Šta dalje??

3

Šta dalje??

offline
  • Data Center Engineer
  • Pridružio: 13 Avg 2004
  • Poruke: 3050
  • Gde živiš: Holandija

Jel imaš uključen show hidden files and folders? Otvoriš Windows Explorer, pa Tools->Folder options, otvoriš tab view i pod Hidden files and folders namesti da se vide.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Imam uključen HF a F i opet ništa .Da ne tražim možda pogrešan fajl?

Dopuna: 13 Mar 2007 22:46

Jesmo li odustali od mog problema?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Nismo, ali je komplikovano.
Sumnjam da imamo posla sa nekom infekcijom koja menja ime pri svakom restartu kompa.

Skini WinPFind3U.exe na desktop i dvoklik na njega da bi ga raspakovao. Kreiraće se folder WinPFind3u na desktopu.

Uđi u folder WinPFind3u i dvoklik na WinPFind3U.exe da bi startovali program.
U Files Created Within grupi kliknuti 30 days
U Files Modified Within grupi selektovati 30 days
U File String Search grupi selektovati Non-Microsoft
Sada klikni na Run Scan dugme na toolbar-u.
Kada se završi skeniranje otvoriće se Notepad sa već upisanim logom.
Klikni na Format meni i proveri da Wordwrap nije čekiran. Ako jeste, klikni na njega da ga odčekiraš.

Iskopiraj sada taj tekst iz Notepada u poruku na forumu

Dopuna: 13 Mar 2007 22:50

Zamolio bih te jos i da imas malo strpljenja. Niko od nas nije non-stop za kompom ili da 100% svog vremena ispred kompa provodi bas u Ambulanti.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Savetuju mi da zgazim komp.da li je to preporučljivo?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Zelis li da pokusamo da nastavimo ciscenje ili ne?

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Sve sam uradio po uputstvu više puta ali skeniranje neće da krene.Pojavljuje mi se obaveštenje: Access violation at adress 0047374F in module WinPFind3u.exe. Read of address 00000004.
Izvini zbog nestrpljenja nije mi bila namera vremena imam na pretek.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Vec pocinje da me nervira na koliko kompova nece da radi taj WinPFind...

Uradi sledeće:
Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
U polju za pisanje poruke na forumu klikni desno dugme misa i odaberi opciju Paste.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-03-14 02:26:22
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT a347bus.sys ZwClose
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT a347bus.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT \??\C:\PROGRA~1\Agnitum\OUTPOS~1\kernel\FILTNT.SYS ZwWriteVirtualMemory

