
Bardzo proszę Was o pomoc w sprawdzeniu moich logów czy mam jakieś programy szpiegowskie. To są moje logi . Z góry bardzo dziękuję
- Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-27 00:09:13
Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-1f ST3500418AS rev.CC37 465,76GB
Running: gmer.exe; Driver: C:\DOCUME~1\Darek\USTAWI~1\Temp\awxyypod.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwAssignProcessToJobObject [0xAE1B6C40]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwCreateThread [0xAE1B6F80]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDebugActiveProcess [0xAE1B7240]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwDuplicateObject [0xAE1B6D60]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwLoadDriver [0xAE1B7040]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenProcess [0xAE1B6AE0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwOpenThread [0xAE1B6BA0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwProtectVirtualMemory [0xAE1B6D00]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwQueueApcThread [0xAE1B6DC0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetContextThread [0xAE1B6CC0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetInformationThread [0xAE1B6C80]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSecurityObject [0xAE1B6E00]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSystemInformation [0xAE1B7000]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendProcess [0xAE1B6B40]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSuspendThread [0xAE1B6BC0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSystemDebugControl [0xAE1B6FC0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateProcess [0xAE1B6B00]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwTerminateThread [0xAE1B6C00]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwWriteVirtualMemory [0xAE1B6D80]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 307C 80504964 12 Bytes [40, 6B, 1B, AE, C0, 6B, 1B, ...] {INC EAX; IMUL EBX, [EBX], -0x52; SHR BYTE [EBX+0x1b], 0xae; SHR BYTE [EDI+0x1b], 0xae}
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6254000, 0x1E2E7A, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[580] kernel32.dll!SetUnhandledExceptionFilter 7C844EE5 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 2.1 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys
---- Threads - GMER 2.1 ----
Thread System [4:1320] 89F70E70
---- EOF - GMER 2.1 ----