Gmer logfile Teil 1:
Code:
Alles auswählen Aufklappen ATTFilter
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-09 22:00:47
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
INT 0x62 ? 89E45BF8
INT 0x82 ? 89E45BF8
INT 0x84 ? 89C98E90
INT 0x94 ? 89C98E90
INT 0xA4 ? 89C98E90
---- Kernel code sections - GMER 1.0.15 ----
? spgu.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload BA13862C 5 Bytes JMP 89C98470
.text aqbja81v.SYS BA087384 1 Byte [20]
.text aqbja81v.SYS BA087384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text aqbja81v.SYS BA0873AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text aqbja81v.SYS BA0873C4 3 Bytes [00, 00, 00]
.text aqbja81v.SYS BA0873C9 1 Byte [00]
.text ...
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\igfxsrvc.exe[136] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\igfxsrvc.exe[136] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 01110001
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe[244] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\IoctlSvc.exe[272] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\Programme\Intel\Wireless\Bin\RegSrvc.exe[276] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text c:\xampp\apache\bin\apache.exe[392] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\svchost.exe[400] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\wdfmgr.exe[452] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\hkcmd.exe[676] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\hkcmd.exe[676] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 00FF0001
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\igfxpers.exe[684] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\igfxpers.exe[684] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 00F70001
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\WINDOWS\system32\WLTRAY.exe[692] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\WINDOWS\system32\WLTRAY.exe[692] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 01040001
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!htons 71A12B66 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!connect 71A1406A 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!WSAEventSelect 71A14573 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!WSAGetLastError + 2 71A194DE 4 Bytes [1E, 00, 0B, 5F] {PUSH DS; ADD [EBX], CL; POP EDI}
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!closesocket 71A19639 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!WSAAsyncSelect 71A20979 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!WSAConnect 71A20C69 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!WSAAccept 71A20DA9 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\WLTRAY.exe[692] WS2_32.dll!accept 71A21028 6 Bytes JMP 5F100F5A
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\Programme\Java\jre6\bin\jqs.exe[696] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\xampp\mysql\bin\mysqld-nt.exe[732] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 01990001
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!htons 71A12B66 6 Bytes JMP 5F040F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!connect 71A1406A 6 Bytes JMP 5F130F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!WSAEventSelect 71A14573 6 Bytes JMP 5F1F0F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!WSAGetLastError + 2 71A194DE 4 Bytes [1E, 00, 0B, 5F] {PUSH DS; ADD [EBX], CL; POP EDI}
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!closesocket 71A19639 6 Bytes JMP 5F0D0F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!WSAAsyncSelect 71A20979 6 Bytes JMP 5F1C0F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!WSAConnect 71A20C69 6 Bytes JMP 5F190F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!WSAAccept 71A20DA9 6 Bytes JMP 5F160F5A
.text C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe[744] WS2_32.dll!accept 71A21028 6 Bytes JMP 5F100F5A
.text C:\windows\pp10.exe[812] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FFA484E
.text C:\windows\pp10.exe[812] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FFA48DD
.text C:\windows\pp10.exe[812] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FFA48EA
.text C:\windows\pp10.exe[812] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FFA4B6E
.text C:\windows\pp10.exe[812] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FFA48D3
.text C:\windows\pp10.exe[812] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FFA492B
.text C:\windows\pp10.exe[812] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 003E0001
.text C:\windows\pp10.exe[812] ws2_32.dll!htons 71A12B66 6 Bytes JMP 5F0A0F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!connect 71A1406A 6 Bytes JMP 5F160F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!WSAEventSelect 71A14573 6 Bytes JMP 5F1F0F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!WSAGetLastError + 2 71A194DE 4 Bytes [1E, 00, 0E, 5F] {PUSH DS; ADD [ESI], CL; POP EDI}
.text C:\windows\pp10.exe[812] ws2_32.dll!closesocket 71A19639 6 Bytes JMP 5F100F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!WSAAsyncSelect 71A20979 6 Bytes JMP 5F070F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!WSAConnect 71A20C69 6 Bytes JMP 5F1C0F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!WSAAccept 71A20DA9 6 Bytes JMP 5F190F5A
.text C:\windows\pp10.exe[812] ws2_32.dll!accept 71A21028 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FF9484E
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FF948DD
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FF948EA
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FF94B6E
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FF948D3
.text C:\WINDOWS\system32\winlogon.exe[864] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FF9492B
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FF9484E
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FF948DD
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FF948EA
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FF94B6E
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FF948D3
.text C:\WINDOWS\system32\services.exe[908] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FF9492B
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtCreateFile 7C91D682 5 Bytes CALL 7FF9484E
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtCreateProcess 7C91D754 5 Bytes CALL 7FF948DD
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtCreateProcessEx 7C91D769 5 Bytes CALL 7FF948EA
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtDeviceIoControlFile 7C91D8E3 5 Bytes CALL 7FF94B6E
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtOpenFile 7C91DCFD 5 Bytes CALL 7FF948D3
.text C:\WINDOWS\system32\lsass.exe[920] ntdll.dll!NtQueryInformationProcess 7C91E01B 5 Bytes CALL 7FF9492B