|
|
|
Poslao: 07 Jun 2007 23:01
|
|
|
cini mi se da je log cist aj da probamo sa GMER-om
Skeniraj komp sa GMER-om i postavi log da proverimo da nema nekih rootkitova...
Uradi sledeće:
Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.
Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
U polju za pisanje poruke na forumu klikni desno dugme misa i odaberi opciju Paste.
|
|
|
|
|
|
|
Poslao: 07 Jun 2007 23:52
|
offline
- mrkavac

- Elitni građanin
- Pridružio: 19 Jul 2005
- Poruke: 1783
|
GMER 1.0.12.12244 - [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-06-07 23:55:57
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwClose
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcessEx
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey
SSDT kl1.sys ZwOpenFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetSecurityObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!KiDispatchInterrupt + BA 804DB92E 7 Bytes JMP BAE4DCD0 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntoskrnl.exe!IoIsOperationSynchronous 804E8752 5 Bytes JMP BAE4AC50 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 804FBE09 5 Bytes JMP BAE4A760 \??\C:\WINDOWS\system32\drivers\klif.sys
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F7C227AE 5 Bytes JMP 82ABB1B8
? System32\Drivers\athjyzu7.SYS The system cannot find the file specified.
? C:\WINDOWS\system32\DRIVERS\update.sys
---- User code sections - GMER 1.0.12 ----
.text C:\WINDOWS\explorer.exe[2020] RPCRT4.dll!NdrComplexArrayMemorySize + AC 77E89980 4 Bytes [ 62, 0B, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!StrStrW + FFE2DA6E 7C9C8920 4 Bytes [ D2, 04, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!StrStrW + FFE2DAE6 7C9C8998 4 Bytes [ FC, 04, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!StrStrW + FFE33B46 7C9CE9F8 4 Bytes [ 04, 03, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!StrStrW + FFE33B56 7C9CEA08 4 Bytes [ 00, 04, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!StrStrW + FFE34A96 7C9CF948 4 Bytes [ 54, 04, FF, 00 ]
.text ...
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!ILLoadFromStream + 397 7CA0617C 4 Bytes [ E0, 0B, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!ILLoadFromStream + 54F 7CA06334 4 Bytes [ 50, 05, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!ILLoadFromStream + 65F 7CA06444 4 Bytes [ 26, 05, FF, 00 ]
.text C:\WINDOWS\explorer.exe[2020] SHELL32.dll!DAD_ShowDragImage + 2370 7CA09E68 4 Bytes [ 22, 06, FF, 00 ]
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!SetScrollInfo 77D49056 7 Bytes JMP 01ADB7C6 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!GetScrollInfo 77D517F8 7 Bytes JMP 01ADB74E C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!ShowScrollBar 77D5F2CA 5 Bytes JMP 01ADB84A C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!GetScrollPos 77D5F6DC 5 Bytes JMP 01ADB776 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!SetScrollPos 77D5F728 5 Bytes JMP 01ADB7F1 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!GetScrollRange 77D5F75F 5 Bytes JMP 01ADB79B C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!SetScrollRange 77D5F973 5 Bytes JMP 01ADB81C C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2540] USER32.dll!EnableScrollBar 77D97BC5 7 Bytes JMP 01ADB726 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!LoadResource 7C809FB5 7 Bytes JMP 27001B70 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceExW 7C80AC88 7 Bytes JMP 27001AE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceW 7C80BBCE 7 Bytes JMP 27001A60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!SizeofResource 7C80BC69 7 Bytes JMP 27001C20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!LockResource 7C80CC97 5 Bytes JMP 27001CD0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!CreateEventA 7C8307DD 5 Bytes JMP 27001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] kernel32.dll!SetUnhandledExceptionFilter 7C8447B5 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\msnmsgr.exe
