![]() |
|
Log-Analyse und Auswertung: Trojaner an BoardWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Trojaner an Board Guten Morgen zusammen!ich erhalte eine Meldung ihr System ist ausgelastet.dann öffnet sich ein Fenster und nichts geht mehr.Ich soll irgendeine Summe zahlen.Mein Virenscanner Antivir wurde gestoppt.ich habe Windows 2000 Professional.Würde mich über Hilfe freuen.gruss seifi Hier noch ein AnhangOTL Logfile: Code:
ATTFilter OTL logfile created on: 27.12.2011 10:17:38 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation Internet Explorer (Version = 6.0.2800.1106) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 895,23 Mb Total Physical Memory | 783,85 Mb Available Physical Memory | 87,56% Memory free 2,14 Gb Paging File | 2,07 Gb Available in Paging File | 96,66% Paging File free Paging file location(s): C:\pagefile.sys 1344 2688 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Programme Drive C: | 74,52 Gb Total Space | 65,17 Gb Free Space | 87,45% Space Free | Partition Type: NTFS Computer Name: AP-SEIFERT | User Name: Seifert | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.12.27 10:15:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner\OTL.exe PRC - [2003.06.19 11:05:04 | 000,245,008 | ---- | M] (Microsoft Corporation) -- C:\WINNT\explorer.exe PRC - [2003.06.19 11:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\wbem\WinMgmt.exe ========== Modules (No Company Name) ========== MOD - [2008.05.02 05:15:37 | 000,010,240 | ---- | M] () -- C:\Programme\Unlocker\UnlockerCOM.dll MOD - [2007.11.09 04:52:00 | 000,466,944 | ---- | M] () -- C:\WINNT\system32\nvshell.dll ========== Win32 Services (SafeList) ========== SRV - [2011.06.29 12:29:16 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.28 09:25:34 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008.02.04 13:37:12 | 000,413,746 | ---- | M] (SafeNet) [Auto | Stopped] -- C:\Programme\Juniper\NetScreen-Remote\IreIKE.exe -- (IreIKE) SRV - [2008.02.04 13:37:12 | 000,073,782 | ---- | M] (SafeNet) [Auto | Stopped] -- C:\Programme\Juniper\NetScreen-Remote\IPSecMon.exe -- (IPSECMON) SRV - [2005.06.03 07:37:10 | 000,123,152 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINNT\system32\mstask.exe -- (Schedule) SRV - [2005.03.15 12:14:42 | 000,041,984 | ---- | M] (Advanced Micro Devices) [Auto | Stopped] -- C:\Programme\AMD\Cool'n'Quiet\GemServ.exe -- (GemServ) AMD PowerNow! (tm) SRV - [2003.07.28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2003.06.19 11:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\wbem\WinMgmt.exe -- (WinMgmt) SRV - [2003.06.19 11:05:04 | 000,147,728 | ---- | M] (VERITAS Software Corp.) [On_Demand | Stopped] -- C:\WINNT\System32\dmadmin.exe -- (dmadmin) SRV - [2003.06.19 11:05:04 | 000,096,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\FAXSVC.EXE -- (Fax) SRV - [2003.06.19 11:05:04 | 000,068,368 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINNT\system32\regsvc.exe -- (RemoteRegistry) SRV - [2003.06.19 11:05:04 | 000,022,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\utilman.exe -- (UtilMan) ========== Driver Services (SafeList) ========== DRV - [2011.06.29 12:29:17 | 000,135,896 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\avipbb.sys -- (avipbb) DRV - [2011.06.29 12:29:17 | 000,078,216 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINNT\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2010.07.07 10:16:20 | 000,058,000 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\System32\drivers\cdr4_2K.sys -- (Cdr4_2K) DRV - [2010.07.07 10:16:20 | 000,023,420 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\System32\drivers\cdralw2k.sys -- (Cdralw2k) DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.02.13 10:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008.02.04 13:29:14 | 000,138,296 | ---- | M] (SafeNet) [Kernel | System | Running] -- C:\WINNT\system32\drivers\IpSecDrv.sys -- (IPSECDRV) DRV - [2008.01.17 10:35:44 | 000,536,634 | ---- | M] (SafeNet) [Kernel | Auto | Stopped] -- C:\WINNT\system32\drivers\Crypto.sys -- (Crypto) DRV - [2008.01.02 15:48:32 | 000,029,184 | ---- | M] (Deterministic Networks Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\vapnt.sys -- (DniVap) SafeNet WAN Miniport (VA) DRV - [2007.09.07 08:40:46 | 000,128,144 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\dne2000.sys -- (DNE) DRV - [2007.03.06 11:27:32 | 000,019,968 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2007.03.06 11:27:24 | 000,055,168 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2007.02.16 07:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\nvsmu.sys -- (nvsmu) DRV - [2006.11.03 08:32:30 | 004,394,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2004.07.09 01:58:10 | 000,015,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\mpe.sys -- (MPE) DRV - [2003.10.29 10:54:24 | 000,011,456 | R--- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\gemwdm.sys -- (gemwdm) AMD PowerNow! (tm) DRV - [2003.06.19 11:05:04 | 000,369,104 | ---- | M] (VERITAS Software Corp.) [Kernel | Disabled | Stopped] -- C:\WINNT\system32\drivers\dmboot.sys -- (dmboot) DRV - [2003.06.19 11:05:04 | 000,137,936 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmio.sys -- (dmio) DRV - [2003.06.19 11:05:04 | 000,060,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\parallel.sys -- (Parallel) DRV - [2003.06.19 11:05:04 | 000,049,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\usbhub20.sys -- (usbhub20) DRV - [2003.06.19 11:05:04 | 000,027,440 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINNT\System32\drivers\efs.sys -- (EFS) DRV - [2003.06.19 11:05:04 | 000,024,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\openhci.sys -- (openhci) DRV - [2003.06.19 11:05:04 | 000,009,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\gameenum.sys -- (gameenum) DRV - [2003.06.19 11:05:04 | 000,007,728 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\diskperf.sys -- (Diskperf) DRV - [2003.06.19 11:05:04 | 000,007,312 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmload.sys -- (dmload) DRV - [2003.01.06 15:27:46 | 000,040,448 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\WINNT\system32\drivers\DgivEcp.sys -- (DgivEcp) DRV - [2002.07.24 13:00:00 | 000,021,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\rca.sys -- (RCA) Microsoft Streaming Network-RCA (Raw Channel Access) DRV - [2002.07.24 13:00:00 | 000,009,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\netdtect.sys -- (NetDetect) DRV - [1999.10.19 14:27:30 | 000,029,968 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\avmwan.sys -- (AVMWAN) DRV - [1999.09.24 19:17:30 | 000,387,440 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\fpcibase.sys -- (fpcibase) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.autohaus.de/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.autohaus.de/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.11.10 12:50:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.06.16 14:41:01 | 000,000,000 | ---D | M] [2009.10.21 12:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Mozilla\Extensions [2009.10.21 12:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Mozilla\Firefox\Profiles\parh2s40.default\extensions [2011.11.10 12:50:38 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2011.11.10 12:50:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2011.10.06 11:57:48 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.10.06 11:57:48 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2011.10.06 11:57:48 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2011.10.06 11:57:48 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.06 11:57:48 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.06 11:57:48 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2002.07.24 13:00:00 | 000,000,820 | ---- | M]) - C:\WINNT\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1031,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx (Microsoft Corporation) O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Alcmtr] C:\WINNT\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [FreePDFAssistent] C:\Programme\FreePDF\FreePDFA.exe (shbox) O4 - HKLM..