Amministratore
28-10-2009, 11:28
Ciao!
Facendo la scansione con GMER, viene trovata una libreria nascosta (PxSecure.dll) e segnalata come possibile attivitā rootkit?!
Mi devo preoccupare?
Segue log completo della scansione:
GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-10-28 12:22:55
Windows 5.1.2600 Service Pack 3
Running: GMER pmy4kw4w.exe; Driver: C:\DOCUME~1\a\IMPOST~1\Temp\uwlyrpob.sys
---- System - GMER 1.0.15 ----
SSDT 88FD6420 ZwAlertResumeThread
SSDT 88FD6598 ZwAlertThread
SSDT 891DA228 ZwAllocateVirtualMemory
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwAssignProcessToJobObject [0xB64AC480]
SSDT 89041AE0 ZwConnectPort
SSDT 88FD60F8 ZwCreateMutant
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwCreateThread [0xB64AC4D0]
SSDT \??\C:\Programmi\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0x9D58F350]
SSDT 88FCBA18 ZwFreeVirtualMemory
SSDT 88FD6130 ZwImpersonateAnonymousToken
SSDT 88FD62A8 ZwImpersonateThread
SSDT 890C5AB8 ZwMapViewOfSection
SSDT 88FD60C0 ZwOpenEvent
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwOpenProcess [0xB64AC890]
SSDT 88FDA0D0 ZwOpenProcessToken
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwOpenThread [0xB64AC720]
SSDT 88FFFBC8 ZwOpenThreadToken
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwProtectVirtualMemory [0xB64AC570]
SSDT 8912E938 ZwQueryValueKey
SSDT 88FFBC58 ZwResumeThread
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwSetContextThread [0xB64AC430]
SSDT 88FFFE40 ZwSetInformationProcess
SSDT 88FD6A00 ZwSetInformationThread
SSDT \??\C:\Programmi\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0x9D58F580]
SSDT 88FC8CB8 ZwSuspendProcess
SSDT 88FD6710 ZwSuspendThread
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwTerminateProcess [0xB64ACA30]
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwTerminateThread [0xB64AC610]
SSDT 88FCB800 ZwUnmapViewOfSection
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwWriteVirtualMemory [0xB64AC660]
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 33A 804E4B74 4 Bytes JMP 5290D48B
.text ntoskrnl.exe!ZwYieldExecution + 452 804E4C8C 2 Bytes [80, F5]
? C:\WINDOWS\System32\drivers\pxkbf.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\System32\drivers\pxscan.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\System32\drivers\pxrts.sys Impossibile trovare il file specificato. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[200] ntdll.dll!NtWriteFile 7C91DF7E 5 Bytes JMP 03285A80 C:\WINDOWS\system32\PxSecure.dll
.text C:\WINDOWS\Explorer.EXE[200] kernel32.dll!CreateThread 7C8106D7 5 Bytes JMP 03285150 C:\WINDOWS\system32\PxSecure.dll
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip pxrts.sys
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp pxrts.sys
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp pxrts.sys
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- Processes - GMER 1.0.15 ----
Library C:\WINDOWS\system32\PxSecure.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [200] 0x03280000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001641dc7e88
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001641dc7e88 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
:confused:
Facendo la scansione con GMER, viene trovata una libreria nascosta (PxSecure.dll) e segnalata come possibile attivitā rootkit?!
Mi devo preoccupare?
Segue log completo della scansione:
GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-10-28 12:22:55
Windows 5.1.2600 Service Pack 3
Running: GMER pmy4kw4w.exe; Driver: C:\DOCUME~1\a\IMPOST~1\Temp\uwlyrpob.sys
---- System - GMER 1.0.15 ----
SSDT 88FD6420 ZwAlertResumeThread
SSDT 88FD6598 ZwAlertThread
SSDT 891DA228 ZwAllocateVirtualMemory
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwAssignProcessToJobObject [0xB64AC480]
SSDT 89041AE0 ZwConnectPort
SSDT 88FD60F8 ZwCreateMutant
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwCreateThread [0xB64AC4D0]
SSDT \??\C:\Programmi\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0x9D58F350]
SSDT 88FCBA18 ZwFreeVirtualMemory
SSDT 88FD6130 ZwImpersonateAnonymousToken
SSDT 88FD62A8 ZwImpersonateThread
SSDT 890C5AB8 ZwMapViewOfSection
SSDT 88FD60C0 ZwOpenEvent
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwOpenProcess [0xB64AC890]
SSDT 88FDA0D0 ZwOpenProcessToken
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwOpenThread [0xB64AC720]
SSDT 88FFFBC8 ZwOpenThreadToken
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwProtectVirtualMemory [0xB64AC570]
SSDT 8912E938 ZwQueryValueKey
SSDT 88FFBC58 ZwResumeThread
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwSetContextThread [0xB64AC430]
SSDT 88FFFE40 ZwSetInformationProcess
SSDT 88FD6A00 ZwSetInformationThread
SSDT \??\C:\Programmi\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0x9D58F580]
SSDT 88FC8CB8 ZwSuspendProcess
SSDT 88FD6710 ZwSuspendThread
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwTerminateProcess [0xB64ACA30]
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwTerminateThread [0xB64AC610]
SSDT 88FCB800 ZwUnmapViewOfSection
SSDT \SystemRoot\System32\drivers\pxrts.sys ZwWriteVirtualMemory [0xB64AC660]
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 33A 804E4B74 4 Bytes JMP 5290D48B
.text ntoskrnl.exe!ZwYieldExecution + 452 804E4C8C 2 Bytes [80, F5]
? C:\WINDOWS\System32\drivers\pxkbf.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\System32\drivers\pxscan.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\System32\drivers\pxrts.sys Impossibile trovare il file specificato. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[200] ntdll.dll!NtWriteFile 7C91DF7E 5 Bytes JMP 03285A80 C:\WINDOWS\system32\PxSecure.dll
.text C:\WINDOWS\Explorer.EXE[200] kernel32.dll!CreateThread 7C8106D7 5 Bytes JMP 03285150 C:\WINDOWS\system32\PxSecure.dll
.text C:\WINDOWS\system32\SearchIndexer.exe[1156] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip pxrts.sys
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp pxrts.sys
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp pxrts.sys
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- Processes - GMER 1.0.15 ----
Library C:\WINDOWS\system32\PxSecure.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [200] 0x03280000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001641dc7e88
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001641dc7e88 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
:confused: