Ewido znalazł backdoor.hupigon.kg E:\Program Files\Rockstar Games\GTA San Andreas\hlm-intro.exe
i Hijacker.agent.jh C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
ale nie mógł ich usunąć
Chyba jednak będzie potrzebny format aby się pozbyć tych syfów.
1)
- Kod: Zaznacz wszystko
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-09 16:29:18
Windows 5.1.2600 Dodatek Service Pack 2
---- Services - GMER 1.0.12 ----
Service .NET CLR Data
Service .NET CLR Networking
Service .NET Data Provider for Oracle
Service .NET Data Provider for SqlServer
Service .NETFramework
Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\system32\DRIVERS\ACPI.sys [BOOT] ACPI
Service [DISABLED] ACPIEC
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [SYSTEM] AFD
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\system32\svchost.exe [DISABLED] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service C:\WINDOWS\system32\DRIVERS\AmdK8.sys [SYSTEM] AmdK8
Service C:\WINDOWS\system32\drivers\amon.sys [AUTO] AMON
Service [DISABLED] amsint
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service ASP.NET
Service ASP.NET_2.0.50727
Service C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [MANUAL] aspnet_state
Service C:\WINDOWS\system32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\system32\DRIVERS\atapi.sys [BOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\system32\DRIVERS\atksgt.sys [AUTO] atksgt
Service C:\WINDOWS\system32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\system32\DRIVERS\audstub.sys [MANUAL] audstub
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys [SYSTEM] AVG Anti-Spyware Driver
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [AUTO] AVG Anti-Spyware Guard
Service C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [SYSTEM] AvgAsCln
Service BattC
Service [SYSTEM] Beep
Service C:\WINDOWS\system32\svchost.exe [MANUAL] BITS
Service C:\WINDOWS\system32\svchost.exe [AUTO] Browser
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [SYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\system32\DRIVERS\cdrom.sys [SYSTEM] Cdrom
Service [SYSTEM] Changer
Service C:\WINDOWS\system32\cisvc.exe [MANUAL] CiSvc
Service C:\WINDOWS\system32\clipsrv.exe [DISABLED] ClipSrv
Service C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [MANUAL] clr_optimization_v2.0.50727_32
Service [DISABLED] CmdIde
Service C:\WINDOWS\system32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service [DISABLED] Cpqarray
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service C:\WINDOWS\system32\drivers\ctac32k.sys [MANUAL] ctac32k
Service C:\WINDOWS\system32\drivers\ctaud2k.sys [MANUAL] ctaud2k
Service C:\WINDOWS\system32\drivers\ctdvda2k.sys [MANUAL] ctdvda2k
Service C:\WINDOWS\system32\drivers\ctprxy2k.sys [MANUAL] ctprxy2k
Service C:\WINDOWS\system32\drivers\ctsfm2k.sys [MANUAL] ctsfm2k
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\system32\svchost.exe [AUTO] DcomLaunch
Service C:\WINDOWS\system32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\system32\DRIVERS\disk.sys [BOOT] Disk
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [BOOT] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [BOOT] dmload
Service C:\WINDOWS\System32\svchost.exe [AUTO] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\system32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service System32\Drivers\dtscsi.sys [MANUAL] dtscsi
Service C:\WINDOWS\system32\drivers\emupia2k.sys [MANUAL] emupia
Service C:\WINDOWS\System32\svchost.exe [AUTO] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\system32\svchost.exe [MANUAL] EventSystem
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [MANUAL] FastUserSwitchingCompatibility
Service C:\WINDOWS\system32\DRIVERS\fdc.sys [MANUAL] Fdc
Service [SYSTEM] Fips
Service C:\WINDOWS\system32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk
Service C:\WINDOWS\system32\DRIVERS\fltMgr.sys [BOOT] FltMgr
Service [SYSTEM] Fs_Rec
Service C:\WINDOWS\system32\DRIVERS\ftdisk.sys [BOOT] Ftdisk
Service C:\WINDOWS\system32\giveio.sys [BOOT] giveio
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service G:\INSTALL\GMSIPCI.SYS [MANUAL] GMSIPCI
Service C:\WINDOWS\system32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service [MANUAL] GVCplDrv
Service C:\WINDOWS\system32\drivers\ha10kx2k.sys [MANUAL] ha10kx2k
Service C:\WINDOWS\system32\DRIVERS\hamachi.sys [MANUAL] hamachi
Service C:\WINDOWS\system32\drivers\hap16v2k.sys [MANUAL] hap16v2k
