Das kam bei
GMER heraus:
Code:
Alles auswählen Aufklappen ATTFilter
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-15 23:00:43
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT BAFA977E ZwCreateKey
SSDT BAFA9774 ZwCreateThread
SSDT BAFA9783 ZwDeleteKey
SSDT BAFA978D ZwDeleteValueKey
SSDT sprs.sys ZwEnumerateKey [0xBA6C6CA2]
SSDT sprs.sys ZwEnumerateValueKey [0xBA6C7030]
SSDT BAFA9792 ZwLoadKey
SSDT sprs.sys ZwOpenKey [0xBA6A80C0]
SSDT BAFA9760 ZwOpenProcess
SSDT BAFA9765 ZwOpenThread
SSDT sprs.sys ZwQueryKey [0xBA6C7108]
SSDT sprs.sys ZwQueryValueKey [0xBA6C6F88]
SSDT BAFA979C ZwReplaceKey
SSDT BAFA9797 ZwRestoreKey
SSDT BAFA9788 ZwSetValueKey
SSDT BAFA976F ZwTerminateProcess
INT 0x62 ? 8A613BF8
INT 0x63 ? 8A613BF8
INT 0x63 ? 8A613BF8
INT 0x63 ? 8A306BF8
INT 0x73 ? 8A5A5BF8
INT 0x73 ? 8A5A5BF8
INT 0x83 ? 8A306BF8
INT 0xA4 ? 8A306BF8
INT 0xB4 ? 8A306BF8
Code 8A0B8FD8 ZwFlushInstructionCache
Code 8A0B8E26 IofCallDriver
Code 88A32386 IofCompleteRequest
Code 8A0B90B5 ZwSaveKey
Code 8A0B918D ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 8A0B8E2B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 88A3238B
.text ntkrnlpa.exe!ZwSaveKey 80500D68 5 Bytes JMP 8A0B90BA
.text ntkrnlpa.exe!ZwSaveKeyEx 80500D7C 5 Bytes JMP 8A0B9192
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8A0B8FDC
? sprs.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload B9A388AC 5 Bytes JMP 8A3061D8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A9040] sprs.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A913C] sprs.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A90BE] sprs.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A97FC] sprs.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A96D2] sprs.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A5A11F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{2833BB1A-0A93-49A6-A6B6-03EA4ACA14FF} 8A37B500
Device \Driver\usbuhci \Device\USBPDO-0 8A304500
Device \Driver\usbuhci \Device\USBPDO-1 8A304500
Device \Driver\usbuhci \Device\USBPDO-2 8A304500
Device \Driver\usbuhci \Device\USBPDO-3 8A304500
Device \Driver\NetBT \Device\NetBT_Tcpip_{3ABE492C-1F38-465D-BD23-F6074506C18A} 8A37B500
Device \Driver\usbehci \Device\USBPDO-4 8A323500
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A5A31F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A5A31F8
Device \Driver\Cdrom \Device\CdRom1 8A258430
Device \Driver\usbstor \Device\00000080 8A0CC1F8
Device \Driver\usbstor \Device\00000081 8A0CC1F8
Device \Driver\usbstor \Device\00000082 8A0CC1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A37B500
Device \Driver\PCI_PNP8880 \Device\0000004b sprs.sys
Device \Driver\NetBT \Device\NetbiosSmb 8A37B500
Device \Driver\usbuhci \Device\USBFDO-0 8A304500
Device \Driver\usbuhci \Device\USBFDO-1 8A304500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89F78500
Device \Driver\usbstor \Device\0000007b 8A0CC1F8
Device \Driver\usbuhci \Device\USBFDO-2 8A304500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89F78500
Device \Driver\usbuhci \Device\USBFDO-3 8A304500
Device \Driver\usbehci \Device\USBFDO-4 8A323500
Device \Driver\Ftdisk \Device\FtControl 8A5A31F8
Device \Driver\usbstor \Device\0000007f 8A0CC1F8
Device \Driver\sptd \Device\2065586380 sprs.sys
Device \Driver\agvko7uw \Device\Scsi\agvko7uw1Port5Path0Target0Lun0 8A2401F8
Device \Driver\agvko7uw \Device\Scsi\agvko7uw1 8A2401F8
Device \Driver\JRAID \Device\Scsi\JRAID1 8A5A21F8
Device \FileSystem\Cdfs \Cdfs 8A0CB1F8
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@oaekjkbfbepihimmfanddhhpkpmmmg 0x64 0x61 0x64 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@oailjhhlcmlbmnhbkmoclnfonplpan 0x6A 0x61 0x64 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@nacipnbaldjcfbiifafcoeinhgmo 0x6A 0x61 0x64 0x69 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----