Hallo Petra hier nun das logfile oder codetags. keine ahnung was ich hier mache, grins. hoffe es ist richtig.
Code:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-31 17:21:54
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD25 rev.01.0
Running: wdfbml0j.exe; Driver: C:\Users\MARKRE~1\AppData\Local\Temp\fwliipog.sys
---- System - GMER 1.0.15 ----
SSDT C473923E ZwCreateSection
SSDT C4739248 ZwRequestWaitReplyPort
SSDT C4739243 ZwSetContextThread
SSDT C473924D ZwSetSecurityObject
SSDT C4739252 ZwSystemDebugControl
SSDT C47391DF ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 215 824F28D8 4 Bytes [3E, 92, 73, C4]
.text ntkrnlpa.exe!KeSetEvent + 539 824F2BFC 4 Bytes [48, 92, 73, C4] {DEC EAX; XCHG EDX, EAX; JAE 0xffffffffffffffc8}
.text ntkrnlpa.exe!KeSetEvent + 56D 824F2C30 4 Bytes [43, 92, 73, C4] {INC EBX; XCHG EDX, EAX; JAE 0xffffffffffffffc8}
.text ntkrnlpa.exe!KeSetEvent + 5D1 824F2C94 4 Bytes [4D, 92, 73, C4] {DEC EBP; XCHG EDX, EAX; JAE 0xffffffffffffffc8}
.text ntkrnlpa.exe!KeSetEvent + 619 824F2CDC 4 Bytes [52, 92, 73, C4] {PUSH EDX; XCHG EDX, EAX; JAE 0xffffffffffffffc8}
.text ...
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ???rt????? ??p??????p???Miniporttreiber f?r erweiterten Microsoft USB 2.0-Hostcontroller?U??system32\DRIVERS\usbehci.sys?usbehci.sys????????????????????????????????????t????????????????????r?r?r?r?r?r?r?????????????g????system32\DRIVERS\usbhub.sys?\usbhub.sys?????????????????????????????????????t????????????????????r?r?r?r?r?r?r?????????????g??????|??r?????????e?????? ??L??????p?????:??r????????h????????????r?&??Microsoft????????r??????La?????r?????r??wsdprint.inf:Microsoft.NTx86...1:WSDPrint_Device:6.0.6002.18005:umb\http://schemas.microsoft.com/windows/2006/08/wdp/print/printerservicetype????????????????h?????q#????r???r??? ???r???5??????nA??6.0.6002.18005?FD ??@wsdprint.inf,%wsdprintdevice.devicedesc%;WSD-Druckger?t????? ?????????????r??????????????????(?&????????????????????1???????r???C?????????????r?????????r??????s???USB2-aktivierter Hub?dhubtreiber?????? ??L??????p?????8??r????????h?????Miniporttreiber f?r universellen Microsoft USB-Hostcontroller???system32\DRIVERS\usbuhci.sys?usbuhci.sys???????????
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C6B56403F35B1A94E9AB3A1F78DA05E2\Usage@SoleFeature 1090471200
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB47909$\1031484148 0 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451 0 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\@ 2048 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\cfg.ini 46 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\L 0 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\L\qnbwvoto 67072 bytes
File C:\Windows\$NtUninstallKB47909$\1903610451\U 0 bytes
---- EOF - GMER 1.0.15 ----
Lesezeichen