Hier ist erstmal der GMER scan (konnte ihn aber nur einmal auf C machen, da er ansonsten immer abgestürzt ist).
Ich führe dann jetzt OSAM aus. Code:
GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2010-12-28 10:45:15
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD3200BEVT-22ZCT0 rev.11.01A11
Running: yczqw3t2.exe; Driver: C:\DOKUME~1\X\LOKALE~1\Temp\uwtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwAllocateVirtualMemory [0xA1C1FFE0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwAssignProcessToJobObject [0xA1C1FF10]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwClose [0xA1C1E0E0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwConnectPort [0xA1C20280]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwCreateFile [0xA1C1DAB0]
SSDT F7B13E7E ZwCreateKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwCreateProcess [0xA1C1F3B0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwCreateProcessEx [0xA1C1F4A0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwCreateSection [0xA1C1D6E0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwCreateSymbolicLinkObject [0xA1C1E3B0]
SSDT F7B13E74 ZwCreateThread
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwDebugActiveProcess [0xA1C208B0]
SSDT F7B13E83 ZwDeleteKey
SSDT F7B13E8D ZwDeleteValueKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwEnumerateKey [0xA1C1E710]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwEnumerateValueKey [0xA1C1E7F0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwFsControlFile [0xA1C1D9C0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwLoadDriver [0xA1C22900]
SSDT F7B13E92 ZwLoadKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwMakeTemporaryObject [0xA1C1E2F0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwOpenFile [0xA1C1DF40]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwOpenKey [0xA1C1E580]
SSDT F7B13E60 ZwOpenProcess
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwOpenSection [0xA1C1D7B0]
SSDT F7B13E65 ZwOpenThread
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwProtectVirtualMemory [0xA1C201A0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwQueryKey [0xA1C1E8D0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwQueryValueKey [0xA1C1E9B0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwQueueApcThread [0xA1C1FE40]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwRenameKey [0xA1C1EEB0]
SSDT F7B13E9C ZwReplaceKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwRequestPort [0xA1C20550]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwRequestWaitReplyPort [0xA1C20620]
SSDT F7B13E97 ZwRestoreKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSaveKey [0xA1C1EC40]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSaveKeyEx [0xA1C1ED10]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSecureConnectPort [0xA1C20370]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSetContextThread [0xA1C1FD50]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSetInformationDebugObject [0xA1C20980]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSetSecurityObject [0xA1C20A80]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSetSystemInformation [0xA1C1F060]
SSDT F7B13E88 ZwSetValueKey
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSuspendProcess [0xA1C1FBA0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSuspendThread [0xA1C1FC60]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwSystemDebugControl [0xA1C207D0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwTerminateProcess [0xA1C1F890]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwTerminateThread [0xA1C1FA50]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwUnloadDriver [0xA1C1F130]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwWriteFile [0xA1C1D8B0]
SSDT \SystemRoot\system32\DRIVERS\SandBox.sys (Host Protection Component/Agnitum Ltd.) ZwWriteVirtualMemory [0xA1C200C0]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2E64 80504700 4 Bytes CALL A966E8C6
.text ntkrnlpa.exe!ZwCallbackReturn + 2EA8 80504744 4 Bytes JMP 0C6AE90A
.text ntkrnlpa.exe!ZwCallbackReturn + 2FD8 80504874 12 Bytes [A0, FB, C1, A1, 60, FC, C1, ...]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF4FA7000, 0x198FE0, 0xE8000020]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F4D5D0AC] \SystemRoot\system32\drivers\afwcore.sys (Agnitum Firewall Core Driver/Agnitum Ltd.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015affd6d4d
