Code:
Hallo!
Ich habe vor längerer Zeit ein Forum eröffnet wegen einem Virenalarm an meinem Laptop Windows 7 ... Leider war ich längere Zeit nicht mehr online, weshalb das Thema geschlossen wurde. Ich habe aber das Programm heute durchlaufen lassen. Das Ergebnis:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-21 13:20:04
Windows 6.1.7600
Running: zu33b87y.exe; Driver: C:\Users\Test\AppData\Local\Temp\pxtyipoc.sys
---- System - GMER 1.0.15 ----
SSDT 807EB63C ZwCreateThread
SSDT 807EB628 ZwOpenProcess
SSDT 807EB62D ZwOpenThread
SSDT 807EB637 ZwTerminateProcess
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83023AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83023104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830233F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8300C2D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8300B898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830231DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83023958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830236F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83023F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830241A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwSaveKeyEx + 13B1 830758E9 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 830953D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 14C3 8309C790 4 Bytes [3C, B6, 7E, 80] {CMP AL, 0xb6; JLE 0xffffffffffffff84}
.text ntoskrnl.exe!KeRemoveQueueEx + 165F 8309C92C 4 Bytes [28, B6, 7E, 80]
.text ntoskrnl.exe!KeRemoveQueueEx + 167F 8309C94C 4 Bytes [2D, B6, 7E, 80]
.text ntoskrnl.exe!KeRemoveQueueEx + 192F 8309CBFC 4 Bytes [37, B6, 7E, 80]
? C:\windows\system32\facc.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. !
.text peauth.sys 8E5E9C9D 28 Bytes [DE, DA, C9, 9B, 76, EE, 79, ...]
.text peauth.sys 8E5E9CC1 28 Bytes [DE, DA, C9, 9B, 76, EE, 79, ...]
PAGE peauth.sys 8E5EFB9B 72 Bytes [0E, 96, CB, 3B, 2A, 60, 98, ...]
PAGE peauth.sys 8E5EFBEC 111 Bytes [67, 47, 7A, AD, AC, 7F, FB, ...]
PAGE peauth.sys 8E5EFE20 101 Bytes [E6, 73, 88, E6, C1, B0, 49, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1632] ntdll.dll!LdrLoadDll 77D6F625 5 Bytes JMP 00F213F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74932494] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74915624] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [749156E2]
C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipFree] [7493250F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74928573] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74924D27] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [749250CE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [749251A3] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [749266D0] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [749282CA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74928819] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7492907A] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7492E21D] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[2284] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74924C59] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144cc f1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp facc.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Vielen Dank schonmal im Voraus für die Hilfe!