|
Plagegeister aller Art und deren Bekämpfung: TR/Trash.GenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.03.2011, 21:17 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/Trash.Gen Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
18.03.2011, 21:54 | #17 |
| TR/Trash.Gen Here we go...
__________________Gmer: GMER Logfile: Code:
ATTFilter GMER 1.0.15.15530 - hxxp://www.gmer.net Rootkit scan 2011-03-08 23:02:44 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-e WDC_WD1600BEVT-22ZCT0 rev.11.01A11 Running: gmer.exe; Driver: C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\kxtdipow.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xA746C534] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0xA7466782] SSDT BAEA36DE ZwCreateKey SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xA746CCC0] SSDT BAEA36D4 ZwCreateThread SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xA746CDF6] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xA7467398] SSDT BAEA36E3 ZwDeleteKey SSDT BAEA36ED ZwDeleteValueKey SSDT BAEA36F2 ZwLoadKey SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xA7487B44] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0xA7466FAA] SSDT BAEA36C0 ZwOpenProcess SSDT BAEA36C5 ZwOpenThread SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0xA74888D2] SSDT BAEA36FC ZwReplaceKey SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xA746C0F4] SSDT BAEA36F7 ZwRestoreKey SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xA746775C] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xA7488E12] SSDT BAEA36E8 ZwSetValueKey ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2C99 80504525 3 Bytes JMP 616622BA .text ntkrnlpa.exe!ZwCallbackReturn + 2D4C 805045D8 8 Bytes JMP 487B44BA .text ntkrnlpa.exe!ZwCallbackReturn + 2FA0 8050482C 4 Bytes CALL 750B3267 ? wnpmbp.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Programme\Mozilla Firefox\plugin-container.exe[1512] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 10406373 C:\Programme\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Programme\Mozilla Firefox\firefox.exe[3792] ntdll.dll!LdrLoadDll 7C9263A3 5 Bytes JMP 004013F0 C:\Programme\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Devices - GMER 1.0.15 ---- Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Classes\CLSID\{586A635p Reg HKLM\SOFTWARE\Classes\CLSID\{586A635p @ Animation General Property Page Object Reg HKLM\SOFTWARE\Classes\CLSID\{586A635p \InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{586A635p \InprocServer32@ C:\WINDOWS\system32\MSCOMCT2.OCX ---- EOF - GMER 1.0.15 ---- Osam OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 21:46:24 on 18.03.2011 OS: Windows XP Professional Service Pack 3 (Build 2600) Default Browser: Mozilla Corporation Firefox 3.6.15 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Boot Execute] -----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager )----- "BootExecute" - "O&O Software GmbH" - C:\WINDOWS\system32\OODBS.exe [Common] -----( %SystemRoot%\Tasks )----- "GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "1-Klick-Wartung.job" - "TuneUp Software GmbH" - C:\Programme\TuneUpUtilities2006\SystemOptimizer.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "ac3filter.cpl" - ? - C:\WINDOWS\system32\ac3filter.cpl "jpicpl32.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\jpicpl32.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "Adobe Version Cue CS4" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.cpl "Avira AntiVir Personal" - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl "Nero BurnRights" - "Nero AG" - C:\Programme\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl "Speech" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Speech\sapi.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "adfs" (adfs) - "Adobe Systems, Inc." - C:\WINDOWS\system32\drivers\adfs.sys "avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys "avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys "AVM Eject" (avmeject) - "AVM Berlin" - C:\WINDOWS\System32\drivers\avmeject.sys "catchme" (catchme) - ? - C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\catchme.sys (File not found) "Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found) "i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys (File not found) "kxtdipow" (kxtdipow) - ? - C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\kxtdipow.sys (Hidden registry entry, rootkit activity | File not found) "lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found) "PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found) "PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found) "PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found) "PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found) "PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found) "PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys "WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found) [Explorer] -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )----- {7790769C-0471-11d2-AF11-00C04FA35D02} "Adressbuch 6" - "Microsoft Corporation" - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install {44BBA840-CC51-11CF-AAFA-00AA00B6015C} "Microsoft Outlook Express 6" - "Microsoft Corporation" - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {7D4D6379-F301-4311-BEBA-E26EB0561882} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroDigitalExt.dll {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll -----( HKLM\Software\Classes\Protocols\Filter )----- {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll {807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL {3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL {12D51199-0DB5-46FE-A120-47A3D7D937CC} "DVD: Pluggable Protocol" - "Microsoft Corporation" - C:\WINDOWS\system32\msvidctl.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} "TV: Pluggable Protocol" - "Microsoft Corporation" - C:\WINDOWS\system32\msvidctl.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {32714800-2E5F-11d0-8B85-00AA0044F941} "&Nach Personen..." - "Microsoft Corporation" - C:\Programme\Outlook Express\wabfind.dll {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - D:\ADOBE\Acrobat 9.0\Acrobat Elements\ContextMenu.dll {888DCA60-FC0A-11CF-8F0F-00C04FD7D062} "Compressed (zipped) Folder SendTo Target" - ? - (File not found | COM-object registry key not found) {42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll (File not found) {88895560-9AA2-1069-930E-00AA0030EBC8} "Erweiterung für HyperTerminal-Icons" - ? - (File not found | COM-object registry key not found) {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found) {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found) {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL {2206CDB2-19C1-11D1-89E0-00C04FD7A829} "Microsoft OLE DB Service Component Data Links" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\System\Ole DB\oledb32.dll {B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroDigitalExt.dll {7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroDigitalExt.dll {0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll {764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found) {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll {00DF1F20-0849-A4D1-0239-00D0AF3E9CB0} "TuneUp Shredder Shell Context Menu Extension" - ? - (File not found | COM-object registry key not found) {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL {2170E0A4-42F2-4EB5-911F-ABC2717F6566} "WebPlus Thumbnail Handler" - "Serif (Europe) Ltd" - C:\Programme\Serif\WebPlus\X4\Program\ThumbnailProvider.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\WinRAR\rarext.dll (File found, but it contains no detailed information) {7DA86F0E-6DE5-49b6-9C98-BA7763A2946A} "wppfilter" - "Serif (Europe) Ltd" - C:\WINDOWS\system32\wppfilt.dll [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- <binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) <binary data> "ITBarLayout" - ? - (File not found | COM-object registry key not found) <binary data> "{00000000-0000-0000-0000-000000000000}" - ? - (File not found | COM-object registry key not found) <binary data> "{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {E2883E8F-472F-4FB0-9522-AC9BF37916A7} "get_atlcom Class" - "NOS Microsystems Ltd." - C:\Programme\NOS\bin\gp.ocx / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.5.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} "Java Plug-in 1.5.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.5.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\WINDOWS\system32\Macromed\Flash\Flash10n.ocx / hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} "ClsidExtension" - "Google Inc." - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll "Messenger" - "Microsoft Corporation" - C:\Programme\Messenger\msmsgs.exe {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- <binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll {30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine " - ? - (File not found | COM-object registry key not found) {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} "Contribute Toolbar" - "Adobe Systems Incorporated." - D:\ADOBE\Adobe Contribute CS4\contributeieplugin.