24 Sie 2011, 17:46
25 Sie 2011, 12:17
25 Sie 2011, 18:36
26 Sie 2011, 12:12
26 Sie 2011, 15:45
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-08-26 16:00:01
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 \Device\0000005f SAMSUNG_HD501LJ rev.CR100-10
Running: gmer.exe; Driver: C:\DOCUME~1\Cripz\USTAWI~1\Temp\fwriapob.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 61
Disk \Device\Harddisk0\DR0 PE file @ sector 976752000
---- System - GMER 1.0.15 ----
SSDT spcw.sys ZwEnumerateKey [0xB7EC6CA2]
SSDT spcw.sys ZwEnumerateValueKey [0xB7EC7030]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdePort0 [B7E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\a3kbxgt8 \Device\Scsi\a3kbxgt81 8A15E500
Device \Driver\a3kbxgt8 \Device\Scsi\a3kbxgt81Port4Path0Target0Lun0 8A15E500
Device \FileSystem\Ntfs \Ntfs 8A55C1F8
AttachedDevice \Driver\Tcpip \Device\Tcp idmtdi.sys (Internet Download Manager TDI Driver/Tonec Inc.)
---- EOF - GMER 1.0.15 ----
27 Sie 2011, 13:03
28 Sie 2011, 13:10
28 Sie 2011, 20:27
28 Sie 2011, 20:34
28 Sie 2011, 20:57
28 Sie 2011, 21:03
28 Sie 2011, 22:50
30 Sie 2011, 10:10
12 Wrz 2011, 21:34