Agent_UG8 | 02.10.2011 20:52 | GMER.txt
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-09-18 21:59:09
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD2500JS-00NCB1 rev.10.02E02
Running: k648gkcv.exe; Driver: C:\DOKUME~1\UMUTGC~1\LOKALE~1\Temp\pwtdipod.sys
---- System - GMER 1.0.15 ----
SSDT F7B769EE ZwCreateKey
SSDT F7B769E4 ZwCreateThread
SSDT F7B769F3 ZwDeleteKey
SSDT F7B769FD ZwDeleteValueKey
SSDT spgg.sys ZwEnumerateKey [0xF738ECA2]
SSDT spgg.sys ZwEnumerateValueKey [0xF738F030]
SSDT F7B76A02 ZwLoadKey
SSDT spgg.sys ZwOpenKey [0xF73700C0]
SSDT F7B769D0 ZwOpenProcess
SSDT F7B769D5 ZwOpenThread
SSDT spgg.sys ZwQueryKey [0xF738F108]
SSDT spgg.sys ZwQueryValueKey [0xF738EF88]
SSDT F7B76A0C ZwReplaceKey
SSDT F7B76A07 ZwRestoreKey
SSDT F7B769F8 ZwSetValueKey
INT 0x62 ? 86168BF8
INT 0x63 ? 85F8EBF8
INT 0x63 ? 85F8EBF8
INT 0x63 ? 85F8EBF8
INT 0x63 ? 85F8EBF8
INT 0x63 ? 85F8EBF8
INT 0x63 ? 85F8EBF8
INT 0x82 ? 86168BF8
INT 0x83 ? 86168BF8
---- Kernel code sections - GMER 1.0.15 ----
? spgg.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload F69D88AC 5 Bytes JMP 85F8E1D8
.text acpqhbmi.SYS F659E386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text acpqhbmi.SYS F659E3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text acpqhbmi.SYS F659E3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text acpqhbmi.SYS F659E3C9 1 Byte [2E]
.text acpqhbmi.SYS F659E3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7371040] spgg.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F737113C] spgg.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73710BE] spgg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73717FC] spgg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73716D2] spgg.sys
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\acpqhbmi.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7381048] spgg.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 861671F8
Device \Driver\usbuhci \Device\USBPDO-0 85EC71F8
Device \Driver\usbuhci \Device\USBPDO-1 85EC71F8
Device \Driver\usbuhci \Device\USBPDO-2 85EC71F8
Device \Driver\usbuhci \Device\USBPDO-3 85EC71F8
Device \Driver\usbehci \Device\USBPDO-4 85EB01F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 861DA1F8
Device \Driver\Cdrom \Device\CdRom0 85FB51F8
Device \Driver\usbstor \Device\00000072 85487358
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-12 [F72E9B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\usbstor \Device\00000074 85487358
Device \Driver\usbstor \Device\00000075 85487358
Device \Driver\usbstor \Device\00000076 85487358
Device \Driver\NetBT \Device\NetBt_Wins_Export 8501B1F8
Device \Driver\PCI_PNP6102 \Device\0000004b spgg.sys
Device \Driver\NetBT \Device\NetbiosSmb 8501B1F8
Device \Driver\usbuhci \Device\USBFDO-0 85EC71F8
Device \Driver\usbuhci \Device\USBFDO-1 85EC71F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85480500
Device \Driver\usbuhci \Device\USBFDO-2 85EC71F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 85480500
Device \Driver\usbuhci \Device\USBFDO-3 85EC71F8
Device \Driver\usbehci \Device\USBFDO-4 85EB01F8
Device \Driver\sptd \Device\2313586102 spgg.sys
Device \Driver\Ftdisk \Device\FtControl 861DA1F8
Device \Driver\acpqhbmi \Device\Scsi\acpqhbmi1 85E991F8
Device \FileSystem\Cdfs \Cdfs 854EE500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 566511147
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -35395895
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x2A 0xFF 0x65 0xDA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x7C 0xC1 0xFC 0x60 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC0 0x89 0xAA 0x63 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC4 0x07 0x9C 0x7C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x14 0xF7 0x2C 0x5D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xBE 0x98 0x12 0x8C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x2A 0xFF 0x65 0xDA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x7C 0xC1 0xFC 0x60 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC0 0x89 0xAA 0x63 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC4 0x07 0x9C 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x14 0xF7 0x2C 0x5D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xBE 0x98 0x12 0x8C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x45 0x42 0x89 0x33 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x85 0x3B 0x31 0xCC ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0x5F 0x30 0x53 ...
---- EOF - GMER 1.0.15 ---- --- --- --- OSAM wollte nicht : hxxp://i52.tinypic.com/2iizsk6.jpg aswMBR.txt Zitat:
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-10-02 21:33:35
-----------------------------
21:33:35.250 OS Version: Windows 5.1.2600 Service Pack 3
21:33:35.250 Number of processors: 2 586 0x403
21:33:35.250 ComputerName: HEIM-PC UserName:
21:33:35.859 Initialize success
21:35:53.734 AVAST engine defs: 11100202
21:36:29.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
21:36:29.531 Disk 0 Vendor: WDC_WD2500JS-00NCB1 10.02E02 Size: 238475MB BusType: 3
21:36:31.546 Disk 0 MBR read successfully
21:36:31.546 Disk 0 MBR scan
21:36:31.578 Disk 0 unknown MBR code
21:36:31.578 Disk 0 scanning sectors +488376000
21:36:31.640 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:41.140 Service scanning
21:36:41.515 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
21:36:42.046 Modules scanning
21:37:06.500 Disk 0 trace - called modules:
21:37:06.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spxu.sys >>UNKNOWN [0x86188938]<<
21:37:06.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86054ab8]
21:37:06.515 3 CLASSPNP.SYS[f75b0fd7] -> nt!IofCallDriver -> \Device\00000068[0x8607df18]
21:37:06.515 5 ACPI.sys[f732e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86136d98]
21:37:07.031 AVAST engine scan C:\WINDOWS
21:37:15.625 AVAST engine scan C:\WINDOWS\system32
21:38:49.343 File: C:\WINDOWS\system32\sens.dll **INFECTED** Win32:Patched-IE [Trj]
21:39:22.984 AVAST engine scan C:\WINDOWS\system32\drivers
21:39:40.484 AVAST engine scan C:\Dokumente und Einstellungen\***
21:46:26.031 Disk 0 MBR has been saved successfully to "C:\Dokumente und Einstellungen\***\Desktop\Intensivstation\MBR.dat"
21:46:26.046 The log file has been saved successfully to "C:\Dokumente und Einstellungen\***\Desktop\Intensivstation\aswMBR.txt" | |