So, Schritt 2 ist auch durch, hier das Ergebnis:
Code:
Alles auswählen Aufklappen ATTFilter
GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2011-01-07 21:44:00
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdePort0 ExcelStor_Technology_J880 rev.PF2OA21B
Running: gmer.exe; Driver: C:\DOKUME~1\Karina\LOKALE~1\Temp\pgdorpow.sys
---- System - GMER 1.0.15 ----
SSDT B1116F16 ZwCreateKey
SSDT B1116F0C ZwCreateThread
SSDT B1116F1B ZwDeleteKey
SSDT B1116F25 ZwDeleteValueKey
SSDT B1116F2A ZwLoadKey
SSDT B1116EF8 ZwOpenProcess
SSDT B1116EFD ZwOpenThread
SSDT B1116F34 ZwReplaceKey
SSDT B1116F2F ZwRestoreKey
SSDT B1116F20 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF74883A4]
? C:\WINDOWS\system32\drivers\atapi.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF664A360, 0x20598D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[1292] ole32.dll!CoCreateInstance 774CFAC3 5 Bytes JMP 0094000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Programme\Logitech\LWS\Webcam Software\LWS.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC3880] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Programme\Logitech\LWS\Webcam Software\LWS.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC3930] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Programme\Logitech\LWS\Webcam Software\LWS.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AC3A60] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Programme\Logitech\LWS\Webcam Software\LWS.exe[772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC39D0] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00CD3880] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00CD3930] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00CD3A60] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00CD39D0] C:\WINDOWS\system32\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-17 866CE77F
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 866CE77F
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 866CE77F
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-f 866CE77F
Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskExcelStor_Technology_J880_______________PF2OA21B#5&3752888c&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sectors 160836377 (+101): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification; TDL3 <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----