Ściągnąłem GMER-a 1.0.1.4
teraz wklejam wszystkie logi, bo nie wiem co będzie potrzebne:
GMER 1.0.14.14205 -
http://www.gmer.net
Rootkit scan 2008-03-31 11:19:50
Windows 5.1.2600 Dodatek Service Pack 2
---- System - GMER 1.0.14 ----
SSDT sptd.sys ZwCreateKey [0xF7740AC8]
SSDT sptd.sys ZwEnumerateKey [0xF7740C22]
SSDT sptd.sys ZwEnumerateValueKey [0xF7740F9A]
SSDT sptd.sys ZwOpenKey [0xF774098E]
SSDT sptd.sys ZwQueryKey [0xF7741064]
SSDT sptd.sys ZwQueryValueKey [0xF7740EFC]
SSDT sptd.sys ZwSetValueKey [0xF77410EC]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
? C:\WINDOWS\System32\Drivers\SPTD2029.SYS Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 EF3BE4F0 16 Bytes [ 0D, 3F, 5C, 1A, 10, 4D, 26, ... ]
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 11 EF3BE501 31 Bytes [ D0, 3B, EF, 41, 12, D4, 1D, ... ]
? C:\WINDOWS\System32\Drivers\dtscsi.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F774989E] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F775FD86] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7749E24] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7749D28] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F7749EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IofCallDriver] [F7749EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7749E24] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7749D28] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F775F1AE] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F7749A5A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F775F04A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F77498F2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F773CAD2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F773CC0E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F773CB96] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F773D76C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F773D642] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F775FE4A] sptd.sys
IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F774E8C6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F775F04A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F775FE4A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F7749CC6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F7749CC6] sptd.sys
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 867C90E8
AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc)
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fastfat \FatCdrom 8622C0E8
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
Device \Driver\dmio \Device\DmControl\DmIoDaemon 867CAEB0
Device \Driver\dmio \Device\DmControl\DmConfig 867CAEB0
Device \Driver\dmio \Device\DmControl\DmPnP 867CAEB0
Device \Driver\dmio \Device\DmControl\DmInfo 867CAEB0
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
Device \Driver\Ftdisk \Device\HarddiskVolume1 867CA0E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 867CA0E8
Device \FileSystem\Rdbss \Device\FsWrap 861A40E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 867CA0E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 867CA0E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 867CA0E8
Device \Driver\Ftdisk \Device\HarddiskVolume6 867CA0E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 862250E8
Device \Driver\00000049 \Device\0000004b sptd.sys
Device \Driver\NetBT \Device\NetbiosSmb 862250E8
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
Device \Driver\Disk \Device\Harddisk0\DR0 867CA550
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
Device \Driver\Disk \Device\Harddisk1\DR1 867CA550
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 861991F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 861991F0
Device \FileSystem\Npfs \Device\NamedPipe 860EC0E8
Device \Driver\Ftdisk \Device\FtControl 867CA0E8
Device \FileSystem\Msfs \Device\Mailslot 8623E4A8
Device \Driver\NetBT \Device\NetBT_Tcpip_{644A76CD-8340-4A6F-9AA2-CF8E6D5D5A0F} 862250E8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port1Path1Target1Lun0 867CA808
Device \Driver\si3112r \Device\Scsi\si3112r1Port0Path0Target0Lun0 867CAA40
Device \Driver\nvidesm \Device\Scsi\nvidesm1 867CA808
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 8619E0E8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port1Path1Target0Lun0 867CA808
Device \Driver\si3112r \Device\Scsi\si3112r1 867CAA40
Device \Driver\dtscsi \Device\Scsi\dtscsi1 8619E0E8
Device \FileSystem\Fastfat \Fat 8622C0E8
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Cdfs \Cdfs 861542E0
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 -1274768246
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 108390011
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -150616131
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x70 0x5F 0xB4 0x42 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x02 0x37 0x96 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x69 0xD4 0x25 0x8F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x70 0x5F 0xB4 0x42 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x02 0x37 0x96 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x69 0xD4 0x25 0x8F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Ac
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Ac@Order 0x08 0x00 0x00 0x00 ...
---- Files - GMER 1.0.14 ----
File C:\RECYCLER\NPROTECT 0 bytes
File C:\RECYCLER\NPROTECT\00000000.MOZ 3093 bytes
File C:\RECYCLER\NPROTECT\00000001.MOZ 166165 bytes
File C:\RECYCLER\NPROTECT\00000002.MOZ 166163 bytes
File C:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File D:\RECYCLER\NPROTECT 0 bytes
File D:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File E:\RECYCLER\NPROTECT 0 bytes
File E:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File F:\RECYCLER\NPROTECT 0 bytes
File F:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File H:\RECYCLER\NPROTECT 0 bytes
File H:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File I:\RECYCLER\NPROTECT 0 bytes
File I:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
---- EOF - GMER 1.0.14 ----