![]() |
| |||||||
Log-Analyse und Auswertung: Infiziert?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #16 |
![]() ![]() | Infiziert? Das kam bei GMER heraus: Code:
ATTFilter GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-15 23:00:43
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT BAFA977E ZwCreateKey
SSDT BAFA9774 ZwCreateThread
SSDT BAFA9783 ZwDeleteKey
SSDT BAFA978D ZwDeleteValueKey
SSDT sprs.sys ZwEnumerateKey [0xBA6C6CA2]
SSDT sprs.sys ZwEnumerateValueKey [0xBA6C7030]
SSDT BAFA9792 ZwLoadKey
SSDT sprs.sys ZwOpenKey [0xBA6A80C0]
SSDT BAFA9760 ZwOpenProcess
SSDT BAFA9765 ZwOpenThread
SSDT sprs.sys ZwQueryKey [0xBA6C7108]
SSDT sprs.sys ZwQueryValueKey [0xBA6C6F88]
SSDT BAFA979C ZwReplaceKey
SSDT BAFA9797 ZwRestoreKey
SSDT BAFA9788 ZwSetValueKey
SSDT BAFA976F ZwTerminateProcess
INT 0x62 ? 8A613BF8
INT 0x63 ? 8A613BF8
INT 0x63 ? 8A613BF8
INT 0x63 ? 8A306BF8
INT 0x73 ? 8A5A5BF8
INT 0x73 ? 8A5A5BF8
INT 0x83 ? 8A306BF8
INT 0xA4 ? 8A306BF8
INT 0xB4 ? 8A306BF8
Code 8A0B8FD8 ZwFlushInstructionCache
Code 8A0B8E26 IofCallDriver
Code 88A32386 IofCompleteRequest
Code 8A0B90B5 ZwSaveKey
Code 8A0B918D ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 8A0B8E2B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 88A3238B
.text ntkrnlpa.exe!ZwSaveKey 80500D68 5 Bytes JMP 8A0B90BA
.text ntkrnlpa.exe!ZwSaveKeyEx 80500D7C 5 Bytes JMP 8A0B9192
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8A0B8FDC
? sprs.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload B9A388AC 5 Bytes JMP 8A3061D8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A9040] sprs.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A913C] sprs.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A90BE] sprs.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A97FC] sprs.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A96D2] sprs.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A5A11F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{2833BB1A-0A93-49A6-A6B6-03EA4ACA14FF} 8A37B500
Device \Driver\usbuhci \Device\USBPDO-0 8A304500
Device \Driver\usbuhci \Device\USBPDO-1 8A304500
Device \Driver\usbuhci \Device\USBPDO-2 8A304500
Device \Driver\usbuhci \Device\USBPDO-3 8A304500
Device \Driver\NetBT \Device\NetBT_Tcpip_{3ABE492C-1F38-465D-BD23-F6074506C18A} 8A37B500
Device \Driver\usbehci \Device\USBPDO-4 8A323500
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A5A31F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A5A31F8
Device \Driver\Cdrom \Device\CdRom1 8A258430
Device \Driver\usbstor \Device\00000080 8A0CC1F8
Device \Driver\usbstor \Device\00000081 8A0CC1F8
Device \Driver\usbstor \Device\00000082 8A0CC1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A37B500
Device \Driver\PCI_PNP8880 \Device\0000004b sprs.sys
Device \Driver\NetBT \Device\NetbiosSmb 8A37B500
Device \Driver\usbuhci \Device\USBFDO-0 8A304500
Device \Driver\usbuhci \Device\USBFDO-1 8A304500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89F78500
Device \Driver\usbstor \Device\0000007b 8A0CC1F8
Device \Driver\usbuhci \Device\USBFDO-2 8A304500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89F78500
Device \Driver\usbuhci \Device\USBFDO-3 8A304500
Device \Driver\usbehci \Device\USBFDO-4 8A323500
Device \Driver\Ftdisk \Device\FtControl 8A5A31F8
Device \Driver\usbstor \Device\0000007f 8A0CC1F8
Device \Driver\sptd \Device\2065586380 sprs.sys
Device \Driver\agvko7uw \Device\Scsi\agvko7uw1Port5Path0Target0Lun0 8A2401F8
Device \Driver\agvko7uw \Device\Scsi\agvko7uw1 8A2401F8
Device \Driver\JRAID \Device\Scsi\JRAID1 8A5A21F8
Device \FileSystem\Cdfs \Cdfs 8A0CB1F8
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@oaekjkbfbepihimmfanddhhpkpmmmg 0x64 0x61 0x64 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@oailjhhlcmlbmnhbkmoclnfonplpan 0x6A 0x61 0x64 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4253CC67-8266-6CC7-E300-0AFF8DB0ABBD}@nacipnbaldjcfbiifafcoeinhgmo 0x6A 0x61 0x64 0x69 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
|
| Themen zu Infiziert? |
| anwendung, b.exe, beendet, datei, deaktiviert, download, exe-datei, fehlermeldung, guten, heute, hijack, hijackthis, hijackthis log-file, infiziert, infiziert?, installation, log-file, malware, nicht öffnen, problem, problemlos, programm, systemstart, taskmanager, überhaupt, öffnen, öffnet, öffnet sich ständig |