Citat:
Ursprungligen postat av
.Chloe
Kan du ge mer information om SSDT-hooken? Printscreen eller bara mer info hade hjälpt. Alltså ifrån GMER.
GMER 2.1.19357 -
http://www.gmer.net
Rootkit quick scan 2015-01-11 16:31:38
Windows 6.0.6000 \Device\Harddisk0\DR0 -> \Device\0000005b SAMSUNG_ rev.CP10 298,09GB
Running: t1d4zsrh.exe; Driver: C:\Users\BERG~1\AppData\Local\Temp\fwddqpob.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys
---- Processes - GMER 2.1 ----
Process (*** hidden *** ) [4] 840E0908
---- EOF - GMER 2.1 ----