GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-20 22:28:05
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT sptd.sys ZwCreateKey [0xF76C3B3A]
SSDT F7E4C214 ZwCreateThread
SSDT sptd.sys ZwEnumerateKey [0xF76C3C7E]
SSDT sptd.sys ZwEnumerateValueKey [0xF76C3FF6]
SSDT sptd.sys ZwOpenKey [0xF76C3A18]
SSDT F7E4C200 ZwOpenProcess
SSDT F7E4C205 ZwOpenThread
SSDT sptd.sys ZwQueryKey [0xF76C40C0]
SSDT sptd.sys ZwQueryValueKey [0xF76C3F58]
SSDT sptd.sys ZwSetValueKey [0xF76C4148]
SSDT F7E4C20F ZwTerminateProcess
SSDT F7E4C20A ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.14 ----
? tstkyt.sys Das System kann die angegebene Datei nicht finden. !
? C:\WINDOWS\system32\drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
? C:\WINDOWS\System32\Drivers\SPTD4413.SYS Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 F63534D0 3 Bytes [ EE, 1E, 71 ]
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 4 F63534D4 12 Bytes [ 29, E1, 12, A1, FF, 75, 50, ... ]
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 11 F63534E1 31 Bytes [ 20, 35, F6, B2, 21, C5, 34, ... ]
? C:\WINDOWS\System32\Drivers\dtscsi.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F76CCDB2] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F76E271E] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F76CD3B2] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F76CD2B6] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F76CD482] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IofCallDriver] [F76CD482] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F76CD3B2] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F76CD2B6] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F76E2032] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F76CCF6E] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F76E2864] sptd.sys
IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F76D1F78] sptd.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F76E1C76] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F76E1C82] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F76E2864] sptd.sys
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F76BF020] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F76BF020] sptd.sys
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 87388C78
Device \FileSystem\Fastfat \FatCdrom 86013708
Device \FileSystem\Fastfat \FatCdrom 86E4288C
Device \Driver\dmio \Device\DmControl\DmIoDaemon 873D4A40
Device \Driver\dmio \Device\DmControl\DmConfig 873D4A40
Device \Driver\dmio \Device\DmControl\DmPnP 873D4A40
Device \Driver\dmio \Device\DmControl\DmInfo 873D4A40
Device \Driver\prodrv06 \Device\ProDrv06 E1A60C30
Device \Driver\Ftdisk \Device\HarddiskVolume1 873D4C78
Device \Driver\Ftdisk \Device\HarddiskVolume2 873D4C78
Device \Driver\Cdrom \Device\CdRom0 86E8B008
Device \FileSystem\Rdbss \Device\FsWrap 871B3458
Device \FileSystem\Rdbss \Device\FsWrap 86F52B44
Device \Driver\Cdrom \Device\CdRom1 86E8B008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86F21008
Device \Driver\atapi \Device\Ide\IdePort0 86F21008
Device \Driver\Cdrom \Device\CdRom2 86E8B008
Device \Driver\Cdrom \Device\CdRom3 86E8B008
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D9375D0-B53C-46D9-BF7E-9DF2B8FE601C} 86FD20E8
Device \Driver\Cdrom \Device\CdRom4 86E8B008
Device \Driver\USBSTOR \Device\000000a8 871AA6D0
Device \Driver\prohlp02 \Device\ProHlp02 E18D6780
Device \Driver\USBSTOR \Device\000000a9 871AA6D0
Device \Driver\NetBT \Device\NetBt_Wins_Export 86FD20E8
Device \Driver\NetBT \Device\NetbiosSmb 86FD20E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{0F2107D0-6C63-4E7F-BBAC-8DFACE06719E} 86FD20E8
Device \FileSystem\Srv \Device\LanmanServer 872797EC
Device \Driver\00000050 \Device\0000005c sptd.sys
Device \Driver\Disk \Device\Harddisk0\DR0 87388EB0
Device \Driver\Disk \Device\Harddisk1\DR1 87388EB0
Device \Driver\Disk \Device\Harddisk2\DR6 87388EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 87388EB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86EEC0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8711D4B4
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86EEC0E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8711D4B4
Device \FileSystem\Npfs \Device\NamedPipe 87029CB8
Device \FileSystem\Npfs \Device\NamedPipe 86CDFCB4
Device \Driver\Ftdisk \Device\FtControl 873D4C78
Device \FileSystem\Msfs \Device\Mailslot 86CD6118
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 871AD058