Service C:\WINDOWS\system32\drivers\hap17v2k.sys [MANUAL] hap17v2k
Service C:\WINDOWS\System32\svchost.exe [AUTO] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service [DISABLED] hpn
Service C:\WINDOWS\System32\Drivers\HTTP.sys [MANUAL] HTTP
Service C:\WINDOWS\System32\svchost.exe [MANUAL] HTTPFilter
Service [SYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\system32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt
Service C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [MANUAL] IDriverT
Service C:\WINDOWS\system32\DRIVERS\imapi.sys [SYSTEM] Imapi
Service C:\WINDOWS\system32\imapi.exe [MANUAL] ImapiService
Service C:\WINDOWS\system32\drivers\InCDFs.sys [DISABLED] InCDfs
Service C:\WINDOWS\system32\drivers\InCDPass.sys [SYSTEM] InCDPass
Service [SYSTEM] InCDrec
Service C:\WINDOWS\system32\drivers\InCDRm.sys [SYSTEM] incdrm
Service C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [AUTO] InCDsrv
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service [DISABLED] IntelIde
Service C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys [MANUAL] Ip6Fw
Service C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\system32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\system32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\system32\DRIVERS\ipsec.sys [SYSTEM] IPSec
Service C:\WINDOWS\system32\DRIVERS\irda.sys [AUTO] irda
Service C:\WINDOWS\system32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service C:\WINDOWS\system32\svchost.exe [AUTO] Irmon
Service C:\WINDOWS\system32\DRIVERS\irsir.sys [MANUAL] irsir
Service ISAPISearch
Service C:\WINDOWS\system32\DRIVERS\isapnp.sys [BOOT] isapnp
Service C:\WINDOWS\system32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [BOOT] KSecDD
Service C:\WINDOWS\system32\svchost.exe [AUTO] lanmanserver
Service C:\WINDOWS\system32\svchost.exe [AUTO] lanmanworkstation
Service [SYSTEM] lbrtfdc
Service ldap
Service LicenseService
Service C:\WINDOWS\system32\DRIVERS\lirsgt.sys [AUTO] lirsgt
Service C:\WINDOWS\system32\svchost.exe [AUTO] LmHosts
Service C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [AUTO] MDM
Service C:\WINDOWS\system32\svchost.exe [DISABLED] Messenger
Service [SYSTEM] mnmdd
Service C:\WINDOWS\system32\mnmsrvc.exe [MANUAL] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\system32\DRIVERS\mouclass.sys [SYSTEM] Mouclass
Service [BOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\system32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\system32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb
Service C:\WINDOWS\system32\msdtc.exe [MANUAL] MSDTC
Service [SYSTEM] Msfs
Service C:\WINDOWS\system32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\system32\DRIVERS\mssmbios.sys [MANUAL] mssmbios
Service [BOOT] Mup
Service C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [MANUAL] NBService
Service [BOOT] NDIS
Service C:\WINDOWS\system32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\system32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\system32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\system32\DRIVERS\netbios.sys [SYSTEM] NetBIOS
Service C:\WINDOWS\system32\DRIVERS\netbt.sys [SYSTEM] NetBT
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDE
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDEdsdm
Service C:\WINDOWS\system32\lsass.exe [MANUAL] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\system32\svchost.exe [MANUAL] Nla
Service C:\Program Files\Eset\nod32krn.exe [AUTO] NOD32krn
Service [SYSTEM] Npfs
Service G:\NTACCESS.sys [MANUAL] NTACCESS
Service [DISABLED] Ntfs
Service C:\WINDOWS\system32\lsass.exe [MANUAL] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [SYSTEM] Null
Service C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [MANUAL] nv
Service C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [MANUAL] NVENETFD
Service C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [MANUAL] nvnetbus
Service C:\WINDOWS\system32\nvsvc32.exe [AUTO] NVSvc
Service C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [MANUAL] ose
Service C:\WINDOWS\system32\drivers\ctoss2k.sys [MANUAL] ossrv
Service C:\WINDOWS\system32\DRIVERS\parport.sys [MANUAL] Parport
Service [BOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\system32\DRIVERS\pci.sys [BOOT] PCI
Service [SYSTEM] PCIDump
Service C:\WINDOWS\system32\DRIVERS\pciide.sys [BOOT] PCIIde
Service [DISABLED] Pcmcia
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\drivers\pfc.sys [MANUAL] pfc
