torvitas | 15.09.2009 15:29 | hier der GMER log: Code:
GMER 1.0.15.15086 - h**p://www.gmer.net
Rootkit scan 2009-09-15 16:24:07
Windows 5.1.2600 Service Pack 2
Running: cppnk76s.exe; Driver: C:\DOKUME~1\***\LOKALE~1\Temp\aujasnkj.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAF0516B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAF051574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAF051A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAF05114C]
SSDT spdg.sys ZwEnumerateKey [0xBA6C5CA4]
SSDT spdg.sys ZwEnumerateValueKey [0xBA6C6032]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAF05164E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAF05108C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAF0510F0]
SSDT spdg.sys ZwQueryKey [0xBA6C610A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAF05176E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAF05172E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAF0518AE]
SSDT \??\C:\Programme\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAF12F0B0]
INT 0x62 ? 89B0ABF8
INT 0x73 ? 898AABF8
INT 0x73 ? 898AABF8
INT 0x82 ? 89B0ABF8
INT 0x83 ? 89B0ABF8
INT 0xA4 ? 898AABF8
INT 0xB4 ? 898AABF8
---- Kernel code sections - GMER 1.0.15 ----
? spdg.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload B7AFC62C 5 Bytes JMP 898AA1D8
.text akw6f31z.SYS B7A33386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text akw6f31z.SYS B7A333AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text akw6f31z.SYS B7A333C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text akw6f31z.SYS B7A333C9 1 Byte [30]
.text akw6f31z.SYS B7A333C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A8042] spdg.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A813E] spdg.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A80C0] spdg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A8800] spdg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A86D6] spdg.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6B7E9C] spdg.sys
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KfAcquireSpinLock] 0C8D1C46
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!READ_PORT_UCHAR] B08B8932
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KeGetCurrentIrql] 89000001
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KfRaiseIrql] 0001BC83
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KfLowerIrql] 24468B00
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!HalGetInterruptVector] 89820C8D
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!HalTranslateBusAddress] D18BF84D
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KeStallExecutionProcessor] 860F1639
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!KfReleaseSpinLock] 000000BD
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0208B389
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 7400067E
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[HAL.dll!WRITE_PORT_UCHAR] 89D60320
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[WMILIB.SYS!WmiSystemControl] 8D168B00
IAT \SystemRoot\System32\Drivers\akw6f31z.SYS[WMILIB.SYS!WmiCompleteRequest] F0003284
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[772] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00370002
IAT C:\WINDOWS\system32\services.exe[772] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00370000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89B091F8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{F9EF0DE5-913A-49F2-951F-0BA8B8D381C6} 8981F500
Device \Driver\PCI_PNP7786 \Device\00000044 spdg.sys
Device \Driver\usbohci \Device\USBPDO-0 898A81F8
Device \Driver\usbohci \Device\USBPDO-1 898A81F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89B771F8
Device \Driver\dmio \Device\DmControl\DmConfig 89B771F8
Device \Driver\dmio \Device\DmControl\DmPnP 89B771F8
Device \Driver\dmio \Device\DmControl\DmInfo 89B771F8
Device \Driver\usbohci \Device\USBPDO-2 898A81F8
Device \Driver\usbohci \Device\USBPDO-3 898A81F8
Device \Driver\usbohci \Device\USBPDO-4 898A81F8
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbehci \Device\USBPDO-5 898701F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89B0B1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89B0B1F8
Device \Driver\Cdrom \Device\CdRom0 898621F8
Device \Driver\Cdrom \Device\CdRom1 898621F8
Device \Driver\atapi \Device\Ide\IdePort0 89B0A1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 89B0A1F8
Device \Driver\atapi \Device\Ide\IdePort1 89B0A1F8
Device \Driver\atapi \Device\Ide\IdePort2 89B0A1F8
Device \Driver\atapi \Device\Ide\IdePort3 89B0A1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-12 89B0A1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8981F500
Device \Driver\NetBT \Device\NetbiosSmb 8981F500
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\sptd \Device\1523521536 spdg.sys
Device \Driver\usbohci \Device\USBFDO-0 898A81F8
Device \Driver\usbohci \Device\USBFDO-1 898A81F8
Device \Driver\usbohci \Device\USBFDO-2 898A81F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89629500
Device \Driver\usbohci \Device\USBFDO-3 898A81F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89629500
Device \Driver\Ftdisk \Device\FtControl 89B0B1F8
Device \Driver\usbohci \Device\USBFDO-4 898A81F8
Device \Driver\usbehci \Device\USBFDO-5 898701F8
Device \Driver\akw6f31z \Device\Scsi\akw6f31z1 897961F8
Device \Driver\akw6f31z \Device\Scsi\akw6f31z1Port4Path0Target0Lun0 897961F8
Device \FileSystem\Cdfs \Cdfs 89769500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA2 0x3C 0x4B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x82 0x8D 0xB0 0x45 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x39 0x15 0x19 0x07 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA2 0x3C 0x4B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x82 0x8D 0xB0 0x45 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x39 0x15 0x19 0x07 ...
---- EOF - GMER 1.0.15 ---- |