Detrimentol | 26.06.2011 19:37 | Hallo,
hier kommen die Logfiles. MBRCheck dagt, er habe non-Standard MBR code gefunden. Z.Info: Ich habe BootItNG installiert und verwende es. Z. Zeit verwende ich es als Bootmanager und boote ausschließlich von Laufwerk 1.
GMER kommt als gezippter ANhang.
Hier ist OSAM Code:
OSAM Logfile:
Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:15:46 on 26.06.2011
OS: Windows XP Home Edition Service Pack 3 (Build 2600)
Default Browser: Mozilla Corporation Firefox 5.0
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"iamcpl.cpl" - "WRQ, Inc." - C:\WINDOWS\system32\iamcpl.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Programme\l+v\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"actser" (actser) - "Siemens AG" - C:\WINDOWS\System32\drivers\actser.sys
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswFsBlk.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswRdr.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswSP.sys
"avast! Asynchronous Virus Monitor" (Aavmker4) - "AVAST Software" - C:\WINDOWS\system32\drivers\Aavmker4.sys
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswTdi.sys
"avast! Standard Shield Support" (aswMon2) - "AVAST Software" - C:\WINDOWS\system32\drivers\aswMon2.sys
"AVM ADSL Adapter Device" (aadev) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\aadev.sys
"AVM CoNDIS WAN CAPI Treiber" (AVMCOWAN) - "AVM GmbH" - C:\WINDOWS\System32\DRIVERS\avmcowan.sys
"AVM DSL NDIS WAN CAPI Treiber" (AVMNDSL) - "AVM GmbH" - C:\WINDOWS\System32\DRIVERS\avmndsl.sys
"AVM DSL PPPoE CAPI-Treiber" (AVMDSLPPPOE) - "AVM GmbH" - C:\WINDOWS\System32\DRIVERS\avmdsloe.sys
"AVM Eject" (avmeject) - "AVM Berlin" - C:\WINDOWS\System32\drivers\avmeject.sys
"AVM FRITZ!Card DSL (WinXP/2000)" (FDSLBASE) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\fdslbase.sys
"AVM FRITZ!web DSL PPP" (NETFWDSL) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\NETFWDSL.SYS
"AVM FRITZ!web PPP over ISDN" (NETFRITZ) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\NETFRITZ.SYS
"AVMPORT" (AVMPORT) - "AVM Berlin" - C:\WINDOWS\System32\drivers\avmport.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys (File not found)
"Cdr4_xp" (Cdr4_xp) - "Roxio" - C:\WINDOWS\system32\drivers\Cdr4_xp.sys
"Cdralw2k" (Cdralw2k) - "Roxio" - C:\WINDOWS\system32\drivers\Cdralw2k.sys
"cdudf_xp" (cdudf_xp) - "Roxio" - C:\WINDOWS\system32\drivers\cdudf_xp.sys
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found)
"DNSFILT" (DNSFILT) - "WRQ, Inc." - C:\Programme\comm\Internet\Atguard\DNSFILT.SYS
"dvd_2K" (dvd_2K) - "Roxio" - C:\WINDOWS\system32\drivers\dvd_2K.sys
"FWFILT" (FWFILT) - "WRQ, Inc." - C:\Programme\comm\Internet\Atguard\FWFILT.SYS
"HTTPFILT" (HTTPFILT) - "WRQ, Inc." - C:\Programme\comm\Internet\Atguard\HTTPFILT.SYS
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys (File not found)
"Iamdrv" (Iamdrv) - "WRQ, Inc." - C:\Programme\comm\Internet\Atguard\iamdrv.sys
"Initio Driver for USB Default Controller" (ivusb) - ? - C:\WINDOWS\System32\DRIVERS\ivusb.sys (File not found)
"kgddyfow" (kgddyfow) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\kgddyfow.sys (Hidden registry entry, rootkit activity | File not found)
"KillFile" (KillFile) - ? - C:\WINDOWS\system32\drivers\KillFile.sys (File found, but it contains no detailed information)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\WINDOWS\system32\drivers\mbam.sys
"mbr" (mbr) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\mbr.sys (Hidden registry entry, rootkit activity | File not found)
"mmc_2K" (mmc_2K) - "Roxio" - C:\WINDOWS\system32\drivers\mmc_2K.sys
"NDISFILT" (NDISFILT) - ? - C:\Programme\comm\Internet\Atguard\NDISFILT.SYS (File found, but it contains no detailed information)
"nv" (nv) - "NVIDIA Corporation" - C:\WINDOWS\System32\DRIVERS\nv4_mini.sys
"Padus ASPI Shell" (pfc) - "Padus, Inc." - C:\WINDOWS\System32\drivers\pfc.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found)
"pwd_2k" (pwd_2k) - "Roxio" - C:\WINDOWS\system32\drivers\pwd_2k.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys
"UdfReadr_xp" (UdfReadr_xp) - "Roxio" - C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found)
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Haali\MatroskaSplitter\mmfinfo.dll (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Programme\Office\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\ut\files\compress\7-Zip\7-zip.dll
{5E44E225-A408-11CF-B581-008029601108} "Adaptec DirectCD Shell Extension" - "Roxio" - C:\PROGRA~1\CD_DVD~1\Roxio\EASYCD~1\DirectCD\Shellex.dll
{32020A01-506E-484D-A2A8-BE3CF17601C3} "AlcoholShellEx" - ? - (File not found | COM-object registry key not found)
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Programme\ut\sicherheit\Alwil Software\Avast5\ashShell.dll
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll (File not found)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.dll
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Haali\MatroskaSplitter\mmfinfo.dll (File found, but it contains no detailed information)
{5574006C-28F5-4a65-A28C-74DE6BFBE0BB} "Haali Matroska Shell Property Page" - ? - C:\Programme\Haali\MatroskaSplitter\mmfinfo.dll (File found, but it contains no detailed information)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Extractor" - ? - C:\Programme\Haali\MatroskaSplitter\mmfinfo.dll (File found, but it contains no detailed information)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found)
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? - (File not found | COM-object registry key not found)