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015affd6d4d (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BBF47A1DD8ACACC4B998ABAA34D61B87\Features@iTunes ??????????B?????????????????C:\WINDOWS\Installer\2cd1ff7.msi?A???????????s????????????????????????????????$??????????t??AppleCare Support???20091109?????????????f???????0??9.0.2.25?}????B?????????????hxxp://www.apple.com/de/support/????F:\iTunes\??????? ???????T??????ei??01805 009 433???9.0.2.25????????????????????? ??????????????????????????????N?????????????????N???????????N??????a??{00020424-0000-0000-C000-000000000046}??????????? ??????????????????????????????N?br?????b??????????????????????{9E93C96F-CF0D-43F6-8BA8-B807A3370712}??0???????????????????????1.c?????? ???????-???????????????? ?????????&???????????????????????????????????IiTunes?????? ??????????????????????????????N?????????????????????????N?????????{00020424-0000-0000-C000-000000000046}??? ??????? ??????????????????????????????N?????????????????N???????????N??????e??{00020424-0000-0000-C000-000000000046}??????? ??????????????????????????????N????????b????????????????0-C0??{9E93C96F-CF0D-43F6-8BA8-B807A3370712}???????????????????n??1.c?????? ?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BBF47A1DD8ACACC4B998ABAA34D61B87\Features@GEAR wrj2b!MWC]I~n*tPfdZOZLy8k=Bk.?0gjLiiedIAAoAE]@ceOAacrz`zqEAC
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BBF47A1DD8ACACC4B998ABAA34D61B87\Features@CoreFP hN!z]?!'h(XybGG%lrLW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BBF47A1DD8ACACC4B998ABAA34D61B87\Features@ATL u.'b9VZqf(g6u.Q(31aRw.'b9VZqf(g6u.Q(31aR
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D55AEDAA438CBCB4893AB4D8C1814FEE\Features@SyncServices ????????????????????????????????? ????????????????????????????????????????????????????????????????????????????????????????????8????????????e????Apple Mobile Device Support?????????????????????????????????????????????????????????Apple Mobile Device Support?????? ?????????????????????z??????0?2??? ???????????????????AppleMobileDeviceSupport????? ?????????????????????z??????0??????????????????????????????????????????????????????????? ???????????????????????????????*?????????????????????Z.$}Ck,ug(d4M!I%lrLW????? 2?????????????s???AppleMobileDeviceSupport????? ??????????????s???tPWdYa*ug(cNaTJ%lrLWAQVoZa*ug(89)UJ%lrLWUX(aga*ug(M'jZJ%lrLW5j{7Y~6'h(Kh!UO%lrLWdAow`Q'=$@oLjx8S9ImNk&vB8Orq4Ah(%D_!]=ySV}v,XqR!D@NV21E~v*1kw=8v]plh*?x-JP%K%lkt~Do_Jb*ug(iH^&K%lrLW?AppleMobileDeviceSupport???? 2?????????????????AppleMobileDeviceSupport????? ????????????????????v????????????e????????????????????????????????????????????????? *ee ????????????*??s??????????????????????? ???????????????? ????z?????? ????? ?????????????????????8
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D55AEDAA438CBCB4893AB4D8C1814FEE\Features@AppleMobileDeviceSupport Z.$}Ck,ug(d4M!I%lrLW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D55AEDAA438CBCB4893AB4D8C1814FEE\Features@MobileDrivers tPWdYa*ug(cNaTJ%lrLWAQVoZa*ug(89)UJ%lrLWUX(aga*ug(M'jZJ%lrLW5j{7Y~6'h(Kh!UO%lrLWdAow`Q'=$@oLjx8S9ImNk&vB8Orq4Ah(%D_!]=ySV}v,XqR!D@NV21E~v*1kw=8v]plh*?x-JP%K%lkt~Do_Jb*ug(iH^&K%lrLW?AppleMobileDeviceSupport
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D55AEDAA438CBCB4893AB4D8C1814FEE\Features@CRT_WinSXS _j0,Y]s!Soe8MkbIdFwUv$f.Z@}4G(*9MkbIdFwUv$f.Z@}4G(u8MkbIdFwU%9YbWIfIbe?9MkbIdFwU_j0,Y]s!Sou8MkbIdFwU_j0,Y]s!So*9MkbIdFwU!N0,YT,$So*9MkbIdFwU!N0,YT,$Sou8MkbIdFwUa@0,YF5$So*9MkbIdFwUe?0,Yk5$So*9MkbIdFwU]A0,Yx4$So*9MkbIdFwUe?0,Yk5$Sou8MkbIdFwUa@0,YF5$Sou8MkbIdFwUXB0,YS4$So*9MkbIdFwU]A0,Yx4$Sou8MkbIdFwUTC0,Y*4$So*9MkbIdFwUPD0,Ya3$So*9MkbIdFwUXB0,YS4$Sou8MkbIdFwU&vv.ZiM}F(*9MkbIdFwUTC0,Y*4$Sou8MkbIdFwULE0,Y83$So*9MkbIdFwUPD0,Ya3$Sou8MkbIdFwULE0,Y83$Sou8MkbIdFwUEgn.Z_T*G(*9MkbIdFwUzH^.ZJcAG(*9MkbIdFwU&vv.ZiM}F(u8MkbIdFwUEgn.Z_T*G(u8MkbIdFwU=6U.Z@jJG(*9MkbIdFwUUQ^.ZZ_AG(*9MkbIdFwUzH^.ZJcAG(u8MkbIdFwU=6U.Z@jJG(u8MkbIdFwUUQ^.ZZ_AG(u8MkbIdFwUaZO,H*K2`Ee8MkbIdFwUxp%0Ij`~kV*9MkbIdFwUaZO,H*K2`E*9MkbIdFwU%?O,H~_2`E*9MkbIdFwUg+O,H9h2`E*9MkbIdFwUc,O,Hog2`E*9MkbIdFwU_-O,HJg2`E*9MkbIdFwUZ.O,H}f2`E*9MkbIdFwUV0O,HWf2`E*9MkbIdFwUR1O,H.f2`E*9MkbIdFwUN2O,Hee2`E*9MkbIdFwU(g70I8-kkV*9MkbIdFwUGW.0I-5tkV*9MkbIdFwU}5y.ItF+lV*9MkbIdFwU@&q.IjM5lV*9MkbIdFwUWBy.I)C+lV*9MkbIdFwU?AppleMobileDeviceSupport
---- EOF - GMER 1.0.15 ---- |