Code:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-29 10:42:40
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Felix\AppData\Local\Temp\kwddipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x8973ABD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8973C52C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8973C782]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8973C9FC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8973B450]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x8973BB32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x8973BF3C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x8973B5F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x8973BE14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x8973A7D6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x8973BCD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8973A992]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8973C06E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0x8973DCB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x8973B0EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x8973B1EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x8973BD72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8973D6A2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8973E672]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x8973B752]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8973D734]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8973DD64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x8973BFDE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x8973B4D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x8973BEAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x8973ADD6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8973DCDA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8973C110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x8973ACFA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8973CC3E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8973E07C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8973D9CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8973C49A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8973C360]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8973D442]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8973E554]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x8973B86C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x8973B30C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8973CCF2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x8973D82E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8973E1BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8973E2A0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8973E3C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8973D5CE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x8973AF4E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x8973AEA4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8973DF32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8973B02E]
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302BAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83013634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83013898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302BF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302C1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C44579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C68F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 220 82C70720 4 Bytes [D0, AB, 73, 89]
.text ntkrnlpa.exe!RtlSidHashLookup + 248 82C70748 8 Bytes [2C, C5, 73, 89, 82, C7, 73, ...]
.text ntkrnlpa.exe!RtlSidHashLookup + 28C 82C7078C 4 Bytes [FC, C9, 73, 89] {CLD ; LEAVE ; JAE 0xffffffffffffff8d}
.text ntkrnlpa.exe!RtlSidHashLookup + 2B8 82C707B8 4 Bytes [50, B4, 73, 89]
.text ntkrnlpa.exe!RtlSidHashLookup + 2DC 82C707DC 4 Bytes JMP F6823A63
.text ...
? System32\Drivers\splf.sys Das System kann den angegebenen Pfad nicht finden. !
.text tcpip.sys 89479800 6 Bytes [00, 3B, 0D, CC, 9C, 52]
.text tcpip.sys 89479807 5 Bytes [0F, 85, 04, 01, 00]
.text tcpip.sys 8947980D 27 Bytes [56, 53, 33, C0, 53, FF, 75, ...]
.text tcpip.sys 89479829 42 Bytes [FF, 35, AC, 9C, 52, 89, 89, ...]
.text tcpip.sys 89479854 241 Bytes [E4, 29, 00, 00, 00, 53, 53, ...]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F601000, 0x23097E, 0xE8000020]
.text USBPORT.SYS!DllUnload 9006ECA0 5 Bytes JMP 862201D8
.text ajge80q9.SYS 9019C000 12 Bytes [44, 68, 01, 83, EE, 66, 01, ...] {INC ESP; PUSH 0x66ee8301; ADD [EBX-0x7cfeb860], EAX}
.text ajge80q9.SYS 9019C00D 9 Bytes [47, 01, 83, 48, 6B, 01, 83, ...] {INC EDI; ADD [EBX-0x7cfe94b8], EAX; ADD [EAX], AL}
.text ajge80q9.SYS 9019C017 103 Bytes [00, DE, 97, F9, 88, E6, 95, ...]
.text ajge80q9.SYS 9019C07F 66 Bytes [82, 03, E4, C0, 82, E3, E4, ...]
.text ajge80q9.SYS 9019C0C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text peauth.sys 9E817C9D 28 Bytes [15, 9A, 09, 0C, 13, 24, A6, ...]
.text peauth.sys 9E817CC1 28 Bytes [15, 9A, 09, 0C, 13, 24, A6, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[784] ole32.dll!CoCreateInstance 771657FC 5 Bytes JMP 001D000A
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88E9D042] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88E9D6D6] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88E9D800] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88E9D13E] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortNotification] 000003E3
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortQuerySystemTime] 8B24568B
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortReadPortUchar] 50522046
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortStallExecution] FFEC9FE8
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortWritePortUchar] 08C483FF
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortWritePortUlong] 0874FF85
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortGetPhysicalAddress] FF53006A
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 08C483D7
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortGetScatterGatherList] 81107D8B
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortGetParentBusType] 0003E5FF
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortRequestCallback] 0F840F00
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 81000001
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0003E3FF
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortCompleteRequest] EC840F00
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortCopyMemory] 8B000000
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortEtwTraceLog] 0001F88E
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] FC8E0B00
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 0F000001
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 0000DA84
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortReadPortBufferUshort] ECD8E800
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortInitialize] [8E8BFFFF] \SystemRoot\system32\DRIVERS\HSX_CNXT.sys (HSF_CNXT driver/Conexant Systems, Inc.)
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortGetDeviceBase] 000001F8
IAT \SystemRoot\System32\Drivers\ajge80q9.SYS[ataport.SYS!AtaPortDeviceStateChange] 01E08E01
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 850921F8
Device \Driver\volmgr \Device\VolMgrControl 8508E1F8
Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 862231F8
Device \Driver\usbuhci \Device\USBPDO-1 862231F8
Device \Driver\usbuhci \Device\USBPDO-2 862231F8
Device \Driver\usbuhci \Device\USBPDO-3 862231F8
Device \Driver\usbehci \Device\USBPDO-4 86228500
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\volmgr \Device\HarddiskVolume1 8508E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 860B51F8
Device \Driver\volmgr \Device\HarddiskVolume2 8508E1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 860B51F8
Device \Driver\atapi \Device\Ide\IdePort0 850901F8
Device \Driver\atapi \Device\Ide\IdePort1 850901F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 850901F8
Device \Driver\sptd \Device\2615796507 splf.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 860981F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{942260DC-B112-47A5-BEB2-703FAAB3E4CC} 860981F8
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\PCI_PNP4505 \Device\0000005e splf.sys
Device \Driver\usbuhci \Device\USBFDO-0 862231F8
Device \Driver\usbuhci \Device\USBFDO-1 862231F8
Device \Driver\usbuhci \Device\USBFDO-2 862231F8
Device \Driver\usbuhci \Device\USBFDO-3 862231F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{BDEF348B-6F5C-4CD1-A5AB-0CB39E7F9BEF} 860981F8
Device \Driver\usbehci \Device\USBFDO-4 86228500
Device \Driver\ajge80q9 \Device\Scsi\ajge80q91 862D61F8
Device \Driver\ajge80q9 \Device\Scsi\ajge80q91Port2Path0Target0Lun0 862D61F8
Device -> \Driver\atapi \Device\Harddisk0\DR0 85E1F856
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x64 0x01 0xBB 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x35 0x77 0xFC 0x8D ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x87 0xB7 0x59 0x5A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x64 0x01 0xBB 0x3A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x35 0x77 0xFC 0x8D ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x87 0xB7 0x59 0x5A ...
