...hier der GMER-LOG:
habich mir länger vorgestellt
Zitat:
GMER 1.0.15.15281 - hxxp://www.gmer.net
Rootkit scan 2010-05-13 11:58:35
Windows 5.1.2600 Service Pack 3
Running: yyi6sfjb.exe; Driver: C:\DOKUME~1\Anwender\LOKALE~1\Temp\fwtdypoc.sys
---- System - GMER 1.0.15 ----
SSDT BAEEC666 ZwCreateKey
SSDT BAEEC65C ZwCreateThread
SSDT BAEEC66B ZwDeleteKey
SSDT BAEEC675 ZwDeleteValueKey
SSDT BAEEC67A ZwLoadKey
SSDT BAEEC648 ZwOpenProcess
SSDT BAEEC64D ZwOpenThread
SSDT BAEEC684 ZwReplaceKey
SSDT BAEEC67F ZwRestoreKey
SSDT BAEEC670 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9E1D360, 0x37399D, 0xE8000020]
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xB7539280]
.reloc C:\WINDOWS\system32\drivers\acedrv11.sys section is executable [0xB60F3600, 0x25B0C, 0xE0000060]
---- EOF - GMER 1.0.15 ----
|
__________________