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target6Lun0 873D4550
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target6Lun0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target1Lun0 873D4550
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target1Lun0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 86176C38
Device \Driver\KR10N \Device\Scsi\KR10N1 873D4550
Device \Driver\KR10N \Device\Scsi\KR10N1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 871AD058
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target0Lun0 873D4550
Device \Driver\KR10N \Device\Scsi\KR10N1Port1Path0Target0Lun0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 871AD058
Device \Driver\dtscsi \Device\Scsi\dtscsi1 871AD058
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 871AD058
Device \FileSystem\Fastfat \Fat 86013708
Device \FileSystem\Fastfat \Fat 86E4288C
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 870422FC
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 870422FC
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 870422FC
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 870422FC
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 870422FC
Device \FileSystem\Cdfs \Cdfs 86D1A0E8
Device \FileSystem\Cdfs \Cdfs 871910AC
---- Modules - GMER 1.0.14 ----
Module _________ F75C8000-F75E0000 (98304 bytes)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE5 0x3D 0xF3 0xAB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x86 0x31 0x04 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCC 0xFE 0x85 0x7F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xCD 0xCF 0xA8 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x3A 0x01 0x63 0x40 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x3A 0x01 0x63 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 -1267934926
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -887537436
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 530801311
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE5 0x3D 0xF3 0xAB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x86 0x31 0x04 0x7E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCC 0xFE 0x85 0x7F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xCD 0xCF 0xA8 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x3A 0x01 0x63 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x3A 0x01 0x63 0x40 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG06.00.00.01WORKSTATION D8805FE6CAC0FD1F50DDEC1272C58C614F5AC7E936AC24216B4938C9D14162DB8960EC2B43527A304098E4715915F7F680961C4C061AE16D22B114AE0E5624F1AA7BA9CAF9B84BCBF0E0372C635194860FD989D28C85C65EA125FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6679DB7CE019D40AA5C5D575E7D6A3B9808FEBC9E127BECC74C023291A1B28850424D01CD36BCB411C0DB5AC4A7564D845188F27A775250DEC7767D88B4762721EB00CFBBA6DD15D4B58210F79F222B1C1C6BF771CAD8DA9AF1A3AA37975F089A57BE130D2EF93C953580DC0DF4BDD801CEB56DA72ACBE771DD53FCE986E0F00741EC3B1278326B34BDF8F87C6496AF46C9E6F25C03050A4D6B02A1C1BEE14E482D251AF0331A06A513C18090AD8EAC1630B1109CC454F5ADC1DEA532023EAB4F60B4E62491381471BBE474689379F02E6AFE2D4EE57987A4C850FA0594433E23659D3EF74B8AC03304223A76DDA140DE266997275DACBBD62DED7957C0B45C610B15A01119005C9D79EB18015842040ED0BF00B32916340061055A9955490238E1046EE1BA7D5BF170E63BA3D28D4934A1877DD3C85438ED1994BC90232D4CE94089703672D8D48A80EF35CCA0A9425F8EF588BB4279AF044F5222547F7EFECEC275532B07E005538315793F1AAD4
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG10.00.00.01WORKSTATION 0BE8DA16D80848BB3FEB834C4521BE7A3EA9BBECC265A6EF1F0D3500510E288268BEB85D53BB9343FB67E56F405A2114133D7AC66A5BC628C36738854FBDA4CEA2AA51877AE7748FE66FE3F174CD1799A68E0C844FEC25F9A56F823A2B0E96B128004742E4E77D08656D654243FCC6BD7B393A6CB8DC1587FC98DD6336A7A45A8C25886E90674308055C957B70B856ABB56F11FA5544EFE6A969577A2786786D0796C0215BE8E1E0764CE372A4A7F1001EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D6794A6A0AC4980AC7933C038D530D6EB3452AE804B0E791A67A8F85488591BFBD162D53AF0805C022867ECB71E5579CD6B7BB0B404DFA575D00CA341BB0DED4CF0AD67DB167276B0C6269B5681A182F9750492C3BA8AC86C6ECBCDF3D3ECA1BE54B04F818BDA79323E603B76E94EA0BABFDF48F3BDC45D2FC86F7FF2DCF9D417CF8A4C15B5A5CAFB51705E80BA4D9ED41841D84D8FAAAFF45A23540A931AFC1DAD012FC1339EA08636542AA08C76191141FE5FA064BA63F916377E486B92DD9BA8FC5CF752F606CB972D59C8AC03003EF2950BFE2658ECF9DC1FBF808B1294E3F38CCF6B17C4DD5013C13BAF1A12992E59211FBE73CC96B9887272C94D290EC7B45E1415B801D916BA7B314B0C25FB359
---- EOF - GMER 1.0.14 ----