Zunächst Gmer: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-09 23:03:53
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005b ST350083 rev.3.AA
Running: j7r0yzdj.exe; Driver: C:\Users\Stefan\AppData\Local\Temp\ugdiqpob.sys
---- System - GMER 1.0.15 ----
SSDT 8DE9F546 ZwCreateSection
SSDT 8DE9F550 ZwRequestWaitReplyPort
SSDT 8DE9F54B ZwSetContextThread
SSDT 8DE9F555 ZwSetSecurityObject
SSDT 8DE9F55A ZwSystemDebugControl
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x8E629640]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 215 82EAC8D8 4 Bytes [46, F5, E9, 8D]
.text ntkrnlpa.exe!KeSetEvent + 539 82EACBFC 4 Bytes [50, F5, E9, 8D]
.text ntkrnlpa.exe!KeSetEvent + 56D 82EACC30 4 Bytes [4B, F5, E9, 8D]
.text ntkrnlpa.exe!KeSetEvent + 5D1 82EACC94 4 Bytes [55, F5, E9, 8D]
.text ntkrnlpa.exe!KeSetEvent + 619 82EACCDC 4 Bytes [5A, F5, E9, 8D]
.text ...
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8D005340, 0x39ED97, 0xE8000020]
.text C:\Windows\system32\drivers\ACEDRV07.sys section is writeable [0x9C604000, 0x328BA, 0xE8000020]
.pklstb C:\Windows\system32\drivers\ACEDRV07.sys entry point in ".pklstb" section [0x9C648000]
.relo2 C:\Windows\system32\drivers\ACEDRV07.sys unknown last section [0x9C664000, 0x8E, 0x42000040]
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x9F512300, 0x3AF78, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9F555300, 0x1BCE, 0xE8000020]
? C:\Windows\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. !
? C:\Users\Stefan\AppData\Local\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. !
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusShutdown] [73F97817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCloneImage] [73FDB4E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDrawImageRectI] [73F9BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [73F8F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusStartup] [73F975E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateFromHDC] [73F8E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73FC73F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromStream] [73F9DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageHeight] [73F8FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageWidth] [73F8FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDisposeImage] [73F871CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipLoadImageFromFileICM] [7401CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipLoadImageFromFile] [73FBC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDeleteGraphics] [73F8D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipFree] [73F86853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipAlloc] [73F8687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5460] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetCompositingMode] [73F92AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT-Dateisystemtreiber/Microsoft Corporation)
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy11 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy12 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy13 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy20 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy14 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy21 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy22 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy15 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy23 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy16 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy24 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy17 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy25 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy18 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy26 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy19 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy27 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy28 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy29 eubakup.sys (Disk Backup Driver/CHENGDU YIWO Tech Development Co., Ltd)
AttachedDevice fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00158307cde2
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00158307cde2 (not active ControlSet)
Reg HKLM\SOFTWARE\Classes\CLSID\{B6A930A0-A4F5-43A5-9B4E-6189A6C2B9E8}@\24!s!\24!y!c!`!s!i!\22!t!t!\22!i!c!s!j! 19583823
---- EOF - GMER 1.0.15 ---- |