| | # 3 |
| Registriert seit: 30.07.2007 Ort: Deutschlands größter Golfplatz
Beiträge: 920
| Du übernimmst, SaraSchnegge? GMER - Rootkit Detection
![]()
ciao, andreas |
|
| | # 6 |
| Threadstarter Registriert seit: 22.03.2009
Beiträge: 40
| GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2009-03-22 18:20:46 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.14 ---- Code 8A0877B8 ZwEnumerateKey Code 89E61190 ZwFlushInstructionCache Code 89F77116 IofCallDriver Code 8A04EAF6 IofCompleteRequest ---- Kernel code sections - GMER 1.0.14 ---- .text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89F7711B .text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A04EAFB ? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.14 ---- .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 11, 84 ] .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BB, 84 ] .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 85 ] .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, C1, 84 ] .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B4, 84 ] .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5E, 84 ] .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7B, 84 ] .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 2F, 86 ] .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 47, 84 ] .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 1F, 84 ] .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, D6, 86 ] .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 0049ECC0 C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7E, 84 ] .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 8F, 85 ] .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 12, 84 ] .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0A, 85 ] .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B9, 84 ] .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 84 ] .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 4B, 86 ] .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 88, 84 ] .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 32, 84 ] .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 57, 84 ] .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 42, 84 ] .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 37, 85 ] .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 004DE392 C:\Programme\MSN Messenger\MsnMsgr.Exe (Messenger/Microsoft Corporation) ---- Modules - GMER 1.0.14 ---- Module \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys (*** hidden *** ) B6E59000-B6E70000 (94208 bytes) ---- Services - GMER 1.0.14 ---- Service C:\WINDOWS\system32\drivers\gaopdxppxlrxsmyojeohpe jepvaqcwodgamduw.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <-- ROOTKIT !!! ---- Registry - GMER 1.0.14 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@group file system Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ start 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ type 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ group file system Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll ---- EOF - GMER 1.0.14 ---- -----Doppelpost zusammengeführt am 22.3.2009 um 18:24:57----- GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2009-03-22 18:24:31 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.14 ---- Code 8A0877B8 ZwEnumerateKey Code 89E61190 ZwFlushInstructionCache Code 89F77116 IofCallDriver Code 8A04EAF6 IofCompleteRequest ---- Kernel code sections - GMER 1.0.14 ---- .text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89F7711B .text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A04EAFB ? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.14 ---- .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 11, 84 ] .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BB, 84 ] .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 85 ] .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, C1, 84 ] .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B4, 84 ] .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5E, 84 ] .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7B, 84 ] .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 2F, 86 ] .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 47, 84 ] .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 1F, 84 ] .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, D6, 86 ] .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 0049ECC0 C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7E, 84 ] .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 8F, 85 ] .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 12, 84 ] .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0A, 85 ] .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B9, 84 ] .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 84 ] .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 4B, 86 ] .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 88, 84 ] .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 32, 84 ] .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 57, 84 ] .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 42, 84 ] .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 37, 85 ] .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 004DE392 C:\Programme\MSN Messenger\MsnMsgr.Exe (Messenger/Microsoft Corporation) ---- Modules - GMER 1.0.14 ---- Module \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys (*** hidden *** ) B6E59000-B6E70000 (94208 bytes) ---- Services - GMER 1.0.14 ---- Service C:\WINDOWS\system32\drivers\gaopdxppxlrxsmyojeohpe jepvaqcwodgamduw.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <-- ROOTKIT !!! ---- Registry - GMER 1.0.14 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@group file system Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ start 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ type 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ group file system Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll ---- EOF - GMER 1.0.14 ---- -----Doppelpost zusammengeführt am 22.3.2009 um 18:26:18----- GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2009-03-22 18:25:51 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.14 ---- Code 8A0877B8 ZwEnumerateKey Code 89E61190 ZwFlushInstructionCache Code 89F77116 IofCallDriver Code 8A04EAF6 IofCompleteRequest ---- Kernel code sections - GMER 1.0.14 ---- .text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89F7711B .text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A04EAFB ? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.14 ---- .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 11, 84 ] .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe[304] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BB, 84 ] .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 85 ] .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, C1, 84 ] .