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\UAService7.exe[200] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\UAService7.exe[200] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\UAService7.exe[200] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\UAService7.exe[200] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe[956] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 017D200E
.text C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe[956] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 017D1DAF
.text C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe[956] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 017D1CF2
.text C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe[956] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 017D191B
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1084] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 07E4200E
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1084] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 07E41DAF
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1084] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 07E41CF2
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1084] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 07E4191B
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1084] KERNEL32.dll!CreateProcessW 7C802332 5 Bytes JMP 51981D1D C:\PROGRA~1\DVDIDL~1\DVDShell.dll
.text C:\WINDOWS\system32\spoolsv.exe[1164] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\spoolsv.exe[1164] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\spoolsv.exe[1164] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\spoolsv.exe[1164] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1308] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1308] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1308] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1308] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1336] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1336] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1336] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1336] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\ESET\nod32krn.exe[1348] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\ESET\nod32krn.exe[1348] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\ESET\nod32krn.exe[1348] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\ESET\nod32krn.exe[1348] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1372] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 017B200E
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1372] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 017B1DAF
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1372] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 017B1CF2
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1372] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 017B191B
.text C:\WINDOWS\system32\svchost.exe[1436] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[1436] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[1436] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[1436] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\ESET\nod32kui.exe[1524] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00E5200E
.text C:\Program Files\ESET\nod32kui.exe[1524] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00E51DAF
.text C:\Program Files\ESET\nod32kui.exe[1524] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00E51CF2
.text C:\Program Files\ESET\nod32kui.exe[1524] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00E5191B
.text C:\WINDOWS\system32\ati2evxx.exe[1528] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\ati2evxx.exe[1528] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\ati2evxx.exe[1528] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\ati2evxx.exe[1528] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1540] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1540] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1540] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1540] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\LClock\LClock.exe[1568] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A3200E
.text C:\Program Files\LClock\LClock.exe[1568] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A31DAF
.text C:\Program Files\LClock\LClock.exe[1568] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A31CF2
.text C:\Program Files\LClock\LClock.exe[1568] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A3191B
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1644] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D3200E
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1644] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D31DAF
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1644] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D31CF2
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1644] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D3191B
.text C:\Program Files\Styler\Styler.exe[1688] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0131200E
.text C:\Program Files\Styler\Styler.exe[1688] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01311DAF
.text C:\Program Files\Styler\Styler.exe[1688] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01311CF2
.text C:\Program Files\Styler\Styler.exe[1688] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0131191B
.text C:\Program Files\Winamp\winampa.exe[1720] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0093200E
.text C:\Program Files\Winamp\winampa.exe[1720] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00931DAF
.text C:\Program Files\Winamp\winampa.exe[1720] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00931CF2
.text C:\Program Files\Winamp\winampa.exe[1720] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0093191B
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1824] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 091B200E
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1824] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 091B1DAF
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1824] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 091B1CF2
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1824] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 091B191B
.text C:\WINDOWS\system32\xdbtyawi.exe[1860] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0262200E
.text C:\WINDOWS\system32\xdbtyawi.exe[1860] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 02621DAF
.text C:\WINDOWS\system32\xdbtyawi.exe[1860] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 02621CF2
.text C:\WINDOWS\system32\xdbtyawi.exe[1860] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0262191B
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1884] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01E9200E
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1884] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01E91DAF
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1884] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01E91CF2
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1884] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01E9191B
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 022C200E
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 022C1DAF
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 022C1CF2
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 022C191B
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] WS2_32.dll!send 71AB428A 5 Bytes JMP 022C30E6
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 022C32CC
.text C:\Program Files\Mozilla Firefox\firefox.exe[1996] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 022C35BC
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe[2112] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A4200E
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe[2112] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A41DAF
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe[2112] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A41CF2
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe[2112] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A4191B
.text C:\WINDOWS\system32\ctfmon.exe[2200] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A6200E
.text C:\WINDOWS\system32\ctfmon.exe[2200] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A61DAF
.text C:\WINDOWS\system32\ctfmon.exe[2200] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A61CF2
.text C:\WINDOWS\system32\ctfmon.exe[2200] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A6191B
.text D:\Super Utilities\SuperUtil.exe[2240] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text D:\Super Utilities\SuperUtil.exe[2240] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text D:\Super Utilities\SuperUtil.exe[2240] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text D:\Super Utilities\SuperUtil.exe[2240] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2296] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0205200E
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2296] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 02051DAF
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2296] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 02051CF2
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2296] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0205191B
.text C:\Program Files\Free Download Manager\fdm.exe[2320] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D2200E
.text C:\Program Files\Free Download Manager\fdm.exe[2320] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D21DAF
.text C:\Program Files\Free Download Manager\fdm.exe[2320] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D21CF2
.text C:\Program Files\Free Download Manager\fdm.exe[2320] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D2191B
.text D:\Super Utilities\SuperUtil.exe[2340] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0294200E
.text D:\Super Utilities\SuperUtil.exe[2340] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 02941DAF
.text D:\Super Utilities\SuperUtil.exe[2340] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 02941CF2
.text D:\Super Utilities\SuperUtil.exe[2340] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0294191B
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe[2436] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0096200E
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe[2436] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00961DAF
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe[2436] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00961CF2
.text C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe[2436] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0096191B
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[2520] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0162200E
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[2520] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01621DAF
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[2520] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01621CF2
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[2520] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0162191B
.text C:\Documents and Settings\-\Desktop\Gmer\gmer\gmer.exe[2696] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D8200E
.text C:\Documents and Settings\-\Desktop\Gmer\gmer\gmer.exe[2696] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D81DAF
.text C:\Documents and Settings\-\Desktop\Gmer\gmer\gmer.exe[2696] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D81CF2
.text C:\Documents and Settings\-\Desktop\Gmer\gmer\gmer.exe[2696] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D8191B
.text C:\DOCUME~1\-\LOCALS~1\Temp\{6C80483E-B746-4091-AB3F-C65823072A50}\Blaero Start Orb.exe[2824] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 015D200E
.text C:\DOCUME~1\-\LOCALS~1\Temp\{6C80483E-B746-4091-AB3F-C65823072A50}\Blaero Start Orb.exe[2824] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 015D1DAF
.text C:\DOCUME~1\-\LOCALS~1\Temp\{6C80483E-B746-4091-AB3F-C65823072A50}\Blaero Start Orb.exe[2824] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 015D1CF2
.text C:\DOCUME~1\-\LOCALS~1\Temp\{6C80483E-B746-4091-AB3F-C65823072A50}\Blaero Start Orb.exe[2824] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 015D191B
.text C:\WINDOWS\explorer.exe[3176] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00EB200E
.text C:\WINDOWS\explorer.exe[3176] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00EB1DAF
.text C:\WINDOWS\explorer.exe[3176] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00EB1CF2
.text C:\WINDOWS\explorer.exe[3176] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00EB191B
.text C:\WINDOWS\explorer.exe[3176] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 51981D1D C:\PROGRA~1\DVDIDL~1\DVDShell.dll