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {AE7CD045-E861-484f-8273-0445EE161910} "Adobe PDF Conversion Toolbar Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {074C1DC5-9320-4A9A-947D-C042949C6216} "ContributeBHO Class" - "Adobe Systems Incorporated." - D:\ADOBE\Adobe Contribute CS4\contributeieplugin.dll {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} "Google Gears Helper" - "Google Inc." - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll {F4971EE7-DAA0-4053-9964-665D8EE6A077} "SmartSelect Class" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll {30F9B915-B755-4826-820B-08FBA6BD249D} "{30F9B915-B755-4826-820B-08FBA6BD249D}" - ? - (File not found | COM-object registry key not found) [Logon] -----( %AllUsersProfile%\Startmenü\Programme\Autostart )----- "desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini "Utility Tray.lnk" - "Silicon Integrated Systems Corporation" - C:\WINDOWS\system32\sistray.exe (Shortcut exists | File exists) -----( %UserProfile%\Startmenü\Programme\Autostart )----- "desktop.ini" - ? - C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart\desktop.ini -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "Skype" - "Skype Technologies S.A." - "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "avgnt" - "Avira GmbH" - "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min "AVMWlanClient" - "AVM Berlin" - C:\Programme\avmwlanstick\FRITZWLANMini.exe "FreePDF Assistant" - "shbox.de" - C:\Programme\FreePDF_XP\fpassist.exe "SiSPower" - "Silicon Integrated Systems Corporation" - Rundll32.exe SiSPower.dll,ModeAgent "SunJavaUpdateSched" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\jusched.exe "TouchPadHotKey" - ? - C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe [Network Providers] -----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )----- "Adobe Drive CS4 Network" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll "PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll (File found, but it contains no detailed information) "Redirected Port" - ? - C:\WINDOWS\system32\redmonnt.dll (File found, but it contains no detailed information) [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe "Adobe LM Service" (Adobe LM Service) - "Adobe Systems" - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe "Adobe Version Cue CS4" (Adobe Version Cue CS4) - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe "ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe "Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe "Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe "Canon imagePROGRAF Status Monitor" (Canon imagePROGRAF Status Monitor) - "CANON INC" - C:\Programme\Canon\imagePROGRAFStatusMonitor\cnwisam.exe "EpsonBidirectionalService" (EpsonBidirectionalService) - "SEIKO EPSON CORPORATION" - C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe "FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe "getPlus(R) Helper" (getPlusHelper) - "NOS Microsystems Ltd." - C:\Programme\NOS\bin\getPlus_Helper.dll "getPlus(R) Helper 3004" (nosGetPlusHelper) - "NOS Microsystems Ltd." - C:\Programme\NOS\bin\getPlus_Helper_3004.dll "Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "O&O Defrag" (O&O Defrag) - "O&O Software GmbH" - C:\WINDOWS\system32\oodag.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE "TuneUp WinStyler Theme Service" (TUWinStylerThemeSvc) - "TuneUp Software GmbH" - C:\Programme\TuneUpUtilities2006\WinStylerThemeSvc.exe [Winlogon] -----( HKCU\Control Panel\IOProcs )----- "MVB" - ? - mvfs32.dll (File not found) ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Mbr MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003c Kernel Drivers (total 123): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E5000 \WINDOWS\system32\hal.dll 0xBADA8000 \WINDOWS\system32\KDCOM.DLL 0xBACB8000 \WINDOWS\system32\BOOTVID.dll 0xBA8A8000 twkjhn.sys 0xBA778000 ACPI.sys 0xBADAA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xBA767000 pci.sys 0xBA8B8000 isapnp.sys 0xBACBC000 compbatt.sys 0xBACC0000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xBAE70000 pciide.sys 