11, ale od tamtego czasu nic nie było pobierane ani instalowane, więc log jest aktualny (a sporządzenie nowego zajmie mi około 1-2h, więc mam nadzieję, że wystarczy). Pozdrawiam