babynator55 | 23.07.2013 01:21 | Ich weiß nicht ob GMER funktioniert hat. Es kam eine Fehlermeldung, dass der Prozess schon vewendet wird. Hab alles geschlossen, Internet getrennt und Antivirus aus. Ich füge den Log mal ein : Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-07-23 01:12:57
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000037 Hitachi_HTS545050A7E380 rev.GG2OA920 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\ANDRE_~1\AppData\Local\Temp\kgtorpob.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\system32\ntoskrnl.exe!KiCpuId + 988 fffff8016365741c 1 byte [31]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\dwm.exe[416] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\dwm.exe[416] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\dwm.exe[416] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe[1444] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fb5f071b32 4 bytes [07, 5F, FB, 07]
.text C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe[1444] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fb5f071b3a 4 bytes [07, 5F, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3376] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3376] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3376] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[3392] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[3392] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[3392] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[3392] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb65c2177a 4 bytes [C2, 65, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[3392] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb65c21782 4 bytes [C2, 65, FB, 07]
.text C:\Windows\system32\taskhostex.exe[3512] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\taskhostex.exe[3512] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\taskhostex.exe[3512] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\Explorer.EXE[3600] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\Explorer.EXE[3600] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\Explorer.EXE[3600] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\Explorer.EXE[3600] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fb5f071b32 4 bytes [07, 5F, FB, 07]
.text C:\Windows\Explorer.EXE[3600] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fb5f071b3a 4 bytes [07, 5F, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[3532] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[3532] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[3532] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3316] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3316] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3316] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\igfxext.exe[3244] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\igfxext.exe[3244] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\igfxext.exe[3244] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3552] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3552] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3552] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxtray.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxtray.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxtray.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\hkcmd.exe[2612] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\hkcmd.exe[2612] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\hkcmd.exe[2612] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxpers.exe[5100] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb65c2177a 4 bytes [C2, 65, FB, 07]
.text C:\Windows\System32\igfxpers.exe[5100] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb65c21782 4 bytes [C2, 65, FB, 07]
.text C:\Windows\System32\igfxpers.exe[5100] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxpers.exe[5100] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\System32\igfxpers.exe[5100] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2428] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2428] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2428] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4296] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4296] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4296] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4604] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4604] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtTray.exe[4604] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4960] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4960] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4960] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4960] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fb5f071b32 4 bytes [07, 5F, FB, 07]
.text c:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4960] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fb5f071b3a 4 bytes [07, 5F, FB, 07]
.text C:\Program Files\Elantech\ETDCtrl.exe[2904] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Elantech\ETDCtrl.exe[2904] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Elantech\ETDCtrl.exe[2904] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Dolby PCEE4\pcee4.exe[3540] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Dolby PCEE4\pcee4.exe[3540] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Dolby PCEE4\pcee4.exe[3540] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[4640] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[4640] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[4640] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5764] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb65c2177a 4 bytes [C2, 65, FB, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5764] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb65c21782 4 bytes [C2, 65, FB, 07]
.text C:\Windows\system32\igfxsrvc.exe[5992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\igfxsrvc.exe[5992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\igfxsrvc.exe[5992] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[5740] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[5740] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[5740] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[5888] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb61471532 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[5888] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb6147153a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[5888] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb6147165a 4 bytes [47, 61, FB, 07]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6940] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fb5f071b32 4 bytes [07, 5F, FB, 07]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6940] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fb5f071b3a 4 bytes [07, 5F, FB, 07]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [704:728] fffff960009cd5e8
Thread C:\Windows\system32\svchost.exe [576:3436] 000007fb5d666ba8
Thread C:\Windows\system32\svchost.exe [576:3440] 000007fb5d666794
Thread C:\Windows\system32\svchost.exe [1528:2920] 000007fb5d3e1544
Thread C:\Windows\system32\svchost.exe [1528:2952] 000007fb5d3355dc
Thread C:\Windows\system32\svchost.exe [1528:3088] 000007fb63064910
Thread C:\Windows\system32\svchost.exe [1528:6992] 000007fb63061044
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:4380] 000007fb685223a8
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:5912] 000007fb5da577b0
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:6864] 000007fb5da577b0
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:7088] 000007fb672c8c44
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:6228] 000007fb65f0c648
Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe [2876:6740] 000007fb64f35990
Thread C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [6376:6576] 00000000732397fe
Thread C:\Windows\SYSTEM32\ntdll.dll [6400:7140] 00000000004ca6be
Thread C:\Windows\SYSTEM32\ntdll.dll [6400:6516] 00000000732397fe
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- MBAR: Code:
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
Database version: v2013.07.22.09
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
andre_000 :: ANDRE [administrator]
23.07.2013 01:35:59
mbar-log-2013-07-23 (01-35-59).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 251074
Time elapsed: 35 minute(s), 27 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) |