Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-05-06 23:40:20
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003b ST500LM012_HN-M500MBB rev.2AR10002 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Butzi\AppData\Local\Temp\uxlorpog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlX64.exe[952] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlX64.exe[952] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
.text C:\Windows\system32\atiesrxx.exe[988] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\Windows\system32\atiesrxx.exe[988] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
.text C:\Windows\system32\atieclxx.exe[1084] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\Windows\system32\atieclxx.exe[1084] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
.text C:\Windows\system32\atieclxx.exe[1084] C:\Windows\system32\WSOCK32.dll!recvfrom + 742 000007fbb07e1b32 4 bytes [7E, B0, FB, 07]
.text C:\Windows\system32\atieclxx.exe[1084] C:\Windows\system32\WSOCK32.dll!recvfrom + 750 000007fbb07e1b3a 4 bytes [7E, B0, FB, 07]
.text C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe[2616] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe[2616] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
.text C:\Windows\Explorer.EXE[3076] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fbae301532 4 bytes [30, AE, FB, 07]
.text C:\Windows\Explorer.EXE[3076] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fbae30153a 4 bytes [30, AE, FB, 07]
.text C:\Windows\Explorer.EXE[3076] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fbae30165a 4 bytes [30, AE, FB, 07]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1656] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fbae301532 4 bytes [30, AE, FB, 07]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1656] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fbae30153a 4 bytes [30, AE, FB, 07]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1656] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fbae30165a 4 bytes [30, AE, FB, 07]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1656] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fbb07e1b32 4 bytes [7E, B0, FB, 07]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1656] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fbb07e1b3a 4 bytes [7E, B0, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3180] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fbae301532 4 bytes [30, AE, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3180] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fbae30153a 4 bytes [30, AE, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3180] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fbae30165a 4 bytes [30, AE, FB, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4116] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4116] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4628] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbb5c7177a 4 bytes [C7, B5, FB, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4628] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbb5c71782 4 bytes [C7, B5, FB, 07]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [632:656] fffff960009bc5e8
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----