moin,
hehe dacht schon hab mein rechner zerschossen^^
k hier der log von virustotal:
hxxp://www.virustotal.com/de/analisis/05ea3da2e18b57e47dfb17ec63cf36735e79c7e8e2e23c93fc15e21040009b98-1270646445
und gmer Zitat:
GMER 1.0.15.15281 - hxxp://www.gmer.net
Rootkit scan 2010-04-07 15:36:19
Windows 6.1.7600
Running: 52biy1ym.exe; Driver: C:\Users\RedNoak\AppData\Local\Temp\fwldrpoc.sys
---- System - GMER 1.0.15 ----
SSDT 9199BCC4 ZwCreateThread
SSDT 9199BCB0 ZwOpenProcess
SSDT 9199BCB5 ZwOpenThread
SSDT 9199BCBF ZwTerminateProcess
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83039AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83039104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830393F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830222D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83021898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830391DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83039958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830396F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83039F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 82C525C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C77052 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 37C 82C7E97C 4 Bytes [C4, BC, 99, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 518 82C7EB18 4 Bytes [B0, BC, 99, 91] {MOV AL, 0xbc; CDQ ; XCHG ECX, EAX}
.text ntkrnlpa.exe!RtlSidHashLookup + 538 82C7EB38 4 Bytes CALL 1C84A0BF
.text ntkrnlpa.exe!RtlSidHashLookup + 7E8 82C7EDE8 4 Bytes [BF, BC, 99, 91]
? System32\Drivers\sprq.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8F629CA0 5 Bytes JMP 85D551D8
.text ajwvlt93.SYS 8F6F8000 12 Bytes [44, 48, 02, 83, EE, 46, 02, ...]
.text ajwvlt93.SYS 8F6F800D 9 Bytes [27, 02, 83, 48, 4B, 02, 83, ...] {DAA ; ADD AL, [EBX-0x7cfdb4b8]; ADD [EAX], AL}
.text ajwvlt93.SYS 8F6F8017 170 Bytes [00, DE, 87, D1, 88, E6, 85, ...]
.text ajwvlt93.SYS 8F6F80C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ajwvlt93.SYS 8F6F80CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x99C6B300, 0x3B6D8, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x99D3E300, 0x1BEE, 0xE8000020]
.text peauth.sys 99D48C9D 28 Bytes [9E, D8, 91, 2B, 5D, B8, D5, ...]
.text peauth.sys 99D48CC1 28 Bytes [9E, D8, 91, 2B, 5D, B8, D5, ...]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88C1C042] \SystemRoot\System32\Drivers\sprq.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88C1C6D6] \SystemRoot\System32\Drivers\sprq.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88C1C800] \SystemRoot\System32\Drivers\sprq.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88C1C13E] \SystemRoot\System32\Drivers\sprq.sys
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortNotification] 00147880
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortQuerySystemTime] 78800C75
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortReadPortUchar] 06750015
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortStallExecution] C25DC033
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortWritePortUchar] 458B0008
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortWritePortUlong] 6A006A08
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 50056A24
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 005AB7E8
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortGetScatterGatherList] 0001B800
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortGetParentBusType] C25D0000
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortRequestCallback] CCCC0008
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortWritePortBufferUshort] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortGetUnCachedExtension] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortCompleteRequest] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortCopyMemory] 53EC8B55
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortEtwTraceLog] 800C5D8B
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7500117B
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 127B806A
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 80647500
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7500137B
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortInitialize] 157B805E
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortGetDeviceBase] 56587500
IAT \SystemRoot\System32\Drivers\ajwvlt93.SYS[ataport.SYS!AtaPortDeviceStateChange] 8008758B
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 84E941F8
Device \Driver\volmgr \Device\VolMgrControl 84E901F8
Device \Driver\usbuhci \Device\USBPDO-0 85DB9500
Device \Driver\usbuhci \Device\USBPDO-1 85DB9500
Device \Driver\usbuhci \Device\USBPDO-2 85DB9500
Device \Driver\usbehci \Device\USBPDO-3 85FCE500
Device \Driver\usbuhci \Device\USBPDO-4 85DB9500
Device \Driver\sptd \Device\3126046659 sprq.sys
Device \Driver\usbuhci \Device\USBPDO-5 85DB9500
Device \Driver\usbuhci \Device\USBPDO-6 85DB9500
Device \Driver\volmgr \Device\HarddiskVolume1 84E901F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\PCI_PNP8658 \Device\00000058 sprq.sys
Device \Driver\usbehci \Device\USBPDO-7 85FCE500
Device \Driver\volmgr \Device\HarddiskVolume2 84E901F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 85ED11F8
Device \Driver\volmgr \Device\HarddiskVolume3 84E901F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 85ED11F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84E921F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 84E921F8
Device \Driver\atapi \Device\Ide\IdePort0 84E921F8
Device \Driver\atapi \Device\Ide\IdePort1 84E921F8
Device \Driver\atapi \Device\Ide\IdePort2 84E921F8
Device \Driver\atapi \Device\Ide\IdePort3 84E921F8
Device \Driver\atapi \Device\Ide\IdePort4 84E921F8
Device \Driver\atapi \Device\Ide\IdePort5 84E921F8
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-6 84E921F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 85F031F8
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 85DB9500
Device \Driver\usbuhci \Device\USBFDO-1 85DB9500
Device \Driver\usbuhci \Device\USBFDO-2 85DB9500
Device \Driver\usbehci \Device\USBFDO-3 85FCE500
Device \Driver\usbuhci \Device\USBFDO-4 85DB9500
Device \Driver\usbuhci \Device\USBFDO-5 85DB9500
Device \Driver\usbuhci \Device\USBFDO-6 85DB9500
Device \Driver\usbehci \Device\USBFDO-7 85FCE500
Device \Driver\ajwvlt93 \Device\Scsi\ajwvlt931 861601F8
Device \Driver\ajwvlt93 \Device\Scsi\ajwvlt931Port6Path0Target0Lun0 861601F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1F 0xAA 0x92 0x7C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB2 0x53 0x81 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x53 0x19 0x12 0xD8 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1F 0xAA 0x92 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB2 0x53 0x81 0x83 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x53 0x19 0x12 0xD8 ...
---- EOF - GMER 1.0.15 ----
|
mfg
red |