
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 21:21:58
Windows 5.1.2600 Dodatek Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mateusz\USTAWI~1\Temp\axlirpod.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF692B000, 0x1C5D38, 0xE8000020]
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xEFB22A80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!connect + 21B 71A54C22 4 Bytes JMP 027517E0 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!send 71A54C27 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!send + 89 71A54CB0 4 Bytes JMP 02751D40 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!WSARecv 71A54CB5 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!WSACloseEvent + 182 71A5676A 4 Bytes JMP 02751930 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!recv 71A5676F 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!recv + 186 71A568F5 4 Bytes JMP 02751A30 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!WSASend 71A568FA 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1980] WS2_32.dll!connect + 21B 71A54C22 7 Bytes JMP 00FB17E0 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1980] WS2_32.dll!send + 89 71A54CB0 7 Bytes JMP 00FB1D40 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1980] WS2_32.dll!WSACloseEvent + 182 71A5676A 7 Bytes JMP 00FB1930 c:\windows\system32\sshnas21.dll
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1980] WS2_32.dll!recv + 186 71A568F5 7 Bytes JMP 00FB1A30 c:\windows\system32\sshnas21.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExA] [00418470] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExW] [004184E8] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DialogBoxParamW] [0041867A] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MessageBoxW] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!ShowWindow] [00418560] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!SetWindowPos] [0041860E] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!ShowWindow] [00418560] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!CreateWindowExA] [00418470] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\CRYPT32.dll [USER32.dll!MessageBoxW] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\CRYPT32.dll [USER32.dll!MessageBoxA] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamA] [0041867A] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [0041867A] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [00418470] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [004184E8] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!MessageBoxA] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!MessageBoxW] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectA] [00418674] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectW] [00418674] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [0041860E] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [00418560] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CreateWindowExW] [004184E8] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DialogBoxParamW] [0041867A] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!ShowWindow] [00418560] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowPos] [0041860E] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!MessageBoxW] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!MessageBoxA] [00418686] C:\WINDOWS\msa.exe
IAT C:\WINDOWS\msa.exe[1632] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!MessageBoxIndirectW] [00418674] C:\WINDOWS\msa.exe
---- Devices - GMER 1.0.15 ----
Device \Driver\USB_RNDIS \Device\{6F918B05-D4F4-4B28-8E79-FB3FE215BA94} RNDISMP.SYS (Remote NDIS Miniport/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Log z OTL
- Kod: Zaznacz wszystko
http://www.wklej.org/id/289264/