blaxXxun | 06.08.2009 09:17 | hier mal der GMER log... und das sind jetzt alles rootkits?:dummguck: Code:
GMER 1.0.15.15011 [6vi52lsr.exe] - http://www.gmer.net
Rootkit scan 2009-08-06 09:50:53
Windows 6.0.6001 Service Pack 1
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x82F0A282]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x82F0A474]
SSDT 8D1C0834 ZwCreateThread
SSDT 8D1C0820 ZwOpenProcess
SSDT 8D1C0825 ZwOpenThread
SSDT 8D1C082F ZwTerminateProcess
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x82F0A67C]
INT 0x52 ? 86D90F00
INT 0x72 ? 85578BF8
INT 0x72 ? 85578BF8
INT 0x72 ? 85578BF8
INT 0x72 ? 86D90F00
INT 0x72 ? 86D90F00
INT 0x72 ? 85578BF8
INT 0x82 ? 85578BF8
INT 0x92 ? 85578BF8
INT 0xB2 ? 86D90F00
INT 0xB2 ? 86D90F00
INT 0xB3 ? 86D90F00
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetTimerEx + 43C 828B8A00 3 Bytes [82, A2, F0]
.text ntkrnlpa.exe!KeSetTimerEx + 440 828B8A04 3 Bytes [74, A4, F0]
.text ntkrnlpa.exe!KeSetTimerEx + 454 828B8A18 4 Bytes [34, 08, 1C, 8D] {XOR AL, 0x8; SBB AL, 0x8d}
.text ntkrnlpa.exe!KeSetTimerEx + 624 828B8BE8 4 Bytes [20, 08, 1C, 8D] {AND [EAX], CL; SBB AL, 0x8d}
.text ntkrnlpa.exe!KeSetTimerEx + 640 828B8C04 4 Bytes [25, 08, 1C, 8D]
.text ...
? System32\Drivers\spzc.sys Das System kann den angegebenen Pfad nicht finden. !
PAGE ataport.SYS!DllUnload 82EAAB2E 5 Bytes JMP 855781D8
.text USBPORT.SYS!DllUnload 8EF4246F 5 Bytes JMP 86D904E0
.text anlmrebd.SYS 8EF72000 22 Bytes [26, 02, BC, 82, 10, 01, BC, ...]
.text anlmrebd.SYS 8EF72017 103 Bytes [00, 32, C7, 79, 80, 3D, C5, ...]
.text anlmrebd.SYS 8EF7207F 41 Bytes [82, A2, DA, 80, 82, EB, DB, ...]
.text anlmrebd.SYS 8EF720A9 35 Bytes [30, 85, 82, A0, 27, 85, 82, ...]
.text anlmrebd.SYS 8EF720CE 10 Bytes [00, 00, 00, 00, 00, 00, 6A, ...]
.text ...
PAGE spsys.sys!?SPVersion@@3PADA + 1A67 98D7703F 240 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B58 98D77130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1B5F 98D77137 2214 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 2406 98D779DE 47 Bytes [04, BB, A8, 01, 00, 00, 8D, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 2436 98D77A0E 44 Bytes [05, 00, 00, 39, 54, 8D, D0, ...]
PAGE ...
? C:\Windows\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtClose 77B57F48 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtClose + 4 77B57F4C 2 Bytes [35, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateFile 77B58008 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateFile + 4 77B5800C 2 Bytes [17, 5F] {POP SS; POP EDI}
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateKey 77B58048 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateKey + 4 77B5804C 2 Bytes [05, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateProcess 77B580C8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateProcess + 4 77B580CC 2 Bytes [29, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateProcessEx 77B580D8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateProcessEx + 4 77B580DC 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateSection 77B580F8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateSection + 4 77B580FC 2 Bytes [23, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtDeleteKey 77B583F8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtDeleteKey + 4 77B583FC 2 Bytes [0B, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtDeleteValueKey 77B58428 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtDeleteValueKey + 4 77B5842C 2 Bytes [11, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtRenameKey 77B58CF8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtRenameKey + 4 77B58CFC 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtSetInformationFile 77B58F18 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtSetInformationFile + 4 77B58F1C 2 Bytes [20, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtSetValueKey 77B59088 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtSetValueKey + 4 77B5908C 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtTerminateProcess 77B59128 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtTerminateProcess + 4 77B5912C 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteFile 77B59278 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteFile + 4 77B5927C 2 Bytes [1A, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteFileGather 77B59288 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteFileGather + 4 77B5928C 2 Bytes [1D, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteVirtualMemory 77B592A8 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtWriteVirtualMemory + 4 77B592AC 2 Bytes [32, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateUserProcess 77B59438 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] ntdll.dll!NtCreateUserProcess + 4 77B5943C 2 Bytes [26, 5F]
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] kernel32.dll!LoadLibraryExW 76D330C3 6 Bytes JMP 5F070F5A
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] USER32.dll!SetWindowsHookExW 77C97B69 6 Bytes JMP 5F3B0F5A
.text D:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2576] USER32.dll!SetWindowsHookExA 77CBBB0E 6 Bytes JMP 5F370F5A
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806936D2] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80693040] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [806937FC] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806930BE] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069313C] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A3048] \SystemRoot\System32\Drivers\spzc.sys
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortNotification] CC000CC2
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortWritePortUchar] 83EC8B55
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortWritePortUlong] 575320EC
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 458DFF33
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 8D5750FC
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5750F845
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortReadPortUchar] 8957046A
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortStallExecution] 75E8FC7D
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortGetParentBusType] BB0001E8
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortRequestCallback] 000000EA
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 850FC33B
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0000012B
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortCompleteRequest] 0FFC7D39
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortMoveMemory] 00012284
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 458D5600
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 106A50F4
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 38335668
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortReadPortUshort] FC75FF36
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortReadPortBufferUshort] D1E85757
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortInitialize] 8B0001E7
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortGetDeviceBase] 1BDEF7F0
IAT \SystemRoot\System32\Drivers\anlmrebd.SYS[ataport.SYS!AtaPortDeviceStateChange] 23D6F7F6
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74A17BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74A598C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74A1D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74A0F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74A17599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74A0E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74A4B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74A1D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74A1012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74A10095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74A071F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74A9D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74A375E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74A0DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74A0668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74A066BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1164] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74A11E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) |