druhy log
GMER 1.0.15.15627 -
http://www.gmer.net
Rootkit scan 2011-05-18 11:11:42
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 MAXTOR_6L080L4 rev.A93.0500
Running: gmer.exe; Driver: C:\DOCUME~1\Martin\LOCALS~1\Temp\pfedrfow.sys
---- System - GMER 1.0.15 ----
SSDT spgg.sys ZwCreateKey [0xF72940E0]
SSDT spgg.sys ZwEnumerateKey [0xF72ACDA4]
SSDT spgg.sys ZwEnumerateValueKey [0xF72AD132]
SSDT spgg.sys ZwOpenKey [0xF72940C0]
SSDT spgg.sys ZwQueryKey [0xF72AD20A]
SSDT spgg.sys ZwQueryValueKey [0xF72AD08A]
SSDT spgg.sys ZwSetValueKey [0xF72AD29C]
INT 0x62 ? 86D73BF8
INT 0x63 ? 86BF2BF8
INT 0x73 ? 86BF2BF8
INT 0x82 ? 86D73BF8
INT 0x83 ? 86D73BF8
INT 0x83 ? 86D73BF8
INT 0x83 ? 86D73BF8
---- Kernel code sections - GMER 1.0.15 ----
? spgg.sys Systém nemôže nájsť zadaný súbor. !
.text USBPORT.SYS!DllUnload F70498AC 5 Bytes JMP 86BF21D8
.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF63D53A0, 0x5FE082, 0xE8000020]
.text axk4zdmm.SYS F6388386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text axk4zdmm.SYS F63883AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text axk4zdmm.SYS F63883C4 3 Bytes [00, 80, 02]
.text axk4zdmm.SYS F63883C9 1 Byte [30]
.text axk4zdmm.SYS F63883C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Programy\Mozilla\firefox.exe[2228] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00401410 C:\Programy\Mozilla\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Programy\Mozilla\plugin-container.exe[2424] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 10698DD9 C:\Programy\Mozilla\xul.dll (Mozilla Foundation)
.text C:\Programy\Mozilla\plugin-container.exe[2424] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 10698D6B C:\Programy\Mozilla\xul.dll (Mozilla Foundation)
.text C:\Programy\Mozilla\plugin-container.exe[2424] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104C7187 C:\Programy\Mozilla\xul.dll (Mozilla Foundation)
.text C:\Programy\Mozilla\plugin-container.exe[2424] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104C7781 C:\Programy\Mozilla\xul.dll (Mozilla Foundation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7295042] spgg.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F729513E] spgg.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F72950C0] spgg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F7295800] spgg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F72956D6] spgg.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F72A4B90] spgg.sys
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\axk4zdmm.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86D721F8
Device \FileSystem\Fastfat \FatCdrom 860431F8
Device \Driver\usbohci \Device\USBPDO-0 86BE11F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86DDF1F8
Device \Driver\dmio \Device\DmControl\DmConfig 86DDF1F8
Device \Driver\dmio \Device\DmControl\DmPnP 86DDF1F8
Device \Driver\dmio \Device\DmControl\DmInfo 86DDF1F8
Device \Driver\usbohci \Device\USBPDO-1 86BE11F8
Device \Driver\usbehci \Device\USBPDO-2 86B901F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{82E1B57E-D3D6-4597-B223-9532A75A4DAE} 860991F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86D741F8
Device \Driver\Cdrom \Device\CdRom0 86B1A500
Device \Driver\atapi \Device\Ide\IdePort0 [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1b [F71D7B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 86B1A500
Device \Driver\Cdrom \Device\CdRom2 86B1A500
Device \Driver\PCI_PNP4276 \Device\0000003d spgg.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 860991F8
Device \Driver\NetBT \Device\NetbiosSmb 860991F8
Device \Driver\sptd \Device\1537843026 spgg.sys
Device \Driver\usbohci \Device\USBFDO-0 86BE11F8
Device \Driver\usbohci \Device\USBFDO-1 86BE11F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8607F1F8
Device \Driver\usbehci \Device\USBFDO-2 86B901F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8607F1F8
Device \Driver\Ftdisk \Device\FtControl 86D741F8
Device \Driver\axk4zdmm \Device\Scsi\axk4zdmm1 86A431F8
Device \Driver\axk4zdmm \Device\Scsi\axk4zdmm1Port5Path0Target0Lun0 86A431F8
Device \FileSystem\Fastfat \Fat 860431F8
Device \FileSystem\Cdfs \Cdfs 860711F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programy\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x79 0x10 0x3A 0x69 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x85 0xA8 0xD1 0x3D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA4 0xC8 0x20 0xBD ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programy\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x79 0x10 0x3A 0x69 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x85 0xA8 0xD1 0x3D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA4 0xC8 0x20 0xBD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programy\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x79 0x10 0x3A 0x69 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x85 0xA8 0xD1 0x3D ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA4 0xC8 0x20 0xBD ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- EOF - GMER 1.0.15 ----