Созданные ответы форума
-
АвторСообщения
-
GMER 1.0.14.14536 — http://www.gmer.net
Rootkit scan 2009-03-12 21:01:39
Windows 5.1.2600 Service Pack 3—- System — GMER 1.0.14 —-
Code 84948588 ZwEnumerateKey
Code 84988290 ZwFlushInstructionCache
Code F3731482 pIofCallDriver—- Kernel IAT/EAT — GMER 1.0.14 —-
IAT SystemRootsystem32DRIVERSarp1394.sys[NDIS.SYS!NdisCloseAdapter] [F36710F0] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSarp1394.sys[NDIS.SYS!NdisOpenAdapter] [F3671060] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSarp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [F3671010] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSarp1394.sys[NDIS.SYS!NdisRegisterProtocol] [F3670FB0] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F3670FB0] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F3671010] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F36710F0] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
IAT SystemRootsystem32DRIVERSndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F3671060] ??C:PROGRA~1AgnitumOUTPOS~1.0kernel2000FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)—- Devices — GMER 1.0.14 —-
AttachedDevice FileSystemNtfs Ntfs spider.sys (SpIDer Guard File System Monitor/Doctor Web, Ltd.)
AttachedDevice DriverTcpip DeviceIp FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
AttachedDevice DriverTcpip DeviceTcp FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
AttachedDevice DriverTcpip DeviceUdp FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
AttachedDevice DriverTcpip DeviceRawIp FILTNT.SYS (Virtual Firewall driver/Agnitum Ltd.)
AttachedDevice FileSystemFastfat Fat spider.sys (SpIDer Guard File System Monitor/Doctor Web, Ltd.)—- Modules — GMER 1.0.14 —-
Module systemrootsystem32driverssenekarviqjyeq.sys (*** hidden *** ) F372F000-F3755000 (155648 bytes)
—- Services — GMER 1.0.14 —-
Service C:WINDOWSsystem32driverssenekarviqjyeq.sys (*** hidden *** ) [SYSTEM] seneka <-- ROOTKIT !!!
Service C:WINDOWSsystem32DRIVERSvdrv9000.sys (*** hidden *** ) [SYSTEM] vdrv9000 <-- ROOTKIT !!! —- Registry — GMER 1.0.14 —- Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@! 0454B 045 0424>494 000 044 0404?4B 0454@4 001 003 9 004 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@34484=484?4>4@4B4 W A N ( L 002 T P ) 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@34484=484?4>4@4B4 W A N ( P P T P ) 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@34484=484?4>4@4B4 W A N ( P P P o E ) 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@374@4O4<4>494 ? 0404@ 0404;4; 0454;4L4=4K494 ?4>4@4B4 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@34484=484?4>4@4B4 W A N ( I P ) 1?
Reg HKLMSYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}Descriptions@34484=484?4>4@4B4 ?4; 0404=484@4> 0424I484: 0404 ? 0404: 0454B4> 0424 1?2?3?4?
Reg HKLMSYSTEMCurrentControlSetServicesLanmanServerShares@374@484=4B 0454@4 CSCFlags=0?MaxUses=4294967295?Path=Presenter-to-Go,LocalsplOnly?Permissions=0?Remark=Presenter-to-Go?Type=1?
Reg HKLMSYSTEMCurrentControlSetServicesLanmanServerShares@36 0414<