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B4, 84 ] .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\lsass.exe[740] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5E, 84 ] .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7B, 84 ] .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[960] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 2F, 86 ] .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\System32\svchost.exe[1072] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 47, 84 ] .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 1F, 84 ] .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, D6, 86 ] .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe[1324] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 0049ECC0 C:\Programme\Tobit ClipInc\Server\ClipInc-Server.exe .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7E, 84 ] .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\spoolsv.exe[1376] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 8F, 85 ] .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jqs.exe[1672] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 12, 84 ] .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\nvsvc32.exe[1684] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0A, 85 ] .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\Explorer.EXE[1724] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B9, 84 ] .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\PC Tools AntiVirus\PCTAV.exe[1800] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 5A, 84 ] .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\RUNDLL32.EXE[1840] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 4B, 86 ] .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe[1848] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 88, 84 ] .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe[1860] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 32, 84 ] .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Winamp\winampa.exe[1868] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 57, 84 ] .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\Java\jre6\bin\jusched.exe[1884] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 42, 84 ] .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\ctfmon.exe[1924] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 37, 85 ] .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetStartupInfoA 7C801EF2 6 Bytes JMP 5F0A0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!CreateMutexA 7C80E9CF 6 Bytes JMP 5F040F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!GetCommandLineA 7C812FAD 6 Bytes JMP 5F0D0F5A .text C:\Programme\MSN Messenger\MsnMsgr.Exe[1944] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 004DE392 C:\Programme\MSN Messenger\MsnMsgr.Exe (Messenger/Microsoft Corporation) ---- Modules - GMER 1.0.14 ---- Module \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys (*** hidden *** ) B6E59000-B6E70000 (94208 bytes) ---- Services - GMER 1.0.14 ---- Service C:\WINDOWS\system32\drivers\gaopdxppxlrxsmyojeohpe jepvaqcwodgamduw.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <-- ROOTKIT !!! ---- Registry - GMER 1.0.14 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys@group file system Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv. sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ start 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ type 1 Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ imagepath \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@ group file system Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxp pxlrxsmyojeohpejepvaqcwodgamduw.sys Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\ modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxiatcwoacj sgxmxedjtnjenyxikwtdhsx.dll ---- EOF - GMER 1.0.14 ---- -----Doppelpost zusammengeführt am 22.3.2009 um 18:30:08----- WARNING Gmer has found any System Modifikation kam jedesmal wenn eine platte fertig gescannt war |
|
| | # 7 |
| Registriert seit: 30.07.2007 Ort: Deutschlands größter Golfplatz
Beiträge: 920
| Anleitung Avenger (by swandog46) Lade dir das Tool Hopsassa und speichere es auf dem Desktop:
Code: Drivers to delete: gaopdxserv.sys Registry keys to delete: HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys Files to delete: C:\WINDOWS\gaopdxcounter C:\WINDOWS\system32\drivers\gaopdxppxlrxsmyojeohpejepvaqcwodgamduw.sys C:\WINDOWS\system32\gaopdxiatcwoacjsgxmxedjtnjenyxikwtdhsx.dll ![]()
Nachdem du das durchgeführt hast, wird es deinem Rechner spürbar besser gehen. ciao, andreas |
|
| | # 12 |
| Threadstarter Registriert seit: 22.03.2009
Beiträge: 40
| ihr seit hammer 1000 tank echt ... ok ich klink mich dann mal aus und folge deiner bzw der avenger anweisung bis später -----Doppelpost zusammengeführt am 22.3.2009 um 19:03:26----- Logfile of The Avenger Version 2.0, (c) by Swandog46 Swandog46's Public Anti-Malware Tools Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. Hidden driver "gaopdxserv.sys" found! ImagePath: \systemroot\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys Start Type: 4 (Disabled) Rootkit scan completed. Driver "gaopdxserv.sys" deleted successfully. Registry key "HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys " deleted successfully. Error: file "C:\WINDOWS\gaopdxcounter" not found! Deletion of file "C:\WINDOWS\gaopdxcounter" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\drivers\gaopdxppxlrxsmyojeohp ejepvaqcwodgamduw.sys" deleted successfully. File "C:\WINDOWS\system32\gaopdxiatcwoacjsgxmxedjtnjeny xikwtdhsx.dll" deleted successfully. Completed script processing. ******************* Finished! Terminate. aber komme immer noch nicht auf meine platten -----Doppelpost zusammengeführt am 22.3.2009 um 19:09:42----- das recycle teil ist immer noch da *megaheul* |
|
| | # 13 |
| Registriert seit: 30.07.2007 Ort: Deutschlands größter Golfplatz
Beiträge: 920
| Du weißt noch gar nicht, was für ein fieses Teil du auf dem Rechner hast, schau doch mal hier vorbei. Falls du irgendetwas hast, das du mit dem Computer verbindest, wie SD-Karten, Kamera, Memorysticks, externe Datenträger, ... so hänge vor dem Scan alle an. ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden wenn ein Kompetenzler dies ausdrücklich empfohlen hat!Hinweis: Combofix verhindert die Autostart Funktion aller CD / DVD und USB - Laufwerken um so eine Verbeitung einzudämmen. Wenn es hierdurch zu Problemen kommt, diese im Thread posten. ciao, andreas |
|
| | # 15 |
| Registriert seit: 30.07.2007 Ort: Deutschlands größter Golfplatz
Beiträge: 920
| Ja, alles, was jemals am Rechner gehangen hat, muss dran sein. Ansonsten infizierst du dich sofort wieder. Hier habe ich gerade einen aktuellen Fall, der genialerweise den Rechner seines Vaters infiziert hat: XP Prof. fehlermeldung!!!! XP Prof. fehlermeldung!!!! ciao, andreas |
|