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82534BD0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 81CFEC00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 82081A38
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82081A38
Device \Driver\nvata \Device\00000072 IRP_MJ_CREATE 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_CREATE_NAMED_PIPE 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_CLOSE 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_READ 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_WRITE 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_QUERY_INFORMATION 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SET_INFORMATION 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_QUERY_EA 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SET_EA 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_FLUSH_BUFFERS 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_QUERY_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SET_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_DIRECTORY_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_FILE_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_INTERNAL_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SHUTDOWN 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_LOCK_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_CLEANUP 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_CREATE_MAILSLOT 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_QUERY_SECURITY 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SET_SECURITY 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_POWER 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_DEVICE_CHANGE 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_QUERY_QUOTA 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_SET_QUOTA 820943F0
Device \Driver\nvata \Device\00000072 IRP_MJ_PNP 820943F0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 823EE638
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 82081A38
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82081A38
Device \Driver\nvata \Device\00000074 IRP_MJ_CREATE 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_CREATE_NAMED_PIPE 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_CLOSE 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_READ 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_WRITE 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_QUERY_INFORMATION 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SET_INFORMATION 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_QUERY_EA 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SET_EA 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_FLUSH_BUFFERS 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_QUERY_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SET_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_DIRECTORY_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_FILE_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_INTERNAL_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SHUTDOWN 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_LOCK_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_CLEANUP 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_CREATE_MAILSLOT 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_QUERY_SECURITY 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SET_SECURITY 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_POWER 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_DEVICE_CHANGE 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_QUERY_QUOTA 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_SET_QUOTA 820943F0
Device \Driver\nvata \Device\00000074 IRP_MJ_PNP 820943F0
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 82257030
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLOSE 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_READ 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_WRITE 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_INFORMATION 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_INFORMATION 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_EA 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_EA 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FILE_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_INTERNAL_DEVICE_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SHUTDOWN 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_LOCK_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLEANUP 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_MAILSLOT 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_SECURITY 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_SECURITY 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_POWER 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SYSTEM_CONTROL 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CHANGE 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_QUOTA 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_QUOTA 820943F0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_PNP 820943F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 82400F10
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CREATE 820943F0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CREATE_NAMED_PIPE 820943F0
Device \Driver\nvata \Device\NvAta1

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Ipak postoji fajl c:\windows\system32\xdbtyawi.exe
Ukoliko koristis Explorer da bi potrazio fajl, lako je moguce da ne mozes da ga nadjes.

Nazalost, moracu da te uputim na skidanje jos jednog programa, koji sluzi za brisanje tih i takvih fajlova.
Program se zove KillBox: http://killbox.net/

Startuj KillBox i u polje za unos teksta unesi sledece:
c:\windows\system32\xdbtyawi.exe

Klikni na crveno dugme sa belim X-om u sredini. To bi trebalo da obrise ovu napast.

Najbolje bi bilo da brisanje KillBox-om odradis odmah nakon startovanja Windowsa jer se ona napast aktivira tek kada ukljucis Internet Explorer ili obican Windows Explore (sto podrazumeva i otvaranje My Computera).

Kada to odradis, napravi novi log programa GMER, ali na sledeci nacin:
Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskopiraj nam ovde sadrzaj ta dva fajla koja smo malopre snimili.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Posle pokušaja brisanja (naravno po uputstvu) Killbox mi izbaci:

This file could not be deleted.
Ne vidim opciju Notepad pa nisam snimio tekst u fajl za slanje (ne znam to da radim).Šaljem sken Gmer-a ovako:

Iz Rootkit-a:
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-03-14 16:15:41
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT a347bus.sys ZwClose
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT a347bus.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT \??\C:\PROGRA~1\Agnitum\OUTPOS~1\kernel\FILTNT.SYS ZwWriteVirtualMemory