0xBAB28000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xBA8C8000 MountMgr.sys 0xBA748000 ftdisk.sys 0xBADAC000 dmload.sys 0xBA722000 dmio.sys 0xBAE71000 siside.sys 0xBACC4000 ACPIEC.sys 0xBAE72000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xBAB30000 PartMgr.sys 0xBA8D8000 VolSnap.sys 0xBA70A000 atapi.sys 0xBA8E8000 disk.sys 0xBA8F8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xBA6EA000 fltmgr.sys 0xBA6D8000 sr.sys 0xBA908000 PxHelp20.sys 0xBA6C1000 KSecDD.sys 0xBA634000 Ntfs.sys 0xBA607000 NDIS.sys 0xBA918000 SISAGPX.sys 0xBA5ED000 Mup.sys 0xBA968000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xBAD78000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xBA541000 \SystemRoot\system32\DRIVERS\sisgrp.sys 0xBA52D000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xBA978000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xBA4FA000 \SystemRoot\system32\DRIVERS\SynTP.sys 0xBADC4000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xBABE0000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xBABE8000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xBA988000 \SystemRoot\system32\DRIVERS\imapi.sys 0xBA998000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xBA9A8000 \SystemRoot\system32\DRIVERS\redbook.sys 0xBA4D7000 \SystemRoot\system32\DRIVERS\ks.sys 0xBABF0000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xBA4B3000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xBABF8000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xBA9B8000 \SystemRoot\system32\DRIVERS\SiSGbeXP.sys 0xBA48B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xBAEEC000 \SystemRoot\system32\DRIVERS\audstub.sys 0xBA9C8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xBAD80000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xBA474000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xBA9D8000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xBA9E8000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xBAC00000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xBA43B000 \SystemRoot\system32\DRIVERS\psched.sys 0xBA9F8000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xBAC08000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xBAC10000 \SystemRoot\system32\DRIVERS\raspti.sys 0xBA40B000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xBAA08000 \SystemRoot\system32\DRIVERS\termdd.sys 0xBADC6000 \SystemRoot\system32\DRIVERS\swenum.sys 0xBA3AD000 \SystemRoot\system32\DRIVERS\update.sys 0xBAD9C000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xB9F25000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xB9F01000 \SystemRoot\system32\drivers\portcls.sys 0xBAA18000 \SystemRoot\system32\drivers\drmk.sys 0xBAA28000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBAA58000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xBADCC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xBAF92000 \SystemRoot\System32\Drivers\Null.SYS 0xBADCE000 \SystemRoot\System32\Drivers\Beep.SYS 0xBAC38000 \SystemRoot\System32\drivers\vga.sys 0xBADD0000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xBADD2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xBAC40000 \SystemRoot\System32\Drivers\Msfs.SYS 0xBAC48000 \SystemRoot\System32\Drivers\Npfs.SYS 0xBAD68000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xA7DBE000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA7D65000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA7D3F000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xA7D17000 \SystemRoot\system32\DRIVERS\netbt.sys 0xA7CF5000 \SystemRoot\System32\drivers\afd.sys 0xBAA68000 \SystemRoot\system32\DRIVERS\netbios.sys 0xBAC50000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0xBAC58000 \SystemRoot\system32\DRIVERS\srvkp.sys 0xA7CCA000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA7C32000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xBAA78000 \SystemRoot\System32\Drivers\Fips.SYS 0xA7C0C000 \SystemRoot\system32\DRIVERS\avipbb.sys 0xBADD8000 \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys 0xBA454000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xBAA98000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xBAC68000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xBA450000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xBAAA8000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xBAAE8000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA7BB3000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xBADDE000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xA7E15000 \SystemRoot\System32\drivers\Dxapi.sys 0xBAC78000 \SystemRoot\System32\watchdog.sys 0xBF9C3000 \SystemRoot\System32\drivers\dxg.sys 0xBAF1A000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF9D5000 \SystemRoot\System32\SiSGRV.