Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-03-13 15:28:01
Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Seagate_ rev.TD27 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Daniel\AppData\Local\Temp\uxlirpod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075191401 2 bytes JMP 76ceeb26 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075191419 2 bytes JMP 76cfb513 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075191431 2 bytes JMP 76d78609 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007519144a 2 bytes CALL 76cd1dfa C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000751914dd 2 bytes JMP 76d77efe C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000751914f5 2 bytes JMP 76d780d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007519150d 2 bytes JMP 76d77df4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075191525 2 bytes JMP 76d781c2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007519153d 2 bytes JMP 76cef088 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075191555 2 bytes JMP 76cfb885 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007519156d 2 bytes JMP 76d786c1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075191585 2 bytes JMP 76d78222 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007519159d 2 bytes JMP 76d77db8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000751915b5 2 bytes JMP 76cef121 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000751915cd 2 bytes JMP 76cfb29f C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000751916b2 2 bytes JMP 76d78584 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[4440] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000751916bd 2 bytes JMP 76d77d4d C:\Windows\syswow64\kernel32.dll
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 0000000076ceeb26 5 bytes JMP 000000016ee31dc0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076cef18b 7 bytes JMP 000000016ee31eb0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076d78584 7 bytes JMP 000000016ee31db0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076d78609 5 bytes JMP 000000016ee31ea0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076d7895f 5 bytes JMP 000000016ee31e30
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076991094 5 bytes JMP 000000016ee324b0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076991142 5 bytes JMP 000000016ee32510
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076991bb2 5 bytes JMP 000000016ee32580
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076991d92 5 bytes JMP 000000016ee326d0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760be84e 5 bytes JMP 000000016ee31aa0
.text C:\Users\Daniel\Downloads\Gmer-19357.exe[1044] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be86e 5 bytes JMP 000000016ee31a10
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ???tte??????????? ??????????????????LocalSystem?????? ?????????????????????????????????????????????4?,??`???H?T??????4???????????????????? ?????????????????????????????????????????0????????????????t?????????? ????????????????????? ????????????????????????????????????????????????????n????Der Mozilla Maintenance Service stellt sicher, dass die neueste und sicherste Version von Mozilla Firefox auf Ihrem Computer installiert ist. Denn Firefox auf dem aktuellen Stand zu halten, ist sehr wichtig f?r Ihre Sicherheit online und Mozilla empfiehlt mit Nachdruck, dass Sie den Dienst aktiviert lassen.?????????????????????????????????.????????????????????????P????????????????????e????????????? ?;? ?4?:?:?}?}?}??????? ???????????????????o???????? ?????????????d:\c9c2b72fc6926dabd8ca\DW\DW20.exe?Microsoft Shared\DW\DW20.exe????(????????B???????????B???????????????B?????????B?B???????????B?B?????B?????????B?B?????????????????B???????B?0???????B???0?0?????B?????????B???0?0???B???0?????0?0???????B?????????????B???B???????????
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c8093613e37
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c8093613e37 (not active ControlSet)
---- EOF - GMER 2.1 ----