stand nicht dabei das ich den log auch posten soll :-) ..
gmer Code:
GMER Logfile:
Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-05-07 15:56:04
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Michael\AppData\Local\Temp\uxdiifow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1712] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076a61465 2 bytes [A6, 76]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1712] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000076a614bb 2 bytes [A6, 76]
.text ... * 2
.text C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe[980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a61465 2 bytes [A6, 76]
.text C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe[980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a614bb 2 bytes [A6, 76]
.text ... * 2
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[3472] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a61465 2 bytes [A6, 76]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[3472] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a614bb 2 bytes [A6, 76]
.text ... * 2
.text C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe[3848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a61465 2 bytes [A6, 76]
.text C:\Users\Michael\AppData\Local\Akamai\netsession_win.exe[3848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a614bb 2 bytes [A6, 76]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a61465 2 bytes [A6, 76]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a614bb 2 bytes [A6, 76]
.text ... * 2
.text C:\Program Files\Internet Explorer\iexplore.exe[4992] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007feff044ed0 9 bytes [68, 78, 03, 3B, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4992] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefc745c54 7 bytes [68, 08, 03, 3B, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[4992] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefc745c64 9 bytes [68, 40, 03, 3B, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4992] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007feff0d17a0 9 bytes [68, B0, 03, 3B, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A 000000007794f548 7 bytes JMP 0000000103310570
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W 000000007795b0ac 7 bytes JMP 00000001033105a8
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\kernel32.dll!CreateThread 00000000775d6580 9 bytes JMP 00000001033104c8
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007feff6275f0 7 bytes [68, E0, 05, 31, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefefe1180 10 bytes [68, C0, 06, 31, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefefe1320 7 bytes [68, 50, 06, 31, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefefe4450 6 bytes [68, 18, 06, 31, 03, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefefe6720 10 bytes [68, 88, 06, 31, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007feff044ed0 9 bytes [68, 78, 03, 31, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefc745c54 7 bytes [68, 08, 03, 31, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefc745c64 9 bytes [68, 40, 03, 31, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5040] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007feff0d17a0 9 bytes [68, B0, 03, 31, 03, C3, CC, ...]
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ?????g??? ?????????????????????0????????????&???????????????????????? ???????????????????/?0????????????????????DISPLAY\PHL0000\4&1fde55bf&0&UID50529024?0???????-???????????????&??????????? ???????/???????????6?,??????(?????????????in????????????????9e6b???????????9??????? ???????????????????h?0????????????????????????????????#???"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"?000??? ?????????????????????0?????????????????????????????????????????????o???s??Adobe Acrobat Updater h?lt Ihre Adobe-Software aktuell.?AA??? ???i???3?????dbu??? ???????6??????n\??6.1.7600.16385?_??????,??????E???????????????i???????????????????????????g??? ??????????????????????#???? ???????U?????????????,????????R???S??????????????????????????????????????????}????? ?????????????????????,??????????????#_05??? ???????????????&???&??oem31.inf???MTP-USB-Ger?t???{36fc9e60-c465-11cf-8056-444553540000}\0011?(S??011?(S??????????????USB\VID_05AC&PID_1281\CPID:8930_CPRV:20_CPFM:03_SCEP:02_BDID:00_ECID:000001F281038D4C_IBFL:02_S
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc773703c1b7
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc773703c1b7 (not active ControlSet)
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- --- --- --- |