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] ADVAPI32.dll!CryptDeriveKey 77DEA685 7 Bytes JMP 27001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] ADVAPI32.dll!CryptDecrypt 77DEA7B1 2 Bytes JMP 27001050 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] ADVAPI32.dll!CryptDecrypt + 3 77DEA7B4 4 Bytes [ 21, AF, CC, CC ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!PeekMessageW 77D4929B 5 Bytes JMP 27003A20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!CreateWindowExW 77D4FF50 5 Bytes JMP 27003330 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!SetWindowRgn 77D502DD 7 Bytes JMP 27004D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!CreateDialogParamW 77D584EE 5 Bytes JMP 27004E20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!SetWindowPlacement 77D5DF46 5 Bytes JMP 27004CA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!MessageBoxIndirectW 77D96093 5 Bytes JMP 27004F80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] USER32.dll!TrackPopupMenuEx 77D9CB1A 5 Bytes JMP 270041F0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WS2_32.dll!send 71AB428A 5 Bytes JMP 27009150 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 27008F40 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WS2_32.dll!recv 71AB615A 5 Bytes JMP 27008DB0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 270092D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 270094E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] SHELL32.dll!Shell_NotifyIconW 7CA21B5A 5 Bytes JMP 27002B10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] ole32.dll!CoInitializeEx 774FEF7B 5 Bytes JMP 27001D30 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] ole32.dll!CoRegisterClassObject 77517EB8 5 Bytes JMP 27001E30 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WININET.dll!HttpOpenRequestA 771C2B19 5 Bytes JMP 27007D00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WININET.dll!InternetCloseHandle 771C4DAC 5 Bytes JMP 27007FE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WININET.dll!HttpSendRequestA 771C6209 5 Bytes JMP 27007F30 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2856] WININET.dll!InternetReadFile 771C812C 5 Bytes JMP 27007E60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82FD61D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82FD61D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_CREATE 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_CLOSE 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_DEVICE_CONTROL 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_INTERNAL_DEVICE_CONTROL 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_CLEANUP 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{97399CBD-8351-4C7A-9D14-2976D459B3C2} IRP_MJ_PNP 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_CREATE 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_CLOSE 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_DEVICE_CONTROL 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_INTERNAL_DEVICE_CONTROL 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_CLEANUP 82C4D6F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5F5F46E6-02FB-46B3-990A-0AA90003246D} IRP_MJ_PNP 82C4D6F0
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 82D8D1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 82D8D1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 82F6A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL
|
|
|
|
|
|
|
Poslao: 07 Jun 2007 23:56
|
offline
- mrkavac

- Elitni građanin
- Pridružio: 19 Jul 2005
- Poruke: 1783
|
Koliko vidim nije sve prekopirao u post-u
Ovaj text mi izgleda drugacije pa eto ga ispod ako zatreba.
[Link mogu videti samo ulogovani korisnici]
|
|
|
|
|
|
|
Poslao: 08 Jun 2007 00:25
|
|
|
ovaj fajl mi je sumnjim:
athjyzu7.SYS
ukljuci prikaz skrivenih fajlova i foldera i probaj da ga nadjes, trebalo bi da se nalazi:
WINDOWS\system32\drivers\athjyzu7.SYS
ako ga nadjes upoaduj ga ovde: [Link mogu videti samo ulogovani korisnici]
|
|
|
|
|
|
|
|
|
Poslao: 08 Jun 2007 00:57
|
|
|
i u logu pise da fajl ne postoji tj da ne moze da ga nadje ali sam hteo da proverim.
Ostalo deluje cisto, mozes jos odraditi:
Bitdefender online scan - [Link mogu videti samo ulogovani korisnici]
- potreban je da Internet Explorer sa ukljucenim ActiveX
- iskopiraj nam ovde sadrzaj log fajla
ili
Ewido micro - [Link mogu videti samo ulogovani korisnici] (oko 8mb za skidanje):
- na prvom ekranu odaberi sve particije (štikliraj polja ispred njih)
- klikni na dugme Start Scan
- nakon završenog skeniranja klikni na Save Report i snimi log fajl na sigurno mesto
- klikni na Remove Infections
- iskopiraj nam ovde sadrzaj log fajla
|
|
|
|
|
|
|
|
|
|
|
|