GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-06-29 16:06:47
Windows 5.1.2600 Service Pack 3
Running: 18kkkchz.exe; Driver: C:\DOKUME~1\Guido\LOKALE~1\Temp\kwxyipod.sys
---- System - GMER 1.0.15 ----
SSDT F7A7094E ZwCreateKey
SSDT F7A70944 ZwCreateThread
SSDT F7A70953 ZwDeleteKey
SSDT F7A7095D ZwDeleteValueKey
SSDT F7A70962 ZwLoadKey
SSDT F7A70930 ZwOpenProcess
SSDT F7A70935 ZwOpenThread
SSDT F7A7096C ZwReplaceKey
SSDT F7A70967 ZwRestoreKey
SSDT F7A70958 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
? miwsb.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text C:\Programme\Mozilla Firefox\firefox.exe[300] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00FF000A
.text C:\Programme\Mozilla Firefox\firefox.exe[300] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 0100000A
.text C:\Programme\Mozilla Firefox\firefox.exe[300] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00FE000C
.text C:\WINDOWS\system32\wuauclt.exe[752] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 003F000A
.text C:\WINDOWS\system32\wuauclt.exe[752] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 0083000A
.text C:\WINDOWS\system32\wuauclt.exe[752] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 003E000C
.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 0071000A
.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 0072000A
.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 0070000C
.text C:\WINDOWS\System32\svchost.exe[1024] ole32.dll!CoCreateInstance 774D057E 5 Bytes JMP 00C7000A
.text C:\WINDOWS\Explorer.EXE[1452] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00A7000A
.text C:\WINDOWS\Explorer.EXE[1452] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00AD000A
.text C:\WINDOWS\Explorer.EXE[1452] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00A6000C
.text C:\Programme\Mozilla Firefox\plugin-container.exe[2344] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 104505FE C:\Programme\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----