\Run: [NvCplDaemon] C:\WINNT\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINNT\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINNT\System32\nwiz.exe () O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [UnlockerAssistant] C:\Programme\Unlocker\UnlockerAssistant.exe () O4 - HKCU..\Run: [{0B803606-B754-11DE-823B-806D6172696F}] C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe (Mozilla Foundation) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\NetScreen-Remote.lnk = C:\Programme\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet) O4 - Startup: C:\Dokumente und Einstellungen\Seifert\Startmenü\Programme\Autostart\Telefon- und Branchenbuch Sommer 2009 - Schnellstarter.lnk = C:\Programme\klickTel\Telefon- und Branchenbuch Sommer 2009\KSTART32.EXE (telegate MEDIA AG) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0 O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM () O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINNT\system32\RNR20.DLL (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O15 - HKCU\..Trusted Domains: leaseplango-partner.de ([autohaus] http in Vertrauenswürdige Sites) O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255365661000 (WUWebControl Class) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {B9BE4AC6-505E-480F-BAC1-35512FBA992F} hxxp://80.139.191.100/eDVR.cab (EFOcx Control) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D1F21B75-F3D2-4A44-9278-BFB70DC7B9F9}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream - No CLSID value found O18 - Protocol\Filter\application/x-complus - No CLSID value found O18 - Protocol\Filter\application/x-msdownload - No CLSID value found O18 - Protocol\Filter\Class Install Handler - No CLSID value found O18 - Protocol\Filter\deflate - No CLSID value found O18 - Protocol\Filter\gzip - No CLSID value found O18 - Protocol\Filter\lzdhtml - No CLSID value found O18 - Protocol\Filter\text/webviewhtml - No CLSID value found O18 - Protocol\Filter\text/xml - No CLSID value found O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\USERINIT.EXE (Microsoft Corporation) O20 - Winlogon\Notify\wzcnotif: DllName - (wzcdlg.dll) - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.10.12 16:58:15 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.12.27 10:14:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner [2011.12.27 09:53:27 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\otl [2011.12.27 09:50:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\defogger [2011.12.17 11:27:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Lagerliste Handweiser [2011.12.12 16:43:08 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Kontaktdaten Mastrangelo [2009.10.13 10:14:17 | 000,018,944 | ---- | C] ( ) -- C:\WINNT\System32\implode.dll [4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ] [1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.27 10:08:21 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_448.dat [2011.12.27 10:07:59 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2ac.dat [2011.12.27 09:56:18 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Seifert\defogger_reenable [2011.12.23 18:12:49 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2b0.dat [2011.12.23 17:58:37 | 000,000,226 | -HS- | M] () -- C:\boot.ini [2011.12.23 17:04:02 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2a8.dat [2011.12.23 11:32:01 | 