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\UAService7.exe[240] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\UAService7.exe[240] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\UAService7.exe[240] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\UAService7.exe[240] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\csrss.exe[568] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\services.exe[640] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\ati2evxx.exe[796] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[812] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[940] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\spoolsv.exe[1160] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\spoolsv.exe[1160] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\spoolsv.exe[1160] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\spoolsv.exe[1160] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1292] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1292] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1292] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1292] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1340] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1340] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1340] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\CDBurnerXP\NMSAccess.exe[1340] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\ESET\nod32krn.exe[1352] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\ESET\nod32krn.exe[1352] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\ESET\nod32krn.exe[1352] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\ESET\nod32krn.exe[1352] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1376] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00F7200E
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1376] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00F71DAF
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1376] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00F71CF2
.text C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe[1376] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00F7191B
.text C:\WINDOWS\system32\ati2evxx.exe[1484] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\ati2evxx.exe[1484] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\ati2evxx.exe[1484] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\ati2evxx.exe[1484] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1676] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 07E2200E
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1676] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 07E21DAF
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1676] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 07E21CF2
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1676] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 07E2191B
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe[1676] KERNEL32.dll!CreateProcessW 7C802332 5 Bytes JMP 51981D1D C:\PROGRA~1\DVDIDL~1\DVDShell.dll
.text C:\WINDOWS\explorer.exe[1716] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01F4200E
.text C:\WINDOWS\explorer.exe[1716] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01F41DAF
.text C:\WINDOWS\explorer.exe[1716] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01F41CF2
.text C:\WINDOWS\explorer.exe[1716] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01F4191B
.text C:\WINDOWS\explorer.exe[1716] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 51981D1D C:\PROGRA~1\DVDIDL~1\DVDShell.dll
.text C:\Program Files\ESET\nod32kui.exe[1728] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A7200E
.text C:\Program Files\ESET\nod32kui.exe[1728] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A71DAF
.text C:\Program Files\ESET\nod32kui.exe[1728] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A71CF2
.text C:\Program Files\ESET\nod32kui.exe[1728] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A7191B
.text C:\Program Files\LClock\LClock.exe[1752] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 009B200E
.text C:\Program Files\LClock\LClock.exe[1752] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 009B1DAF
.text C:\Program Files\LClock\LClock.exe[1752] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009B1CF2
.text C:\Program Files\LClock\LClock.exe[1752] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009B191B
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1844] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1844] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1844] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1844] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1864] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A8200E
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1864] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A81DAF
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1864] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A81CF2
.text C:\Program Files\VisualTooltip\VisualToolTip.exe[1864] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A8191B
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1904] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 091B200E
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1904] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 091B1DAF
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1904] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 091B1CF2
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe[1904] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 091B191B
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1948] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01E9200E
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1948] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01E91DAF
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1948] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01E91CF2
.text C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe[1948] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01E9191B
.text C:\Program Files\Styler\Styler.exe[2136] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00AC200E
.text C:\Program Files\Styler\Styler.exe[2136] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00AC1DAF
.text C:\Program Files\Styler\Styler.exe[2136] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00AC1CF2
.text C:\Program Files\Styler\Styler.exe[2136] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00AC191B
.text C:\Program Files\Winamp\winampa.exe[2196] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0086200E
.text C:\Program Files\Winamp\winampa.exe[2196] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00861DAF
.text C:\Program Files\Winamp\winampa.exe[2196] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00861CF2
.text C:\Program Files\Winamp\winampa.exe[2196] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0086191B
.text C:\WINDOWS\system32\xdbtyawi.exe[2316] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 02B0200E
.text C:\WINDOWS\system32\xdbtyawi.exe[2316] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 02B01DAF
.text C:\WINDOWS\system32\xdbtyawi.exe[2316] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 02B01CF2
.text C:\WINDOWS\system32\xdbtyawi.exe[2316] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 02B0191B
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0255200E
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 02551DAF
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 02551CF2
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0255191B
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] WS2_32.dll!send 71AB428A 5 Bytes JMP 025530E6
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 025532CC
.text C:\Program Files\Mozilla Firefox\firefox.exe[2324] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 025535BC
.text C:\WINDOWS\system32\ctfmon.exe[2416] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A2200E
.text C:\WINDOWS\system32\ctfmon.exe[2416] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A21DAF
.text C:\WINDOWS\system32\ctfmon.exe[2416] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A21CF2
.text C:\WINDOWS\system32\ctfmon.exe[2416] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A2191B
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2816] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 022C200E
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2816] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 022C1DAF
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2816] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 022C1CF2
.text C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe[2816] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 022C191B
.text C:\Program Files\Free Download Manager\fdm.exe[2944] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01E9200E
.text C:\Program Files\Free Download Manager\fdm.exe[2944] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01E91DAF
.text C:\Program Files\Free Download Manager\fdm.exe[2944] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01E91CF2
.text C:\Program Files\Free Download Manager\fdm.exe[2944] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01E9191B
.text D:\Programs from MyCity for Viruses\GMER 1.0.12\gmer.exe[3004] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0100200E
.text D:\Programs from MyCity for Viruses\GMER 1.0.12\gmer.exe[3004] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01001DAF
.text D:\Programs from MyCity for Viruses\GMER 1.0.12\gmer.exe[3004] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01001CF2
.text D:\Programs from MyCity for Viruses\GMER 1.0.12\gmer.exe[3004] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0100191B
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[3024] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01B5200E
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[3024] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01B51DAF
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[3024] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01B51CF2
.text C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe[3024] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01B5191B
.text C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe[3064] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00E2200E
.text C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe[3064] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00E21DAF
.text C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe[3064] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00E21CF2
.text C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe[3064] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00E2191B

