Re: Vírus v Operačnej pamäti !
Napsal: 21 pro 2010 15:53
Tu je druhý :
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-20 15:54:32
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD800BB-00JHC0 rev.05.01C05
Running: gmer.exe; Driver: C:\DOCUME~1\karkas\LOCALS~1\Temp\ugloiaog.sys
---- System - GMER 1.0.15 ----
SSDT 85F51C90 ZwAssignProcessToJobObject
SSDT 85F52200 ZwDebugActiveProcess
SSDT 85F522F0 ZwDuplicateObject
SSDT 85F51590 ZwOpenProcess
SSDT 85F51800 ZwOpenThread
SSDT 85F51FD0 ZwProtectVirtualMemory
SSDT 85F520E0 ZwQueueApcThread
SSDT 85F51EC0 ZwSetContextThread
SSDT 85F51D90 ZwSetInformationThread
SSDT 85F4EDA0 ZwSetSecurityObject
SSDT 85F51B90 ZwSuspendProcess
SSDT 85F51A80 ZwSuspendThread
SSDT 85F516E0 ZwTerminateProcess
SSDT 85F51A50 ZwTerminateThread
SSDT 85F526D0 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1884] kernel32.dll!SetUnhandledExceptionFilter 7C8447ED 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\EagleNT \Device\EAGLENT A5063330
Device \Driver\Kbdclass \Device\KeyboardClass0 A5069890
Device \Driver\Kbdclass \Device\KeyboardClass1 A5069890
Device \Driver\Mouclass \Device\PointerClass0 A506A1E0
Device \Driver\Mouclass \Device\PointerClass1 A506A1E0
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-20 15:54:32
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD800BB-00JHC0 rev.05.01C05
Running: gmer.exe; Driver: C:\DOCUME~1\karkas\LOCALS~1\Temp\ugloiaog.sys
---- System - GMER 1.0.15 ----
SSDT 85F51C90 ZwAssignProcessToJobObject
SSDT 85F52200 ZwDebugActiveProcess
SSDT 85F522F0 ZwDuplicateObject
SSDT 85F51590 ZwOpenProcess
SSDT 85F51800 ZwOpenThread
SSDT 85F51FD0 ZwProtectVirtualMemory
SSDT 85F520E0 ZwQueueApcThread
SSDT 85F51EC0 ZwSetContextThread
SSDT 85F51D90 ZwSetInformationThread
SSDT 85F4EDA0 ZwSetSecurityObject
SSDT 85F51B90 ZwSuspendProcess
SSDT 85F51A80 ZwSuspendThread
SSDT 85F516E0 ZwTerminateProcess
SSDT 85F51A50 ZwTerminateThread
SSDT 85F526D0 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1884] kernel32.dll!SetUnhandledExceptionFilter 7C8447ED 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\EagleNT \Device\EAGLENT A5063330
Device \Driver\Kbdclass \Device\KeyboardClass0 A5069890
Device \Driver\Kbdclass \Device\KeyboardClass1 A5069890
Device \Driver\Mouclass \Device\PointerClass0 A506A1E0
Device \Driver\Mouclass \Device\PointerClass1 A506A1E0
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- EOF - GMER 1.0.15 ----