000,000,940 | ---- | M] () -- C:\WINNT\FBAReg.ini [2011.12.22 15:12:21 | 000,000,316 | ---- | M] () -- C:\WINNT\ktel.ini [2011.12.20 13:41:20 | 000,002,706 | ---- | M] () -- C:\WINNT\SSDS32.INI [2011.12.20 13:38:07 | 000,000,024 | ---- | M] () -- C:\WINNT\ssnew01.ini [2011.12.19 09:25:23 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2c0.dat [4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ] [1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.27 10:08:21 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_448.dat [2011.12.27 10:07:59 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2ac.dat [2011.12.27 09:56:18 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Seifert\defogger_reenable [2011.12.23 18:12:49 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2b0.dat [2011.12.23 17:04:02 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2a8.dat [2011.12.19 09:25:23 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2c0.dat [2011.11.05 09:10:14 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2c4.dat [2011.08.19 08:08:43 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2b8.dat [2011.07.18 13:49:37 | 000,143,360 | ---- | C] () -- C:\WINNT\System32\nsldap32v50.dll [2011.02.07 13:06:12 | 000,000,024 | ---- | C] () -- C:\WINNT\ssnew01.ini [2010.09.02 13:54:58 | 000,102,400 | ---- | C] () -- C:\WINNT\DLL2KUSB.DLL [2010.09.02 13:54:58 | 000,098,304 | ---- | C] () -- C:\WINNT\DLL32.DLL [2010.09.02 13:54:58 | 000,048,176 | ---- | C] () -- C:\WINNT\Imp16d20.dll [2010.09.02 13:54:58 | 000,045,056 | ---- | C] () -- C:\WINNT\System32\USBPRN.DLL [2010.09.02 13:54:58 | 000,045,056 | ---- | C] () -- C:\WINNT\System32\SCANX.DLL [2010.09.02 13:54:57 | 000,135,104 | ---- | C] () -- C:\WINNT\Tab16d20.dll [2010.09.02 13:54:57 | 000,028,672 | ---- | C] () -- C:\WINNT\SSTHUNK.DLL [2010.09.02 13:54:57 | 000,024,576 | ---- | C] () -- C:\WINNT\NTFAX.EXE [2010.09.02 13:54:57 | 000,012,800 | ---- | C] () -- C:\WINNT\SS16FT.DLL [2010.09.02 13:54:57 | 000,011,079 | ---- | C] () -- C:\WINNT\LxUsbOpn.dll [2010.09.02 13:54:57 | 000,002,706 | ---- | C] () -- C:\WINNT\SSDS32.INI [2010.09.02 13:54:57 | 000,002,554 | ---- | C] () -- C:\WINNT\SSDS16.INI [2010.09.02 13:54:57 | 000,002,269 | ---- | C] () -- C:\WINNT\SSDEF32.INI [2010.09.02 13:54:57 | 000,002,267 | ---- | C] () -- C:\WINNT\SSDEF16.INI [2010.09.02 13:54:57 | 000,000,051 | ---- | C] () -- C:\WINNT\MyScan.ini [2010.09.02 13:54:54 | 000,094,208 | ---- | C] () -- C:\WINNT\System32\getpntid.exe [2010.07.07 10:09:21 | 000,354,816 | ---- | C] () -- C:\WINNT\System32\psisdecd.dll [2009.10.21 12:15:33 | 000,000,000 | ---- | C] () -- C:\WINNT\nsreg.dat [2009.10.20 13:51:30 | 000,000,063 | ---- | C] () -- C:\WINNT\mdm.ini [2009.10.20 10:15:34 | 000,000,316 | ---- | C] () -- C:\WINNT\ktel.ini [2009.10.13 10:14:56 | 000,000,052 | ---- | C] () -- C:\WINNT\favreg.ini [2009.10.13 10:14:54 | 000,053,248 | ---- | C] () -- C:\WINNT\System32\zlib.dll [2009.10.13 10:14:20 | 000,000,197 | ---- | C] () -- C:\WINNT\lmicddl4.ini [2009.10.13 10:14:19 | 000,210,944 | ---- | C] () -- C:\WINNT\System32\msvcrt10.dll [2009.10.13 10:14:16 | 000,775,168 | ---- | C] () -- C:\WINNT\System32\corent23.dll [2009.10.13 10:14:16 | 000,613,376 | ---- | C] () -- C:\WINNT\System32\corent.dll [2009.10.13 10:14:07 | 002,281,472 | ---- | C] () -- C:\WINNT\System32\micCrypt.dll [2009.10.13 10:14:07 | 000,494,080 | ---- | C] () -- C:\WINNT\System32\HyperZIP.dll [2009.10.13 10:13:59 | 000,000,940 | ---- | C] () -- C:\WINNT\FBAReg.ini [2009.10.12 18:31:37 | 000,000,919 | ---- | C] () -- C:\WINNT\ODBC.INI [2009.10.12 17:50:30 | 000,041,232 | ---- | C] () -- C:\WINNT\System32\capi2032.dll [2009.10.12 17:49:45 | 000,004,073 | ---- | C] () -- C:\WINNT\ODBCINST.INI [2009.10.12 17:49:17 | 000,095,072 | ---- | C] () -- C:\WINNT\System32\FNTCACHE.DAT [2009.10.12 17:36:04 | 000,049,152 | ---- | C] () -- C:\WINNT\System32\ChCfg.exe [2009.10.12 17:24:56 | 000,001,732 | ---- | C] () -- C:\WINNT\System32\drivers\nvphy.bin [2009.10.12 17:22:36 | 001,626,112 | ---- | C] () -- C:\WINNT\System32\nwiz.exe [2009.10.12 17:22:32 | 001,019,904 | ---- | C] () -- C:\WINNT\System32\nvwimg.dll [2009.10.12 17:22:31 | 001,703,936 | ---- | C] () -- C:\WINNT\System32\nvwdmcpl.dll [2009.10.12 17:22:24 | 000,466,944 | ---- | C] () -- C:\WINNT\System32\nvshell.dll [2009.10.12 17:22:19 | 000,286,720 | ---- | C] () -- C:\WINNT\System32\nvnt4cpl.dll [2009.10.12 17:22:14 | 001,474,560 | ---- | C] () -- C:\WINNT\System32\nview.dll [2009.10.12 17:22:10 | 001,339,392 | ---- | C] () -- C:\WINNT\System32\nvdspsch.exe [2009.10.12 17:21:46 | 000,442,368 | ---- | C] () -- C:\WINNT\System32\nvappbar.exe [2009.10.12 17:21:37 | 000,425,984 | ---- | C] () -- C:\WINNT\System32\keystone.exe [2009.10.12 16:57:52 | 000,022,080 | -H-- | C] () -- C:\Programme\folder.htt [2009.10.12 16:57:24 | 000,015,076 | ---- | C] () -- C:\WINNT\System32\emptyregdb.dat [2003.02.20 16:53:42 | 000,005,702 | ---- | C] () -- C:\WINNT\System32\OUTLPERF.INI [2002.07.24 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINNT\System32\mlang.dat [2002.07.24 13:00:00 | 000,398,006 | ---- | C] () -- C:\WINNT\System32\perfh009.dat [2002.07.24 13:00:00 | 000,397,680 | ---- | C] () -- C:\WINNT\System32\perfh007.dat [2002.07.24 13:00:00 | 000,272,492 | ---- | C] () -- C:\WINNT\System32\perfi009.dat [2002.07.24 13:00:00 | 000,252,934 | ---- | C] () -- C:\WINNT\System32\perfi007.dat [2002.07.24 13:00:00 | 000,217,359 | ---- | C] () -- C:\WINNT\System32\dssec.dat [2002.07.24 13:00:00 | 000,176,400 | ---- | C] () -- C:\WINNT\System32\qcut.dll [2002.07.24 13:00:00 | 000,076,000 | ---- | C] () -- C:\WINNT\System32\perfc007.dat [2002.07.24 13:00:00 | 000,062,416 | ---- | C] () -- C:\WINNT\System32\perfc009.dat [2002.07.24 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINNT\System32\mib.bin [2002.07.24 13:00:00 | 000,034,108 | ---- | C] () -- C:\WINNT\System32\perfd007.dat [2002.07.24 13:00:00 | 000,034,064 | ---- | C] () -- C:\WINNT\System32\efsadu.dll [2002.07.24 13:00:00 | 000,028,270 | ---- | C] () -- C:\WINNT\System32\perfd009.dat [2002.07.24 13:00:00 | 000,014,413 | ---- | C] () -- C:\WINNT\System32\iasperf.ini [2002.07.24 13:00:00 | 000,003,056 | ---- | C] () -- C:\WINNT\System32\faxperf.ini [2002.07.24 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINNT\System32\noise.dat [2002.07.24 13:00:00 | 000,000,023 | ---- | C] () -- C:\WINNT\welcome.ini [1999.09.25 11:36:24 | 000,088,816 | ---- | C] () -- C:\WINNT\System32\drivers\lvcam.sys [1999.09.25 11:36:22 | 000,017,424 | ---- | C] () -- C:\WINNT\System32\drivers\lvsound.sys ========== LOP Check ========== [2009.12.23 17:39:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip [2009.10.20 11:53:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\klickTel ========== Purity Check ========== < End of report > GMER Logfile: Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2011-12-27 11:18:17 Windows 5.0.2195 Service Pack 4 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e ST380815AS rev.3.AAD Running: je1givwm.exe; Driver: C:\DOKUME~1\Seifert\LOKALE~1\Temp\uxtcapoc.sys ---- System - GMER 1.0.15 ---- INT 0x52 ? F90D9AE4 INT 0x72 ? F9250D24 INT 0xA3 ? F924F044 INT 0xB1 ? F928F044 INT 0xB3 ? F90D9D64 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExA] [760B78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [760B78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Cdfs \Cdfs EB1602F0 ---- EOF - GMER 1.0.15 ---- Geändert von Seifi (27.12.2011 um 11:26 Uhr) |
Themen zu Trojaner an Board |
0x00000001, antivir, board, erhalte, fenster, freue, guten, locker, meldung, morgen, msvcrt, nichts, plug-in, safer networking, scan, scanner, sched.exe, system, troja, trojaner, virenscan, virenscanner, windows, zusammen, öffnet |