Hallo,
 
ich habe interessehalber mal 
GMER laufen lassen, welcher mir folgendes Logfile ausspuckte:  
 Zitat:
   
			
				GMER 1.0.15.15281 - http://www.gmer.net 
Rootkit scan 2010-02-28 14:00:21 
Windows 5.1.2600 Service Pack 3 
Running: 6xc7eqg0.exe; Driver: C:\DOKUME~1\user\LOKALE~1\Temp\uggorkoc.sys     
---- System - GMER 1.0.15 ----   
SSDT            F7CFE83E                                                                         ZwCreateKey 
SSDT            F7CFE834                                                                         ZwCreateThread 
SSDT            F7CFE843                                                                         ZwDeleteKey 
SSDT            F7CFE84D                                                                         ZwDeleteValueKey 
SSDT            F7CFE852                                                                         ZwLoadKey 
SSDT            F7CFE820                                                                         ZwOpenProcess 
SSDT            F7CFE825                                                                         ZwOpenThread 
SSDT            F7CFE85C                                                                         ZwReplaceKey 
SSDT            F7CFE857                                                                         ZwRestoreKey 
SSDT            F7CFE848                                                                         ZwSetValueKey 
SSDT            F7CFE82F                                                                         ZwTerminateProcess   
---- Kernel code sections - GMER 1.0.15 ----   
.text           ntkrnlpa.exe!ZwCallbackReturn + 2410                                             80501C48 4 Bytes  CALL 645B141C  
.text           ntkrnlpa.exe!ZwCallbackReturn + 2440                                             80501C78 4 Bytes  CALL 518F144C  
.text           ntkrnlpa.exe!ZwCallbackReturn + 2468                                             80501CA0 4 Bytes  CALL 2D211474  
.text           ntkrnlpa.exe!ZwCallbackReturn + 2470                                             80501CA8 4 Bytes  CALL 6513147C  
.text           ntkrnlpa.exe!ZwCallbackReturn + 24F4                                             80501D2C 4 Bytes  CALL 418F1500  
.text           ...                                                                                 
---- Devices - GMER 1.0.15 ----   
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                        fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation) 
AttachedDevice  \FileSystem\Fastfat \Fat                                                         fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)   
Device          \FileSystem\Cdfs \Cdfs                                                           EBC25400   
---- Services - GMER 1.0.15 ----   
Service         system32\drivers\TDSSpaxt.sys (*** hidden *** )                                  [SYSTEM] TDSSserv.sys                                                       <-- ROOTKIT !!!   
---- Registry - GMER 1.0.15 ----   
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@start                        1 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@type                         1 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@imagepath                    \systemroot\system32\drivers\TDSSpaxt.sys 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@group                        file system 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules                       
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSserv             \systemroot\system32\drivers\TDSSpaxt.sys 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSl                \systemroot\system32\TDSSoeqh.dll 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssservers          \systemroot\system32\TDSSosvn.dat 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssmain             \systemroot\system32\TDSSnrsr.dll 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsslog              \systemroot\system32\TDSSriqp.dll 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssadw              \systemroot\system32\TDSScfub.dll 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssinit             \systemroot\system32\TDSSfpmp.dll 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssurls             \systemroot\system32\TDSSnmxh.log 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsspanels           \systemroot\system32\TDSSsbhc.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@start                            1 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@type                             1 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@imagepath                        \systemroot\system32\drivers\TDSSpaxt.sys 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@group                            file system 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules (not active ControlSet)   
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSserv                 \systemroot\system32\drivers\TDSSpaxt.sys 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSl                    \systemroot\system32\TDSSoeqh.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssservers              \systemroot\system32\TDSSosvn.dat 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssmain                 \systemroot\system32\TDSSnrsr.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsslog                  \systemroot\system32\TDSSriqp.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssadw                  \systemroot\system32\TDSScfub.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssinit                 \systemroot\system32\TDSSfpmp.dll 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssurls                 \systemroot\system32\TDSSnmxh.log 
Reg             HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsspanels               \systemroot\system32\TDSSsbhc.dll   
---- EOF - GMER 1.0.15 ----
			
		 |  
 
  
Im Anhang MBAM und 
RSIT Logs. 
Danke schonmal für die Hilfe