der_gizmo | 15.07.2009 22:27 | HIer kamen mehrere Fehlermeldungen, zum einen diese hier: Could not read the boot sector. Try adjusting the Disk Acces Level in the OPtions dialog.
Diese kam mehrfach.
Desweiteren kam noch eine weitere, nach der der Scan beendet war. Ich wieß nun nicht, ob der Scan aufgrund dieser Fehlermeldung (den Inhalt kann ich leider nicht wiedergeben, da ich zunächst annahm, es wäre wieder die obige Fehelermeldung.) beendet wurde, oder, ob er schon abgeschlossen war.
Das Ergebnis lautet wiefolgt: Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/07/15 23:22
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: aujasnkj.sys
Image Path: C:\DOKUME~1\kwam\LOKALE~1\Temp\aujasnkj.sys
Address: 0xAB366000 Size: 81664 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB2FEA000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBADC6000 Size: 8192 File Visible: No Signed: -
Status: -
Name: ESQULfilmctpitjlkdnwynadxrykqgxtfhmto.sys
Image Path: C:\WINDOWS\system32\drivers\ESQULfilmctpitjlkdnwynadxrykqgxtfhmto.sys
Address: 0xB325D000 Size: 192512 File Visible: - Signed: -
Status: Hidden from the Windows API!
Name: PCI_PNP8880
Image Path: \Driver\PCI_PNP8880
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAB39A000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sprs.sys
Image Path: sprs.sys
Address: 0xBA6A7000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xbafa977e
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xbafa9774
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xbafa9783
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xbafa978d
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sprs.sys" at address 0xba6c6ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sprs.sys" at address 0xba6c7030
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xbafa9792
#: 119 Function Name: NtOpenKey
Status: Hooked by "sprs.sys" at address 0xba6a80c0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xbafa9760
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xbafa9765
#: 160 Function Name: NtQueryKey
Status: Hooked by "sprs.sys" at address 0xba6c7108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sprs.sys" at address 0xba6c6f88
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xbafa979c
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xbafa9797
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xbafa9788
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xbafa976f
Stealth Objects
-------------------
Object: Hidden Module [Name: ESQULcrlbgpsvaxtvndqqnxxoquvgvupxtvyk.dll]
Process: svchost.exe (PID: 1060) Address: 0x10000000 Address: 57344
Object: Hidden Module [Name: ESQULjwoaypplxqliosrhdgapirxxdnowqyin.dll]
Process: firefox.exe (PID: 3016) Address: 0x10000000 Address: 241664
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8a5a11f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8a258430 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_CREATE]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_CLOSE]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_POWER]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: JRAID, IRP_MJ_PNP]
Process: System Address: 0x8a5a21f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_READ]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP]
Process: System Address: 0x8a0cc1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8a304500 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8a5a31f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8a37b500 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_CREATE]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_CLOSE]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_POWER]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: agvko7uwЅ敓Ёఈ浍浓訍Ā, IRP_MJ_PNP]
Process: System Address: 0x8a2401f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8a323500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x89f78500 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_CREATE]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_CLOSE]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_READ]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_CLEANUP]
Process: System Address: 0x8a0cb1f8 Address: 121
Object: Hidden Code [Driver: Cdfsȅఈ灐畳ꅰ爠, IRP_MJ_PNP]
Process: System Address: 0x8a0cb1f8 Address: 121
==EOF== |