вторник, 17 апреля 2012 г.

Simda.gen!A

wincheck -ndis said:

OpenBlock [1] 8AB7D868
RootName: \DEVICE\{ABEB65C6-0636-48CF-81DC-4C0282FB061A}
BindName: \DEVICE\{ABEB65C6-0636-48CF-81DC-4C0282FB061A}
Flags:    1
SendHandler:                 8A7A74F0 UNKNOWN
WanSendHandler:              8A1A0398 UNKNOWN
TransferDataHandler:         8A3259E0 UNKNOWN
SendCompleteHandler:         8A1BA3C0 UNKNOWN
TransferDataCompleteHandler: 8A2B4458 UNKNOWN
ReceiveHandler:              A8B68AC6 \SystemRoot\system32\DRIVERS\ndisuio.sys
ReceiveCompleteHandler:      00000000
WanReceiveHandler:           A8B689A6 \SystemRoot\system32\DRIVERS\ndisuio.sys
RequestCompleteHandler:      8A672880 UNKNOWN
ReceivePacketHandler:        8A331340 UNKNOWN
SendPacketsHandler:          B9E20B65 NDIS.sys
ResetHandler:                B9E1D8C7 NDIS.sys
RequestHandler:              A8B6899E \SystemRoot\system32\DRIVERS\ndisuio.sys
ResetCompleteHandler:        A8B689C8 \SystemRoot\system32\DRIVERS\ndisuio.sys
StatusHandler:               A8B68AC6 \SystemRoot\system32\DRIVERS\ndisuio.sys
StatusCompleteHandler:       00000000

on 7 of 19 OpenBlocks.

Btw MS Forefront was unable to cure infected machine - it just completely removed acpi.sys and windows didn`t boot anymore, he-he

Комментариев нет:

Отправить комментарий