---- Files - GMER 1.0.15 ----
File C:\Windows\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----
Code:
Adobe After Effects CS4 Adobe Systems Incorporated 23.11.2009 1.615,2MB 9
Adobe After Effects CS4 Third Party Content Adobe Systems Incorporated 23.11.2009 86,9MB 9
Adobe AIR Adobe Systems Inc. 23.11.2009 1.1.0.5790
Adobe Creative Suite 3 Design Premium hinzufügen oder entfernen Adobe Systems Incorporated 02.10.2009 3.789,0MB 1.0
Adobe ExtendScript Toolkit 2 Adobe Systems Incorporated 18.10.2009 16,4MB 2.0.2
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 30.09.2009 10.0.32.18
Adobe Flash Player 10 Plugin Adobe Systems Incorporated 30.12.2009 10.0.42.34
Adobe Flash Player 9 ActiveX Adobe Systems, Inc. 02.10.2009 2,66MB 9.0.45.0
Adobe Media Player Adobe Systems Incorporated 23.11.2009 1.1
Adobe Reader 9.2 - Deutsch Adobe Systems Incorporated 23.11.2009 161,3MB 9.2.0
Apple Application Support Apple Inc. 23.11.2009 32,4MB 1.1.0
Apple Software Update Apple Inc. 23.11.2009 2,16MB 2.1.1.116
Apple Time Fix for Hackintosh Valter 16.10.2009 1.0
Canon MP Navigator EX 1.0 21.10.2009
Canon MP610 series 21.10.2009
Canon Utilities My Printer 21.10.2009
CCleaner Piriform 28.01.2010 2.28
Cisco Systems VPN Client 5.0.05.0290 Cisco Systems, Inc. 19.10.2009 12,3MB 5.0.5
Conexant HDA D110 MDC V.92 Modem 30.09.2009
ConvertXtoDVD 4.0.5.315 21.11.2009 4.0.5.315
Creative WebCam Vista/Live! Cam Chat Driver (1.11.01.00) 02.10.2009
DivX Plus Web Player DivX,Inc. 26.11.2009 2.0.0
DVD Decrypter (Remove Only) 18.10.2009
E.V.O.L.U.T.I.O.N. Patch 2009 1.00 09.11.2009
FileZilla Client 3.3.1 18.01.2010 3.3.1
GoldWave v5.54 19.01.2010
HiJackThis Trend Micro 26.01.2010 0,36MB 1.0.0
Holomatrix 01.12.2009
Java(TM) 6 Update 17 Sun Microsystems, Inc. 01.10.2009 95,0MB 6.0.170
Kaspersky Internet Security 2010 Kaspersky Lab 26.01.2010 9.0.0.736
Microsoft Office Enterprise 2007 Microsoft Corporation 01.10.2009 12.0.6215.1000
Microsoft Silverlight Microsoft Corporation 06.10.2009 14,9MB 3.0.40818.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 14.10.2009 0,41MB 8.0.56336
Microsoft – Speichern als PDF oder XPS – Add-In für 2007 Microsoft Office-Programme Microsoft Corporation 15.11.2009 0,13MB 12.0.4518.1014
Mozilla Firefox (3.6) Mozilla 25.01.2010 3.6 (de)
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 15.10.2009 1,28MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 24.11.2009 1,33MB 4.20.9876.0
Nero 9 Nero AG 14.10.2009
Notepad++ 18.01.2010 5.6.4
Pdf995 17.01.2010
PdfEdit995 17.01.2010
Pro Evolution Soccer 2009 KONAMI 09.11.2009 3.400,0MB 1.20.0000
QIP Infium 9032 Jeak-Edition jeak.de 08.10.2009 16,0MB 2.0.9032
QuickTime Apple Inc. 23.11.2009 77,3MB 7.65.17.80
Red Giant ToonIt 23.11.2009
Security Task Manager 1.7h Neuber GmbH 26.01.2010 1.7h
Signature995 17.01.2010
Skype™ 4.1 Skype Technologies S.A. 02.10.2009 31,1MB 4.1.166
SparVoip Finarea S.A. Switzerland 11.10.2009 4.03 build 546
Spelling Dictionaries Support For Adobe Reader 9 Adobe Systems Incorporated 23.11.2009 29,7MB 9.0.0
TextPad 5 Helios 21.11.2009 6,63MB 5.3.1
VLC media player 1.0.3 VideoLAN Team 26.11.2009 1.0.3
Winamp Nullsoft, Inc 11.12.2009 5.56
WinRAR archiver 01.10.2009
Xilisoft Video Converter Ultimate Xilisoft 27.01.2010 5.1.26.1211
Ich hoffe, Ihr könnt aus dem Code auf die Ursache schließen.