Code:
Alles auswählen Aufklappen ATTFilter
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-14 17:51:07
-----------------------------
17:51:07.468 OS Version: Windows 5.1.2600 Service Pack 2
17:51:07.468 Number of processors: 1 586 0x602
17:51:07.468 ComputerName: NINE UserName:
17:51:07.937 Initialize success
18:02:00.671 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
18:02:00.671 Disk 0 Vendor: IC35L040AVVN07-0 VA2OAF0C Size: 39266MB BusType: 3
18:02:00.687 Disk 1 MBR read successfully
18:02:00.687 Disk 1 MBR scan
18:02:00.687 Disk 1 Windows XP default MBR code
18:02:00.687 Disk 1 MBR hidden
18:02:00.687 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 24011 MB offset 63
18:02:00.687 Disk 1 Partition - 00 0F Extended LBA 15249 MB offset 49174965
18:02:00.703 Disk 1 Partition 2 00 0B FAT32 MSWIN4.1 15249 MB offset 49175028
18:02:00.781 Disk 1 scanning G:\WINDOWS\system32\drivers
18:02:09.015 Service scanning
18:02:23.703 Modules scanning
18:03:17.328 Disk 1 trace - called modules:
18:03:17.328 ntoskrnl.exe CLASSPNP.SYS disk.sys hal.dll
18:03:17.843 1 nt!IofCallDriver -> \Device\Harddisk1\DR3[0x81eec3c0]
18:03:17.843 Scan finished successfully
18:08:26.859 Disk 1 MBR has been saved successfully to "G:\Dokumente und Einstellungen\Janine\Desktop\MBR.dat"
18:08:26.859 The log file has been saved successfully to "G:\Dokumente und Einstellungen\Janine\Desktop\aswMBRneu.txt"
[CODE]
GMER Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-02-14 18:28:57
Windows 5.1.2600 Service Pack 2 \Device\Harddisk1\DR3 -> \Device\Ide\IdePort0 HUAWEI__ rev.2.31 0,00MB
Running: gmer_2.0.18454.exe; Driver: G:\DOKUME~1\Janine\LOKALE~1\Temp\pxtdqpow.sys
---- Kernel code sections - GMER 2.0 ----
? G:\DOKUME~1\Janine\LOKALE~1\Temp\aswMBR.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 2.0 ----
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!CallNextHookEx 77D1ED6E 5 Bytes JMP 0122DD81 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!SetWindowsHookExW 77D3E621 5 Bytes JMP 0122DBCB G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!UnhookWindowsHookEx 77D3F29F 5 Bytes JMP 01191CA2 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] ole32.dll!CoCreateInstance 774F6009 5 Bytes JMP 0123488E G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!CallNextHookEx 77D1ED6E 5 Bytes JMP 0122DD81 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!SetWindowsHookExW 77D3E621 5 Bytes JMP 0122DBCB G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!UnhookWindowsHookEx 77D3F29F 5 Bytes JMP 01191CA2 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] ole32.dll!CoCreateInstance 774F6009 5 Bytes JMP 0123488E G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetSysColor 77D18E50 5 Bytes JMP 0045B9C0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetSysColorBrush 77D18E83 5 Bytes JMP 0045BA20 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollInfo 77D1902C 7 Bytes JMP 0045B8B0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollPos 77D1F66F 5 Bytes JMP 0045B840 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollRange 77D1F6BB 5 Bytes JMP 0045B930 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollPos 77D1F780 5 Bytes JMP 0045B8F0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollRange 77D1F7B7 5 Bytes JMP 0045B870 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!ShowScrollBar 77D20142 5 Bytes JMP 0045B980 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollInfo 77D23A2F 7 Bytes JMP 0045B800 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!EnableScrollBar 77D67BAD 7 Bytes JMP 0045B7C0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
---- User IAT/EAT - GMER 2.0 ----
IAT G:\Programme\Internet Explorer\IEXPLORE.EXE[608] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00C718FD] G:\Programme\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00C718FD] G:\Programme\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Disk sectors - GMER 2.0 ----
Disk \Device\Harddisk1\DR3 sector 00: rootkit-like behavior
---- EOF - GMER 2.0 ----
--- --- ---