Und hier die
GMER Logdatei Teil1
Code:
Alles auswählen Aufklappen ATTFilter
GMER 1.0.15.14878 - http://www.gmer.net
Rootkit scan 2009-03-11 17:06:43
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT F7A614E4 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.) ZwMapViewOfSection [0xF78788D0]
SSDT F7A614D0 ZwOpenProcess
SSDT F7A614D5 ZwOpenThread
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.) ZwShutdownSystem [0xF7878E70]
SSDT F7A614DF ZwTerminateProcess
SSDT F7A614DA ZwWriteVirtualMemory
Code \??\C:\WINDOWS\system32\drivers\winebgn.sys ZwResumeThread [0xF49E51F4]
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!ZwResumeThread 805D31FE 7 Bytes JMP F49E51F8 \??\C:\WINDOWS\system32\drivers\winebgn.sys
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\spoolsv.exe[232] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\spoolsv.exe[232] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\spoolsv.exe[232] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\spoolsv.exe[232] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\spoolsv.exe[232] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\spoolsv.exe[232] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\Programme\Java\jre6\bin\jusched.exe[276] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\Programme\Java\jre6\bin\jusched.exe[276] WS2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\Programme\Java\jre6\bin\jusched.exe[276] WS2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\Programme\Java\jre6\bin\jusched.exe[276] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\Programme\Java\jre6\bin\jusched.exe[276] WS2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\Programme\Java\jre6\bin\jusched.exe[276] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\WINDOWS\system32\nvsvc32.exe[300] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 107731F8
.text C:\WINDOWS\system32\nvsvc32.exe[300] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10773140
.text C:\WINDOWS\system32\nvsvc32.exe[300] ws2_32.dll!send 71A1428A 5 Bytes JMP 10772BA4
.text C:\WINDOWS\system32\nvsvc32.exe[300] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10772404
.text C:\WINDOWS\system32\nvsvc32.exe[300] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10772388
.text C:\WINDOWS\system32\nvsvc32.exe[300] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 107730F4
.text C:\WINDOWS\system32\ctfmon.exe[456] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\ctfmon.exe[456] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\ctfmon.exe[456] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\ctfmon.exe[456] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\ctfmon.exe[456] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\ctfmon.exe[456] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100131F8
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] WS2_32.dll!connect 71A1406A 5 Bytes JMP 10013140
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] WS2_32.dll!send 71A1428A 5 Bytes JMP 10012BA4
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 10012404
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] WS2_32.dll!recv 71A1615A 5 Bytes JMP 10012388
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe[492] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100130F4
.text C:\WINDOWS\system32\winlogon.exe[800] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\winlogon.exe[800] WS2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\winlogon.exe[800] WS2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\winlogon.exe[800] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\winlogon.exe[800] WS2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\winlogon.exe[800] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\WINDOWS\system32\services.exe[844] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\services.exe[844] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\services.exe[844] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\services.exe[844] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\services.exe[844] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\services.exe[844] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\WINDOWS\system32\lsass.exe[856] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\lsass.exe[856] WS2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\lsass.exe[856] WS2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\lsass.exe[856] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\lsass.exe[856] WS2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\lsass.exe[856] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\WINDOWS\system32\svchost.exe[1020] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\svchost.exe[1020] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\svchost.exe[1020] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\svchost.exe[1020] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\svchost.exe[1020] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\svchost.exe[1020] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\WINDOWS\System32\svchost.exe[1228] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\System32\svchost.exe[1228] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\System32\svchost.exe[1228] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\System32\svchost.exe[1228] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\System32\svchost.exe[1228] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\System32\svchost.exe[1228] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\Programme\XpertVision\TBPanel.exe[1376] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 107731F8
.text C:\Programme\XpertVision\TBPanel.exe[1376] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10773140
.text C:\Programme\XpertVision\TBPanel.exe[1376] ws2_32.dll!send 71A1428A 5 Bytes JMP 10772BA4
.text C:\Programme\XpertVision\TBPanel.exe[1376] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10772404
.text C:\Programme\XpertVision\TBPanel.exe[1376] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10772388
.text C:\Programme\XpertVision\TBPanel.exe[1376] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 107730F4
.text C:\Programme\Sygate\SPF\smc.exe[1428] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100D31F8
.text C:\Programme\Sygate\SPF\smc.exe[1428] WS2_32.dll!connect 71A1406A 5 Bytes JMP 100D3140
.text C:\Programme\Sygate\SPF\smc.exe[1428] WS2_32.dll!send 71A1428A 5 Bytes JMP 100D2BA4
.text C:\Programme\Sygate\SPF\smc.exe[1428] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 100D2404
.text C:\Programme\Sygate\SPF\smc.exe[1428] WS2_32.dll!recv 71A1615A 5 Bytes JMP 100D2388
.text C:\Programme\Sygate\SPF\smc.exe[1428] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100D30F4
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100631F8
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10063140
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] ws2_32.dll!send 71A1428A 5 Bytes JMP 10062BA4
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10062404
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10062388
.text C:\Programme\Analog Devices\Core\smax4pnp.exe[1508] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100630F4
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\Programme\Analog Devices\SoundMAX\Smax4.exe[1704] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100331F8
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10033140
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] ws2_32.dll!send 71A1428A 5 Bytes JMP 10032BA4
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10032404
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10032388
.text C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe[1716] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100330F4
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] ws2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] ws2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] ws2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] ws2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\WINDOWS\system32\RUNDLL32.EXE[1756] ws2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100031F8
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] WS2_32.dll!connect 71A1406A 5 Bytes JMP 10003140
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] WS2_32.dll!send 71A1428A 5 Bytes JMP 10002BA4
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 10002404
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] WS2_32.dll!recv 71A1615A 5 Bytes JMP 10002388
.text C:\Programme\Java\jre6\bin\jqs.exe[1984] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 100030F4