
Sformatowałem blaszaka , to samo
- Kod: Zaznacz wszystko
GMER
[code]GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-18 23:54:46
Windows 5.1.2600 Dodatek Service Pack 2
Running: sfuvnz7w.exe; Driver: C:\DOCUME~1\jaRo1920\USTAWI~1\Temp\kfxirfoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB5244D98]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB5244CB8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB524512A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB52448AA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB5244D2E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB52447C8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB524483C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB5244E42]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB5244E02]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB5244F84]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB7D403A0, 0x59FFE5, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1232] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 00F5ADCD
.text C:\WINDOWS\System32\svchost.exe[1232] NETAPI32.dll!NetpwPathCanonicalize 6FF4A259 5 Bytes JMP 00F5AD64
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 0095ADCD
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[848] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003C0002
IAT C:\WINDOWS\system32\services.exe[848] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003C0000
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] lbcvrjsj <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@DisplayName Microsoft Config
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj@Description ?aduje pliki do pami?ci w celu p??niejszego wydrukowania.
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\lbcvrjsj\Parameters@ServiceDll C:\WINDOWS\system32\qbtvnql.dll
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@DisplayName Microsoft Config
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj@Description ?aduje pliki do pami?ci w celu p??niejszego wydrukowania.
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\lbcvrjsj\Parameters@ServiceDll C:\WINDOWS\system32\qbtvnql.dll
---- EOF - GMER 1.0.15 ----
otl
http://wklej.org/id/378778/
http://wklej.org/id/378779/
dwa razy robiłem logi bo za pierwszym się oczywiście ściął -.-