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8256A810
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 821D9F00
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 821D9F00
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 82152370
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 821D9F00
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 821D9F00
Device \Driver\nvata \Device\00000076 IRP_MJ_CREATE 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_CREATE_NAMED_PIPE 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_CLOSE 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_READ 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_WRITE 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_QUERY_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SET_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_QUERY_EA 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SET_EA 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_FLUSH_BUFFERS 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_QUERY_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SET_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_DIRECTORY_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_FILE_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_INTERNAL_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SHUTDOWN 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_LOCK_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_CLEANUP 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_CREATE_MAILSLOT 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_QUERY_SECURITY 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SET_SECURITY 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_POWER 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_DEVICE_CHANGE 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_QUERY_QUOTA 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_SET_QUOTA 823F35A0
Device \Driver\nvata \Device\00000076 IRP_MJ_PNP 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_CREATE 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_CREATE_NAMED_PIPE 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_CLOSE 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_READ 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_WRITE 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_QUERY_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SET_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_QUERY_EA 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SET_EA 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_FLUSH_BUFFERS 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_QUERY_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SET_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_DIRECTORY_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_FILE_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_INTERNAL_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SHUTDOWN 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_LOCK_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_CLEANUP 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_CREATE_MAILSLOT 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_QUERY_SECURITY 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SET_SECURITY 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_POWER 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_DEVICE_CHANGE 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_QUERY_QUOTA 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_SET_QUOTA 823F35A0
Device \Driver\nvata \Device\00000078 IRP_MJ_PNP 823F35A0
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 82297E40
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLOSE 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_READ 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_WRITE 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_EA 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_EA 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FILE_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_INTERNAL_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SHUTDOWN 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_LOCK_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLEANUP 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_MAILSLOT 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_SECURITY 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_SECURITY 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_POWER 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CHANGE 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_QUOTA 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_QUOTA 823F35A0
Device \Driver\nvata \Device\NvAta0 IRP_MJ_PNP 823F35A0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 82122498
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CREATE 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CREATE_NAMED_PIPE 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CLOSE 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_READ 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_WRITE 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_QUERY_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SET_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_QUERY_EA 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SET_EA 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_FLUSH_BUFFERS 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_QUERY_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SET_VOLUME_INFORMATION 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_DIRECTORY_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_FILE_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_INTERNAL_DEVICE_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SHUTDOWN 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_LOCK_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CLEANUP 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_CREATE_MAILSLOT 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_QUERY_SECURITY 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SET_SECURITY 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_POWER 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SYSTEM_CONTROL 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_DEVICE_CHANGE 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_QUERY_QUOTA 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_SET_QUOTA 823F35A0
Device \Driver\nvata \Device\NvAta1 IRP_MJ_PNP 823F35A0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ

Ko je trenutno na forumu
 

Ukupno su 1080 korisnika na forumu :: 55 registrovanih, 4 sakrivenih i 1021 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, A.R.Chafee.Jr., atmel, Atomski čoban, babaroga, Bobrock1, bokisha253, Buzdovan, cavatina, darkojbn, Dimitrise93, doklevise, dragoljub11987, FOX, goxin, HrcAk47, Ilija Cvorovic, ivica976, JimmyNapoli, Karla, Koridor, krkalon, Leonov, Lošmi, Magistar78, mikki jons, mikrimaus, Milos ZA, Ne doznajem se u oružje, Nobunaga, nuke92, Oscar, ozzy, panzerwaffe, Parker, procesor, raketaš, repac, RJ, robert1979, Rogan33, royst33, ruger357, sasa76, savaskytec, slonic_tonic, Smiljke, Srki94, Sumadija34, tubular, wolverined4, YugoSlav, zdrebac, zziko, 79693