Erstmal das Log von GMER
GMER Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-08-16 13:16:00
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6 Hitachi_HDT721010SLA360 rev.ST6OA31B
Running: h4l6tffw.exe; Driver: C:\DOKUME~1\Admin\LOKALE~1\Temp\ufkdqfow.sys
---- System - GMER 1.0.15 ----
SSDT BA6C01A4 ZwClose
SSDT BA6C015E ZwCreateKey
SSDT BA6C01AE ZwCreateSection
SSDT BA6C0154 ZwCreateThread
SSDT BA6C0163 ZwDeleteKey
SSDT BA6C016D ZwDeleteValueKey
SSDT BA6C019F ZwDuplicateObject
SSDT BA6C018B ZwLoadDriver
SSDT BA6C0172 ZwLoadKey
SSDT BA6C0140 ZwOpenProcess
SSDT BA6C0145 ZwOpenThread
SSDT BA6C017C ZwReplaceKey
SSDT BA6C0177 ZwRestoreKey
SSDT BA6C01B3 ZwSetContextThread
SSDT BA6C0190 ZwSetSystemInformation
SSDT BA6C0168 ZwSetValueKey
SSDT BA6C014F ZwTerminateProcess
SSDT BA6C014A ZwWriteVirtualMemory
Code \??\C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8572380, 0x35F8DD, 0xE8000020]
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. !
? C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. !
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \Driver\Tcpip \Device\Tcp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \Driver\Tcpip \Device\Udp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \Driver\Tcpip \Device\RawIp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
---- EOF - GMER 1.0.15 ----
--- --- ---