Leon87
10-01-2007, 18:53
ho fatto una scansione con GMER e nella tabella Rootkit c'è questo:
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-10 19:48:48
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\Programmi\Agnitum\Outpost Firewall\kernel\Sandbox.SYS ZwQueryDirectoryFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823641D8
---- Threads - GMER 1.0.12 ----
Thread 4:168 82104A20
Thread 4:172 820E2C60
Thread 4:176 820E2C60
Thread 4:420 82104A20
---- EOF - GMER 1.0.12 ----
c'è o non c'è ??? :mbe:
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-10 19:48:48
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\Programmi\Agnitum\Outpost Firewall\kernel\Sandbox.SYS ZwQueryDirectoryFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823641D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823641D8
---- Threads - GMER 1.0.12 ----
Thread 4:168 82104A20
Thread 4:172 820E2C60
Thread 4:176 820E2C60
Thread 4:420 82104A20
---- EOF - GMER 1.0.12 ----
c'è o non c'è ??? :mbe: