21.07.2010, 17:25
|
#17 |
| Rechner versäucht - Animalware Doctor, Antivirus software alert unterbinden alles ok, hier ist es. Zitat:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/07/21 18:13
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB2462000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8B69000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB0C60000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xf8d16fc6
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xf8d16fbc
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xf8d16fcb
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xf8d16fd5
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf8d16fda
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf8d16fa8
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xf8d16fad
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf8d16fe4
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xf8d16fdf
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xf8d16fd0
==EOF==
|
__________________ |