Service C:\WINDOWS\system32\drivers\PfModNT.sys [AUTO] PfModNT
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\system32\lsass.exe [AUTO] PolicyAgent
Service C:\WINDOWS\system32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service [SYSTEM] PQNTDrv
Service C:\WINDOWS\system32\DRIVERS\processr.sys [SYSTEM] Processor
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\system32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\system32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service C:\WINDOWS\System32\Drivers\PxHelp20.sys [BOOT] PxHelp20
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service C:\WINDOWS\system32\DRIVERS\rasacd.sys [SYSTEM] RasAcd
Service C:\WINDOWS\system32\svchost.exe [MANUAL] RasAuto
Service C:\WINDOWS\system32\DRIVERS\rasirda.sys [MANUAL] Rasirda
Service C:\WINDOWS\system32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\system32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\system32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\system32\DRIVERS\rdbss.sys [SYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [SYSTEM] RDPCDD
Service RDPDD
Service C:\WINDOWS\system32\DRIVERS\rdpdr.sys [MANUAL] rdpdr
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [MANUAL] RDSessMgr
Service C:\WINDOWS\system32\DRIVERS\redbook.sys [SYSTEM] redbook
Service C:\WINDOWS\system32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\system32\svchost.exe [AUTO] RemoteRegistry
Service C:\WINDOWS\system32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\system32\rsvp.exe [MANUAL] RSVP
Service C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [MANUAL] RTL8023xp
Service C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [MANUAL] rtl8139
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [AUTO] Schedule
Service C:\WINDOWS\system32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\System32\svchost.exe [AUTO] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\system32\DRIVERS\SER120.sys [MANUAL] SER120
Service C:\WINDOWS\system32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\system32\DRIVERS\serial.sys [SYSTEM] Serial
Service G:\NTGLM7X.sys [MANUAL] SetupNTGLM7X
Service C:\WINDOWS\System32\drivers\sfdrv01.sys [BOOT] sfdrv01
Service C:\WINDOWS\System32\drivers\sfhlp02.sys [BOOT] sfhlp02
Service [SYSTEM] Sfloppy
Service C:\WINDOWS\System32\drivers\sfsync04.sys [BOOT] sfsync04
Service C:\WINDOWS\system32\svchost.exe [AUTO] SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\speedfan.sys [BOOT] speedfan
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [AUTO] Spooler
Service C:\WINDOWS\System32\Drivers\sptd.sys [BOOT] sptd
Service C:\WINDOWS\system32\DRIVERS\sr.sys [DISABLED] sr
Service C:\WINDOWS\system32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\system32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\system32\svchost.exe [MANUAL] SSDPSRV
Service C:\WINDOWS\system32\DRIVERS\st3bus28.sys [MANUAL] st3bus28
Service C:\WINDOWS\system32\DRIVERS\st3mp28.sys [MANUAL] st3mp28
Service C:\WINDOWS\system32\svchost.exe [MANUAL] stisvc
Service C:\WINDOWS\system32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\system32\dllhost.exe [MANUAL] SwPrv
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [MANUAL] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\system32\DRIVERS\tcpip.sys [SYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\system32\DRIVERS\termdd.sys [SYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\WINDOWS\system32\tlntsvr.exe [DISABLED] TlntSvr
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [AUTO] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\system32\wdfmgr.exe [AUTO] UMWdf
Service C:\WINDOWS\system32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\system32\svchost.exe [MANUAL] upnphost
Service C:\WINDOWS\System32\ups.exe [MANUAL] UPS
Service usb
Service C:\WINDOWS\system32\DRIVERS\usbehci.sys [MANUAL] usbehci
Service C:\WINDOWS\system32\DRIVERS\usbhub.sys [MANUAL] usbhub
Service C:\WINDOWS\system32\DRIVERS\usbohci.sys [MANUAL] usbohci
Service C:\WINDOWS\system32\DRIVERS\usbprint.sys [MANUAL] usbprint
Service C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR
Service C:\WINDOWS\System32\drivers\vga.sys [SYSTEM] VgaSave
Service [DISABLED] ViaIde
Service [BOOT] VolSnap
Service C:\WINDOWS\System32\vssvc.exe [MANUAL] VSS
Service C:\WINDOWS\System32\svchost.exe [AUTO] W32Time
Service W3SVC
Service C:\WINDOWS\system32\DRIVERS\wanarp.sys [MANUAL] Wanarp
Service [MANUAL] WDICA
Service C:\WINDOWS\system32\drivers\wdmaud.sys [MANUAL] wdmaud
