Scusami per lo san rootkit senza file però
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2008-03-11 16:34:51
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwClose
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwConnectPort
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwCreateFile
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwCreateKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreatePort
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwCreateSection
SSDT FCBBB4FC ZwCreateThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwDeleteFile
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwDeleteKey
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwLoadDriver
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwOpenFile
SSDT FCBBB4E8 ZwOpenProcess
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwOpenSection
SSDT FCBBB4ED ZwOpenThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetContextThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwSetValueKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwShutdownSystem
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS2\system32\drivers\sp_rsdrv2.sys ZwWriteFile
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwWriteFileGather
SSDT FCBBB4F2 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.12 ----
.text C:\Programmi\Comodo\Firewall\cpf.exe[1720] ntdll.dll!LdrLoadDll 7C9261CA 3 Bytes [ FF, 25, 1E ]
.text C:\Programmi\Comodo\Firewall\cpf.exe[1720] ntdll.dll!LdrLoadDll + 4 7C9261CE 2 Bytes [ 05, 5F ]
.text C:\Programmi\Comodo\Firewall\cpf.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F08001E
---- Registry - GMER 1.0.12 ----
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@bbpfkpoepdokjenlcggclmfmcoagndhpflpc 0x6A 0x61 0x6B 0x6C ...
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@abfeekcgphhpcfcjcdfpnkileejbemmfck 0x6A 0x61 0x6B 0x6C ...
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@ablfckamkaljaagdphcdbbmcgpikliebef 0x61 0x61 0x00 0x00
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@mamofmipnndmjhoijiaalbeboo 0x61 0x61 0x00 0x00
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@bbpfkpoepdokjenlcggclmfmcoagiakfdaig 0x6A 0x61 0x6B 0x6C ...
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@abfeekcgphhpcfcjcdfpnkileeobjhehap 0x6A 0x61 0x6C 0x6C ...
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@iapfkpoepdokjenlcg 0x61 0x61 0x00 0x00
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@hafeekcgphhpcfcj 0x61 0x61 0x00 0x00
Reg \Registry\USER\S-1-5-21-1614895754-1563985344-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2B3EAA5-F1EE-168B-3E5B-3665E6E47CCC}@ialfcjifechdmlkinl 0x61 0x61 0x00 0x00
---- EOF - GMER 1.0.12 ----