1)
http://www.virustotal.com/cs/analisis/5 ... 1276776932
Nic nenalezeno
2) Vím o tom, řeší se...
3) -
4) SPTD - krok přeskočen
5) Deffoger - OK
6) MBR
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
7) Gmer
LOG 1:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit quick scan 2010-06-17 14:34:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\kluchor\LOCALS~1\Temp\uwloapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
---- EOF - GMER 1.0.15 ----
LOG 2:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-06-17 15:21:08
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\kluchor\LOCALS~1\Temp\uwloapow.sys
---- System - GMER 1.0.15 ----
SSDT 888E1580 ZwAssignProcessToJobObject
SSDT 888E2100 ZwDebugActiveProcess
SSDT 888E1B30 ZwDuplicateObject
SSDT 888E0CC0 ZwOpenProcess
SSDT 888E0FC0 ZwOpenThread
SSDT 888E19C0 ZwProtectVirtualMemory
SSDT 888E1860 ZwSetContextThread
SSDT 888E16E0 ZwSetInformationThread
SSDT 888DE700 ZwSetSecurityObject
SSDT 888E1420 ZwSuspendProcess
SSDT 888E12C0 ZwSuspendThread
SSDT 888E0E50 ZwTerminateProcess
SSDT 888E1150 ZwTerminateThread
SSDT 888E1F50 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB904A380, 0x2F2537, 0xE8000020]
? C:\DOCUME~1\kluchor\LOCALS~1\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1336] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\WINDOWS\system32\SearchIndexer.exe[2004] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[3132] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 32605164 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[3132] ole32.dll!OleLoadFromStream 77519C85 5 Bytes JMP 330B9D32 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3724] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
---- EOF - GMER 1.0.15 ----
Pokračování asi zítra....