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xA7A5E000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0xA7A83000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA7729000 \SystemRoot\system32\drivers\wdmaud.sys 0xA78A6000 \SystemRoot\system32\drivers\sysaudio.sys 0xA75BC000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA7039000 \SystemRoot\System32\Drivers\adfs.SYS 0xA6F97000 \SystemRoot\system32\DRIVERS\srv.sys 0xA6C86000 \SystemRoot\System32\Drivers\HTTP.sys 0xBABD8000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xA66E7000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA66A6000 \SystemRoot\system32\DRIVERS\fwlanusb.sys 0xA668E000 \??\C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\kxtdipow.sys 0xA6663000 \SystemRoot\system32\drivers\kmixer.sys 0x7C910000 \WINDOWS\system32\ntdll.dll Processes (total 46): 0 System Idle Process 4 System 812 C:\WINDOWS\system32\smss.exe 892 csrss.exe 916 C:\WINDOWS\system32\winlogon.exe 960 C:\WINDOWS\system32\services.exe 972 C:\WINDOWS\system32\lsass.exe 1156 C:\WINDOWS\system32\svchost.exe 1204 svchost.exe 1244 C:\WINDOWS\system32\svchost.exe 1340 svchost.exe 1392 svchost.exe 1748 C:\WINDOWS\system32\spoolsv.exe 1800 C:\Programme\Avira\AntiVir Desktop\sched.exe 160 C:\Programme\Google\Update\1.2.183.39\GoogleCrashHandler.exe 196 C:\WINDOWS\explorer.exe 568 C:\Programme\Java\jre1.5.0_06\bin\jusched.exe 592 C:\WINDOWS\RTHDCPL.exe 604 C:\Programme\Synaptics\SynTP\SynTPEnh.exe 612 C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe 636 C:\Programme\Avira\AntiVir Desktop\avgnt.exe 652 C:\Programme\FreePDF_XP\fpassist.exe 668 C:\Programme\avmwlanstick\FRITZWLANMini.exe 676 C:\Programme\Skype\Phone\Skype.exe 800 C:\WINDOWS\system32\sistray.exe 1992 C:\Programme\Skype\Plugin Manager\skypePM.exe 472 C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSvc.exe 748 C:\Programme\Avira\AntiVir Desktop\avguard.exe 776 C:\Programme\Canon\imagePROGRAFStatusMonitor\cnwisam.exe 2036 C:\WINDOWS\system32\oodag.exe 2156 C:\Programme\Avira\AntiVir Desktop\avshadow.exe 2628 C:\WINDOWS\system32\wbem\wmiapsrv.exe 2872 wmiprvse.exe 3152 alg.exe 3576 C:\WINDOWS\system32\ctfmon.exe 3964 C:\WINDOWS\system32\wuauclt.exe 868 C:\Programme\Java\jre1.5.0_06\bin\jucheck.exe 3256 dfrgntfs.exe 3372 C:\Programme\Mozilla Firefox\plugin-container.exe 3220 dfrgntfs.exe 2772 C:\Programme\Mozilla Firefox\firefox.exe 3308 C:\Programme\Mozilla Thunderbird\thunderbird.exe 3236 dfrgntfs.exe 3312 C:\WINDOWS\system32\wscntfy.exe 2300 C:\Programme\Mozilla Firefox\plugin-container.exe 1388 C:\Dokumente und Einstellungen\Administrator\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000009`c3dcd400 (NTFS) PhysicalDrive0 Model Number: WDCWD1600BEVT-22ZCT0, Rev: 11.01A11 Size Device Name MBR Status -------------------------------------------- 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 Done! |
18.03.2011, 22:16 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/Trash.Gen Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
__________________Denk dran beide Tools zu updaten vor dem Scan!!
__________________ |
19.03.2011, 05:07 | #19 |
| TR/Trash.Gen Hi Arne, superspyware habich nicht mehr geschafft- ich bin jetzt bis Dienstag in Urlaub. Vielen vielen Dank für Deine Hilfe. Ich schick das Log wenn ich wieder da bin. Grüße, claus Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6100 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 18.03.2011 23:13:15 mbam-log-2011-03-18 (23-13-15).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 341004 Laufzeit: 57 Minute(n), 38 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
Themen zu TR/Trash.Gen |
0x00000001, adblock, adobe, alternate, antivir, avgntflt.sys, avira, bho, browser, canon, conduit, cs4/contributeieplugin.dll, desktop, einstellungen, fehler, firefox, ftp, google, helper, hängen, kein copy and paste, kein drag and drop, location, logfile, mozilla, mozilla thunderbird, netzwerk, ntdll.dll, oldtimer, pdfforge toolbar, plug-in, port, problem, realtek, registry, schädling, searchplugins, software, stick, system, tr/spy., trash.gen, udp, versteckte objekte, verweise, virus gefunden |