ausdemFF | 22.11.2011 22:07 | Hui, jetzt gings voll Fix :)
[CODE]
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-11-22 22:06:46
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-5 MAXTOR_STM3250310AS rev.4.AAA
Running: l1mtzr72.exe; Driver: C:\Users\MARCEL~1\AppData\Local\Temp\kwliaaow.sys
---- System - GMER 1.0.15 ----
SSDT 90CE8ABE ZwCreateSection
SSDT 90CE8A96 ZwCreateSymbolicLinkObject
SSDT 90CE8A9B ZwLoadDriver
SSDT 90CE8A91 ZwOpenSection
SSDT 90CE8AC8 ZwRequestWaitReplyPort
SSDT 90CE8AC3 ZwSetContextThread
SSDT 90CE8ACD ZwSetSecurityObject
SSDT 90CE8AA0 ZwSetSystemInformation
SSDT 90CE8AD2 ZwSystemDebugControl
SSDT 90CE8A5F ZwTerminateProcess
SSDT 90CE8A5A ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C7B349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB4D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82CBBEAC 4 Bytes [BE, 8A, CE, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11FF 82CBBEB4 4 Bytes [96, 8A, CE, 90] {XCHG ESI, EAX; MOV CL, DH; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1313 82CBBFC8 4 Bytes [9B, 8A, CE, 90] {WAIT ; MOV CL, DH; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 13AF 82CBC064 4 Bytes [91, 8A, CE, 90] {XCHG ECX, EAX; MOV CL, DH; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82CBC208 4 Bytes [C8, 8A, CE, 90] {ENTER 0xce8a, 0x90}
.text ...
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [746C2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [746A5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [746A56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [746C24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [746B8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [746B4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [746B506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [746B5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [746B6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [746B826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [746B87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [746B901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [746BE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2328] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [746B4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000058 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume9 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \Driver\tdx \Device\RawIp avfwot.sys (TDI filtering kernel driver/Avira GmbH)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{721F34D6-177E-0B5A-100D-6F2E2FB2D6A9}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{721F34D6-177E-0B5A-100D-6F2E2FB2D6A9}@hagdjmlmbgfojoff 0x6A 0x61 0x61 0x63 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{721F34D6-177E-0B5A-100D-6F2E2FB2D6A9}@iamcdoknakfgojhdhg 0x6A 0x61 0x61 0x63 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A225EC91-5397-517E-C9B1-973E71617067}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A225EC91-5397-517E-C9B1-973E71617067}@iaecmhkjhjfchkkjhp 0x6B 0x61 0x69 0x64 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A225EC91-5397-517E-C9B1-973E71617067}@hakbgomlhamfaklm 0x6B 0x61 0x69 0x64 ...
---- EOF - GMER 1.0.15 ---- --- --- --- |