1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48. | GMER 1.0.15.15273 - http://www.gmer.net
Rootkit scan 2009-12-09 18:11:40
Windows 5.1.2600 Dodatek Service Pack 3
Running: gjfkign4.exe; Driver: C:\\DOCUME~1\\Belmondo\\USTAWI~1\\Temp\\awriqkog.sys
---- System - GMER 1.0.15 ----
SSDT 89BD58A0 ZwAssignProcessToJobObject
SSDT 89BD4CB0 ZwOpenProcess
SSDT 89BD50D0 ZwOpenThread
SSDT 89BD56D0 ZwSuspendProcess
SSDT 89BD54F0 ZwSuspendThread
SSDT 89BD4EE0 ZwTerminateProcess
SSDT 89BD5310 ZwTerminateThread
---- Kernel code sections - GMER 1.0.15 ----
.text C:\\WINDOWS\\system32\\DRIVERS\\nv4_mini.sys section is writeable [0xB97B7360, 0x32E00D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\\Program Files\\ESET\\ESET Smart Security\\ekrn.exe[200] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \\FileSystem\\Ntfs \\Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \\Driver\\Tcpip \\Device\\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \\Driver\\Tcpip \\Device\\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Device \\Driver\\atapi \\Device\\Ide\\IdeDeviceP3T0L0-12 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort0 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort1 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort2 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort3 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort4 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdePort5 [8A6486F2] atapi.sys[.reloc]
Device \\Driver\\atapi \\Device\\Ide\\IdeDeviceP0T1L0-3 [8A6486F2] atapi.sys[.reloc]
AttachedDevice \\Driver\\Tcpip \\Device\\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \\Driver\\Tcpip \\Device\\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- Threads - GMER 1.0.15 ----
Thread System [4:516] 89BD3930
---- EOF - GMER 1.0.15 ----
|