
Dodam również, iż na przy starcie wyskakuje komunikat, że wystąpił błąd z aplikacją hidserv.exe i zostanie ona zamknięta.
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-25 16:09:20
Windows 5.1.2600 Dodatek Service Pack 3
Running: cubsn4xs.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\uwndafow.sys
---- System - GMER 1.0.15 ----
SSDT sphl.sys ZwCreateKey [0xF84140E0]
SSDT sphl.sys ZwEnumerateKey [0xF8432CA4]
SSDT sphl.sys ZwEnumerateValueKey [0xF8433032]
SSDT sphl.sys ZwOpenKey [0xF84140C0]
SSDT sphl.sys ZwQueryKey [0xF843310A]
SSDT sphl.sys ZwQueryValueKey [0xF8432F8A]
SSDT sphl.sys ZwSetValueKey [0xF843319C]
INT 0x62 ? 8236CBF8
INT 0x63 ? 822EBF00
INT 0x73 ? 822EBF00
INT 0x73 ? 822EBF00
INT 0x82 ? 8236CBF8
INT 0xA4 ? 822EBF00
INT 0xB4 ? 822EBF00
---- Kernel code sections - GMER 1.0.15 ----
? sphl.sys Nie można odnaleźć określonego pliku. !
.text USBPORT.SYS!DllUnload F7FBF8AC 5 Bytes JMP 822EB4E0
.text C:\WINDOWS\system32\drivers\oreans32.sys section is writeable [0xF8705280, 0x7B04, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB85AC300, 0x3AE88, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF8835300, 0x1B7E, 0xE8000020]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 823DD2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8445C4C] sphl.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8445CA0] sphl.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8415042] sphl.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F841513E] sphl.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F84150C0] sphl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8415800] sphl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F84156D6] sphl.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 822EB5E0
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F87C6690] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F87C6430] mksidsa.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F87C65B0] mksidsa.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8236B1F8
AttachedDevice \Driver\Tcpip \Device\Ip mksfwallt.sys
Device \Driver\usbuhci \Device\USBPDO-0 8234C1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 823DB1F8
Device \Driver\dmio \Device\DmControl\DmConfig 823DB1F8
Device \Driver\dmio \Device\DmControl\DmPnP 823DB1F8
Device \Driver\dmio \Device\DmControl\DmInfo 823DB1F8
Device \Driver\usbuhci \Device\USBPDO-1 8234C1F8
Device \Driver\usbuhci \Device\USBPDO-2 8234C1F8
Device \Driver\usbuhci \Device\USBPDO-3 8234C1F8
Device \Driver\usbehci \Device\USBPDO-4 822EC500
AttachedDevice \Driver\Tcpip \Device\Tcp mksfwallt.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 8236D1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8236D1F8
Device \Driver\Cdrom \Device\CdRom0 822E51F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F8367B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F8367B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F8367B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [F8367B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\NetBT \Device\NetBt_Wins_Export 81ECF1F8
Device \Driver\NetBT \Device\NetbiosSmb 81ECF1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{EBA830AB-907C-4DCA-8334-E772A7B9298D} 81ECF1F8
AttachedDevice \Driver\Tcpip \Device\Udp mksfwallt.sys
AttachedDevice \Driver\Tcpip \Device\RawIp mksfwallt.sys
Device \Driver\usbuhci \Device\USBFDO-0 8234C1F8
Device \Driver\usbuhci \Device\USBFDO-1 8234C1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81ED9500
Device \Driver\usbuhci \Device\USBFDO-2 8234C1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 81ED9500
Device \Driver\usbuhci \Device\USBFDO-3 8234C1F8
Device \Driver\usbehci \Device\USBFDO-4 822EC500
Device \Driver\Ftdisk \Device\FtControl 8236D1F8
Device \FileSystem\Cdfs \Cdfs 81E8C500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC2 0x88 0x68 0x76 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x0C 0x86 0xFC 0xCC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0D 0xF5 0xC2 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Hubert\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x37 0xE5 0x30 0xD7 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x47 0xF1 0x9D 0xEE ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x83 0xF6 0x56 0xB8 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0D 0xF5 0xC2 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC2 0x88 0x68 0x76 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x0C 0x86 0xFC 0xCC ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0D 0xF5 0xC2 0x24 ...
---- EOF - GMER 1.0.15 ----