GMER 1.0.15.15627 -
http://www.gmer.net
Rootkit scan 2011-05-15 20:38:16
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\iaStor0 ST932032 rev.SD03
Running: gmer.exe; Driver: C:\DOCUME~1\VOJTCH~1\LOCALS~1\Temp\kgnyafoc.sys
---- System - GMER 1.0.15 ----
SSDT 87A5AC90 ZwAssignProcessToJobObject
SSDT spwy.sys ZwCreateKey [0xB9EB50E0]
SSDT 87A5B200 ZwDebugActiveProcess
SSDT 87A5B2F0 ZwDuplicateObject
SSDT spwy.sys ZwEnumerateKey [0xB9ECDDA4]
SSDT spwy.sys ZwEnumerateValueKey [0xB9ECE132]
SSDT spwy.sys ZwOpenKey [0xB9EB50C0]
SSDT 87A5A590 ZwOpenProcess
SSDT 87A5A800 ZwOpenThread
SSDT 87A5AFD0 ZwProtectVirtualMemory
SSDT spwy.sys ZwQueryKey [0xB9ECE20A]
SSDT spwy.sys ZwQueryValueKey [0xB9ECE08A]
SSDT 87A5B0E0 ZwQueueApcThread
SSDT 87A5AEC0 ZwSetContextThread
SSDT 87A5AD90 ZwSetInformationThread
SSDT 87A57DA0 ZwSetSecurityObject
SSDT spwy.sys ZwSetValueKey [0xB9ECE29C]
SSDT 87A5AB90 ZwSuspendProcess
SSDT 87A5AA80 ZwSuspendThread
SSDT 87A5A6E0 ZwTerminateProcess
SSDT 87A5AA50 ZwTerminateThread
SSDT 87A5B6D0 ZwWriteVirtualMemory
INT 0x63 ? 89B87BF8
INT 0x73 ? 8A6C1BF8
INT 0x73 ? 89B87BF8
INT 0x73 ? 89B87BF8
INT 0x73 ? 89B87BF8
INT 0x73 ? 8A6C1BF8
INT 0x94 ? 89B87BF8
INT 0xA4 ? 89B87BF8
INT 0xB4 ? 89B87BF8
INT 0xB4 ? 8A733BF8
INT 0xB4 ? 8A733BF8
INT 0xB4 ? 8A733BF8
INT 0xB4 ? 8A733BF8
Code \??\C:\DOCUME~1\VOJTCH~1\LOCALS~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
? spwy.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B84268AC 5 Bytes JMP 89B871D8
.text alzljty1.SYS B5587386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text alzljty1.SYS B55873AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text alzljty1.SYS B55873C4 3 Bytes [00, 80, 02]
.text alzljty1.SYS B55873C9 1 Byte [30]
.text alzljty1.SYS B55873C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !
? C:\DOCUME~1\VOJTCH~1\LOCALS~1\Temp\catchme.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[392] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EB1A
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EB8B
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90ECB9
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 15, 00]
.text C:\Documents and Settings\Vojtěch\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe[2220] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EC5B90] spwy.sys
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\alzljty1.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A6C01F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 89B861F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A7311F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A7311F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A7311F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A7311F8
Device \Driver\usbehci \Device\USBPDO-1 89B641F8
Device \Driver\usbuhci \Device\USBPDO-2 89B861F8
Device \Driver\usbuhci \Device\USBPDO-3 89B861F8
Device \Driver\PCI_PNP0066 \Device\00000054 spwy.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{9096A345-C3C6-48E4-94DB-3477F482BDA7} 87C191F8
Device \Driver\usbuhci \Device\USBPDO-4 89B861F8
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \Driver\usbuhci \Device\USBPDO-5 89B861F8
Device \Driver\usbehci \Device\USBPDO-6 89B641F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6C21F8
Device \Driver\usbuhci \Device\USBPDO-7 89B861F8
Device \Driver\Cdrom \Device\CdRom0 8998F1F8
Device \Driver\iaStor \Device\Ide\iaStor0 [B9D715A0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [B9D715A0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [B9D715A0] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 8998F1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 87C191F8
Device \Driver\NetBT \Device\NetbiosSmb 87C191F8
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \Driver\usbuhci \Device\USBFDO-0 89B861F8
Device \Driver\usbuhci \Device\USBFDO-1 89B861F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 879C31F8
Device \Driver\usbuhci \Device\USBFDO-2 89B861F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 879C31F8
Device \Driver\usbehci \Device\USBFDO-3 89B641F8
Device \Driver\usbuhci \Device\USBFDO-4 89B861F8
Device \Driver\Ftdisk \Device\FtControl 8A6C21F8
Device \Driver\usbuhci \Device\USBFDO-5 89B861F8
Device \Driver\usbuhci \Device\USBFDO-6 89B861F8
Device \Driver\usbehci \Device\USBFDO-7 89B641F8
Device \Driver\alzljty1 \Device\Scsi\alzljty11 8998B1F8
Device \Driver\JMCR \Device\Scsi\JMCR1 89B4F1F8
Device \Driver\JMCR \Device\Scsi\JMCR2 89B4F1F8
Device \Driver\JMCR \Device\Scsi\JMCR3 89B4F1F8
Device \Driver\JMCR \Device\Scsi\JMCR4 89B4F1F8
Device \Driver\alzljty1 \Device\Scsi\alzljty11Port1Path0Target0Lun0 8998B1F8
Device \Driver\sptd \Device\3616792566 spwy.sys
Device \FileSystem\Cdfs \Cdfs 88FE1500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000df05e2038
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000df05e2038@001f012a19a2 0x8A 0xBB 0xBB 0xE3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000df05e2038@0012620f4764 0x31 0xE0 0xFF 0xB2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000df05e2038@0025cf5c9d53 0xEE 0x54 0xAA 0x5A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x44 0x81 0x50 0xDA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xAF 0x4F 0x54 0x48 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2A 0x7A 0x16 0xFE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xD9 0x3F 0x9E 0x6D ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000df05e2038 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000df05e2038@001f012a19a2 0x8A 0xBB 0xBB 0xE3 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000df05e2038@0012620f4764 0x31 0xE0 0xFF 0xB2 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000df05e2038@0025cf5c9d53 0xEE 0x54 0xAA 0x5A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x44 0x81 0x50 0xDA ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xAF 0x4F 0x54 0x48 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2A 0x7A 0x16 0xFE ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xD9 0x3F 0x9E 0x6D ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- Files - GMER 1.0.15 ----
---- EOF - GMER 1.0.15 ----