Service C:\WINDOWS\system32\svchost.exe [AUTO] WebClient
Service C:\WINDOWS\system32\svchost.exe [AUTO] winmgmt
Service [MANUAL] Winsock
Service WinSock2
Service WinTrust
Service C:\WINDOWS\System32\svchost.exe [MANUAL] WmdmPmSN
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Wmi
Service WmiApRpl
Service C:\WINDOWS\system32\wbem\wmiapsrv.exe [MANUAL] WmiApSrv
Service C:\WINDOWS\System32\drivers\ws2ifsl.sys [SYSTEM] WS2IFSL
Service C:\WINDOWS\System32\svchost.exe [AUTO] wscsvc
Service C:\WINDOWS\system32\svchost.exe [AUTO] wuauserv
Service C:\WINDOWS\System32\svchost.exe [AUTO] WZCSVC
Service C:\WINDOWS\System32\svchost.exe [MANUAL] xmlprov
Service {05892524-4C5A-4FC6-8ABC-0ED87BBED890}
Service {5A4064D1-99C3-4869-9DB0-5E7FA61C458F}
Service {DC68E865-E475-4D62-963B-0E69C4408D96}
Service [MANUAL] ab7ina7z
---- EOF - GMER 1.0.12 ----
2)
[code]
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-09 16:35:39
Windows 5.1.2600 Dodatek Service Pack 2
---- System - GMER 1.0.12 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.text USBPORT.SYS!DllUnload F6EB862C 5 Bytes JMP 865A8960
? System32\Drivers\ab7ina7z.SYS Nie można odnaleźć określonego pliku.
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 867D11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 867D11D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 86331980
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 86331980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLOSE 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_WRITE 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_SET_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_VOLUME_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DIRECTORY_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DEVICE_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_LOCK_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLEANUP 848B31D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_PNP 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLOSE 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_WRITE 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_SET_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_VOLUME_INFORMATION 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DIRECTORY_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DEVICE_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_LOCK_CONTROL 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLEANUP 848B31D8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_PNP 848B31D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8656B578
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 8656B578
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CREATE 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CLOSE 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_POWER 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8656F980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_PNP 8656F980
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 867641D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 867641D8
Device \Driver\00000037 \Device\00000056 IRP_MJ_POWER [F7413C7E] sptd.sys
Device \Driver\00000037 \Device\00000056 IRP_MJ_SYSTEM_CONTROL [F742D2A2] sptd.sys
Device \Driver\00000037 \Device\00000056 IRP_MJ_PNP [F742E228] sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 867D31D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86572980
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 867D31D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 867D31D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86572980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86572980
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 867D21D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 867D21D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL [F739BA6C] sfsync04.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 867D21D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL [F739BA6C] sfsync04.sys
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL [F739BA6C] sfsync04.sys
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 867D21D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 867D21D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 867D21D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL [F739BA6C] sfsync04.sys
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 867D21D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTRO