UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0) Gecko/20100101 Firefox/6.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0) Gecko/20100101 Firefox/6.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-08-26 16:00:01
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 \Device\0000005f SAMSUNG_HD501LJ rev.CR100-10
Running: gmer.exe; Driver: C:\DOCUME~1\Cripz\USTAWI~1\Temp\fwriapob.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 61
Disk \Device\Harddisk0\DR0 PE file @ sector 976752000
---- System - GMER 1.0.15 ----
SSDT spcw.sys ZwEnumerateKey [0xB7EC6CA2]
SSDT spcw.sys ZwEnumerateValueKey [0xB7EC7030]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdePort0 [B7E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\a3kbxgt8 \Device\Scsi\a3kbxgt81 8A15E500
Device \Driver\a3kbxgt8 \Device\Scsi\a3kbxgt81Port4Path0Target0Lun0 8A15E500
Device \FileSystem\Ntfs \Ntfs 8A55C1F8
AttachedDevice \Driver\Tcpip \Device\Tcp idmtdi.sys (Internet Download Manager TDI Driver/Tonec Inc.)
---- EOF - GMER 1.0.15 ----
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.50
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.9.168 Version/11.51
Zarejestrowani użytkownicy: Bing [Bot]