Hier ist noch Gmer, hat nicht gepasst.
Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-11-01 11:36:19
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BPVT-00HXZT1 rev.01.01A01 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\G\AppData\Local\Temp\pxldqpog.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A46A35 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A80392 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [82, 71]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [79, 71] {JNS 0x73}
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [7F, 71] {JG 0x73}
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [73, 71] {JAE 0x73}
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [85, 71]
.text C:\Windows\system32\notepad.exe[1008] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [70, 71] {JO 0x73}
.text C:\Windows\system32\notepad.exe[1008] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 7189000A
.text C:\Windows\system32\notepad.exe[1008] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 718C000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 7198000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7192000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 718F000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 7195000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A1000A
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!SendInput + 4 7590701D 2 Bytes [9A, 71]
.text C:\Windows\system32\notepad.exe[1008] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 719E000A
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Windows\system32\taskhost.exe[1964] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Windows\system32\taskhost.exe[1964] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Windows\system32\taskhost.exe[1964] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Windows\system32\taskhost.exe[1964] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Windows\system32\Dwm.exe[2696] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Windows\system32\Dwm.exe[2696] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Windows\system32\Dwm.exe[2696] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Windows\system32\Dwm.exe[2696] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Windows\Explorer.EXE[2724] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\Explorer.EXE[2724] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Windows\Explorer.EXE[2724] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Windows\Explorer.EXE[2724] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2724] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Windows\Explorer.EXE[2724] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Windows\Explorer.EXE[2724] WS2_32.dll!WSALookupServiceBeginW 76CC575A 6 Bytes JMP 715C000A
.text C:\Windows\Explorer.EXE[2724] WS2_32.dll!connect 76CC6BDD 6 Bytes JMP 7165000A
.text C:\Windows\Explorer.EXE[2724] WS2_32.dll!listen 76CCB001 6 Bytes JMP 715F000A
.text C:\Windows\Explorer.EXE[2724] WS2_32.dll!WSAConnect 76CCCC3F 6 Bytes JMP 7162000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [73, 71] {JAE 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [6D, 71]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [70, 71] {JO 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [6A, 71] {PUSH 0x71}
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 7192000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 718C000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7189000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 718F000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!mouse_event 758F6209 6 Bytes JMP 719B000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!SendInput + 4 7590701D 2 Bytes [94, 71]
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 7198000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] advapi32.DLL!CreateServiceW 76BF70C4 6 Bytes JMP 7183000A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[2844] advapi32.DLL!CreateServiceA 76C13264 6 Bytes JMP 7186000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Program Files\TrueCrypt\TrueCrypt.exe[2856] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [82, 71]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [79, 71] {JNS 0x73}
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [7F, 71] {JG 0x73}
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [73, 71] {JAE 0x73}
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [85, 71]
.text C:\Windows\system32\notepad.exe[2944] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [70, 71] {JO 0x73}
.text C:\Windows\system32\notepad.exe[2944] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 7189000A
.text C:\Windows\system32\notepad.exe[2944] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 718C000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 7198000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7192000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 718F000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 7195000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A1000A
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!SendInput + 4 7590701D 2 Bytes [9A, 71]
.text C:\Windows\system32\notepad.exe[2944] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 719E000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Users\G\Desktop\Gmer-19357.exe[3560] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtCreateFile 77155608 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtCreateFile + 4 7715560C 2 Bytes [82, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtDeleteValueKey 77155888 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtDeleteValueKey + 4 7715588C 2 Bytes [88, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtFlushBuffersFile 77155998 5 Bytes JMP 5DC4EB90 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtOpenFile 77155D18 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtOpenFile + 4 77155D1C 2 Bytes [7F, 71] {JG 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtOpenProcess 77155DC8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtOpenProcess + 4 77155DCC 2 Bytes [85, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtQueryFullAttributesFile 77156028 5 Bytes JMP 5DC69C70 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtReadFile 771562F8 5 Bytes JMP 5DC4EC80 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtReadFileScatter 77156308 5 Bytes JMP 5E564CE1 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetContextThread 771565A8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetContextThread + 4 771565AC 2 Bytes [79, 71] {JNS 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetInformationFile 77156678 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetInformationFile + 4 7715667C 2 Bytes [7C, 71] {JL 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetValueKey 77156848 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtSetValueKey + 4 7715684C 2 Bytes [8B, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtWriteFile 77156AA8 5 Bytes JMP 5DC6ACB0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!NtWriteFileGather 77156AB8 5 Bytes JMP 5E564C90 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ntdll.dll!LdrLoadDll 771722AE 5 Bytes JMP 60BD1F42 C:\Program Files\Mozilla Firefox\mozglue.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 76F494E6 7 Bytes JMP 5E4D1CEB C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] kernel32.dll!QueryPerformanceCounter + 13 76F4C4E5 7 Bytes JMP 5E4D1D0E C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] kernel32.dll!LoadAppInitDlls + 355 76F4F5A6 7 Bytes JMP 5DC66A9C C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] kernel32.dll!CreateProcessInternalW 76F50852 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] kernel32.dll!CreateProcessInternalW + 4 76F50856 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!SendMessageA 758DAD60 6 Bytes JMP 719E000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!PostMessageA 758DB446 6 Bytes JMP 7198000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!PostMessageW 758E447B 6 Bytes JMP 7195000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!GetWindowInfo 758E4B5E 5 Bytes JMP 5E3D78E5 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!SendMessageW 758E5539 6 Bytes JMP 719B000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!mouse_event 758F6209 6 Bytes JMP 71A7000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!SendInput 75907019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!SendInput + 4 7590701D 2 Bytes [A0, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] USER32.dll!keybd_event 7592EC3B 6 Bytes JMP 71A4000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] GDI32.dll!GetViewportOrgEx + 26C 76C7884B 7 Bytes JMP 5E4D1C6C C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ADVAPI32.dll!CreateServiceW 76BF70C4 6 Bytes JMP 718F000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] ADVAPI32.dll!CreateServiceA 76C13264 6 Bytes JMP 7192000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] WS2_32.dll!WSALookupServiceBeginW 76CC575A 6 Bytes JMP 716B000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] WS2_32.dll!connect 76CC6BDD 6 Bytes JMP 7174000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] WS2_32.dll!listen 76CCB001 6 Bytes JMP 716E000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3692] WS2_32.dll!WSAConnect 76CCCC3F 6 Bytes JMP 7171000A
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 VMkbd.sys
Device \Driver\usbhub \Device\00000083 hcmon.sys
Device \Driver\usbhub \Device\00000084 hcmon.sys
Device \Driver\usbhub \Device\00000085 hcmon.sys
Device \Driver\usbhub \Device\00000086 hcmon.sys
Device \Driver\usbhub \Device\00000087 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys
Device \Driver\usbehci \Device\USBFDO-3 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-4 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-5 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-6 hcmon.sys
Device \Driver\usbehci \Device\USBFDO-7 hcmon.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active@2E238BA9 55
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- Möchte mich schon mal im Voraus bedanken.
LG |