Das Resultat vom gmer-scan
Code:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-16 01:55:15
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 rev.
Running: zvoxn3gz.exe; Driver: C:\DOKUME~1\Holger\LOKALE~1\Temp\pgddipob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text redbook.sys F747A000 166 Bytes [C7, 45, EC, 00, 00, 00, 00, ...]
.text redbook.sys F747A0A7 54 Bytes [C7, 45, E0, 01, 00, 00, 00, ...]
.text redbook.sys F747A0DE 58 Bytes [B5, 47, F7, 51, 8B, 15, 08, ...]
.text redbook.sys F747A11A 17 Bytes [8B, 4D, 08, C7, 41, 78, 00, ...]
.text redbook.sys F747A12E 2 Bytes [8B, 45]
.text ...
? C:\WINDOWS\System32\DRIVERS\redbook.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1344] ntdll.dll!NtProtectVirtualMemory 7C91D6D0 5 Bytes JMP 01F0000A
.text C:\WINDOWS\System32\svchost.exe[1344] ntdll.dll!NtWriteVirtualMemory 7C91DF90 5 Bytes JMP 01F1000A
.text C:\WINDOWS\System32\svchost.exe[1344] ntdll.dll!KiUserExceptionDispatcher 7C91E45C 5 Bytes JMP 01EF000C
? C:\WINDOWS\System32\svchost.exe[1344] C:\WINDOWS\System32\smss.exe image checksum mismatch; time/date stamp mismatch;
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mausklassentreiber/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 otman5.sys (Open Transaction Manager ®/Columbia Data Products, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 otman5.sys (Open Transaction Manager ®/Columbia Data Products, Inc.)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) F7546000-F7556000 (65536 bytes)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB46105$\2339851787 0 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305 0 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\cfg.ini 169 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\L 0 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\L\nnmhraur 57728 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\oemid 63 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U 0 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\80000000.@ 66560 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\U\80000032.@ 96256 bytes
File C:\WINDOWS\$NtUninstallKB46105$\3506988305\version 864 bytes
---- EOF - GMER 1.0.15 ----
Lesezeichen