
- Kod: Zaznacz wszystko
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-16 12:58:04
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9160821AS rev.3.ALC
Running: n4w9c40z.exe; Driver: C:\DOCUME~1\Ja\USTAWI~1\Temp\pxtdypow.sys
---- System - GMER 1.0.15 ----
SSDT BA6E21D6 ZwCreateKey
SSDT BA6E21CC ZwCreateThread
SSDT BA6E21DB ZwDeleteKey
SSDT BA6E21E5 ZwDeleteValueKey
SSDT BA6E21EA ZwLoadKey
SSDT BA6E21B8 ZwOpenProcess
SSDT BA6E21BD ZwOpenThread
SSDT BA6E21F4 ZwReplaceKey
SSDT BA6E21EF ZwRestoreKey
SSDT BA6E21E0 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2D6C 80504608 4 Bytes JMP F8BA6E21
? dshryr.sys Nie można odnaleźć określonego pliku. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB92A9000, 0x187662, 0xE8000020]
C:\Program Files\CyberLink\PowerDVD\000.fcl entry point in "" section [0xA52F3000]
.clc C:\Program Files\CyberLink\PowerDVD\000.fcl unknown last section [0xA52F4000, 0x1000, 0x00000000]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[3044] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x8E 0x33 0x3E 0x6C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x8E 0x33 0x3E 0x6C ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG10.00.00.01WORKSTATION 5D08DC9561129FC7857299F5D276EFCF9EA82A844DCECEC0D93685923EBA202BC89D8FBB0026A9061819C8CE1D7BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A9C6AECB7A5D1407A6171C11EC38DE3D5E689C003AF40103BB666DF451DC1DA13DC8C12181094C39C116F5962D893AB5CD062A274BC263956FBD04269556E120B960787F54DBBAD64FF3B31BA5E8CB4BFE0BFB11696742B8ECC93930AC4199EBCA377FCF33593D0926D92BF5834FA30D412B984A8C1D0EB2FBD5565E577C499C514A7BBB49228852601B07CDF9C3460706AD481610EFBEC0883DE22E38BA783BD12BDA9CA33055A83B1CB2F99F243C3FE4EC1B683543CE92A2EFB1D15801B14376FD4D82334EE0F699D86008EE2194AB985A62EB9C4CBD4DFD72D3B1A52C06268AFD46314D1DEA9A805F8438453E613681F6B47CCE940D86F2DC9FE6EDEA09C8FE767FA02B8EB8661A51D8FDE556373F205B6B2D387AC34CFD5CB2BF683FD0856A49F3FBEAEC131E35E55982F694301A9DB224C327AFEC9E3DB0EABFAA8079A783ECE3230D52467F42E6492303FA690CC23CC3B74EB895F075ACEA1DB358A3F02968D229F7AE23B4D7B1AB6FF75D85D1004A6EB8C6F1532B8FBA1BC162C7F217DBDB8B5574C57D62B0B94B2DA9E4A89A684
---- EOF - GMER 1.0.15 ----
Logi z OTL:
Extras:
http://wklej.org/hash/4e4baf02f3b/
otl:
http://wklej.org/hash/82764c2103d/