{59850401-6664-101B-B21C-00AA004BA90B} "Microsoft Office Binder Unbind" - "Microsoft Corporation" - C:\PROGRA~1\Office\MICROS~1\Office\1031\UNBIND.DLL
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{49BF5420-FA7F-11cf-8011-00A0C90A8F78} "Mobiles Gerät" - "Microsoft Corporation" - C:\PROGRA~1\comm\MICROS~1\Wcesview.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Programme\Office\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Programme\Office\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Programme\Office\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Programme\Office\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\Office\MICROS~1\Office\OLKFSTUB.DLL
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Programme\l+v\Real\RealPlayer\rpshell.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{ED65AC21-B24F-11d3-BA80-00C0CA16AA37} "Siemens Device" - "Siemens AG" - C:\Programme\comm\Mobile Phone Manager\DES\DESShellExt.dll
{ED65AC22-B24F-11d3-BA80-00C0CA16AA37} "Siemens Device ContextMenuHandler" - "Siemens AG" - C:\Programme\comm\Mobile Phone Manager\DES\DESShellExt.dll
{ED65AC23-B24F-11d3-BA80-00C0CA16AA37} "Siemens Device PropertySheetHandler" - "Siemens AG" - C:\Programme\comm\Mobile Phone Manager\DES\DESShellExt.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\ut\files\compress\WinRAR\rarext.dll (File found, but it contains no detailed information)
{5464D816-CF16-4784-B9F3-75C0DB52B499} "YMailShellExt Class" - "Yahoo! Inc." - C:\PROGRA~1\Comm\Internet\Yahoo\Common\ymmapi.dll
{ABE00001-0123-ABED-1248-0248ADFA1909} "ZPShellExt" - ? - C:\PROGRA~1\L_V~1\ZOOMPL~1\zpshlext.dll (File found, but it contains no detailed information)
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{4528BBE0-4E08-11D5-AD55-00010333D0AD} "&Yahoo! Messenger" - "Yahoo! Inc." - C:\Programme\Comm\Internet\Yahoo\Messenger\yhexbmes.dll
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? - (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
DirectAnimation Java Classes "DirectAnimation Java Classes" - ? - (File not found | COM-object registry key not found) / file://C:\WINDOWS\Java\classes\dajava.cab
{90A29DA5-D020-4B18-8660-6689520C7CD7} "DmiReader Class" - "Dell Computer Corporation" - C:\WINDOWS\DOWNLO~1\SYSPRO~1.DLL / hxxp://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Microsoft XML Parser for Java "Microsoft XML Parser for Java" - ? - (File not found | COM-object registry key not found) / file://C:\WINDOWS\Java\classes\xmldso.cab
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} "MUWebControl Class" - "Microsoft Corporation" - C:\WINDOWS\system32\muweb.dll / hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1278230930984
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\WINDOWS\system32\Macromed\Flash\Flash10l.ocx / hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool" - "Microsoft Corporation" - C:\WINDOWS\system32\legitcheckcontrol.dll / hxxp://go.microsoft.com/fwlink/?linkid=39204
{31435657-9980-0010-8000-00AA00389B71} "{31435657-9980-0010-8000-00AA00389B71}" - ? - (File not found | COM-object registry key not found) / hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} "{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}" - ? - (File not found | COM-object registry key not found) / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "ClsidExtension" - "Microsoft Corporation" - C:\PROGRA~1\comm\MICROS~1\INetRepl.dll
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "Create Mobile Favorite" - "Microsoft Corporation" - C:\PROGRA~1\comm\MICROS~1\INetRepl.dll
{4C171D40-8277-11D5-AD55-00010333D0AD} "Messenger" - "Yahoo! Inc." - C:\Programme\Comm\Internet\Yahoo\Messenger\yhexbmes.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Plug-In" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "AcroIEHlprObj Class" - "Adobe Systems Incorporated" - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Plug-In" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
[Logon]
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"Dropbox.lnk" - "Dropbox, Inc." - C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Shortcut exists | File exists)
"OpenOffice.org 3.2.lnk" - ? - C:\Programme\Office\OpenOffice.org 3\program\quickstart.exe (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"H/PC Connection Agent" - "Microsoft Corporation" - "C:\Programme\comm\Microsoft ActiveSync\wcescomm.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AdaptecDirectCD" - "Roxio" - C:\Programme\cd+dvd\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
"AVMWlanClient" - "AVM Berlin" - C:\Programme\avmwlanstick\wlangui.exe
"DAEMON Tools-1033" - "DAEMON'S HOME" - "C:\Programme\cd+dvd\D-Tools\daemon.exe" -lang 1033
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Programme\ut\sicherheit\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"NvCplDaemon" - "NVIDIA Corporation" - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"NvMediaCenter" - "NVIDIA Corporation" - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"QuickTime Task" - "Apple Inc." - "C:\Programme\l+v\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"FRITZ!fax Color Port Monitor" - "AVM Berlin GmbH" - C:\WINDOWS\system32\FritzColorPort.dll
"FRITZ!fax Port Monitor" - "AVM Berlin GmbH" - C:\WINDOWS\system32\FritzPort.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll (File not found)
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Programme\ut\sicherheit\Alwil Software\Avast5\AvastSvc.exe
"AVM FRITZ!web Routing Service" (de_serv) - "AVM Berlin" - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe
"AVM WLAN Connection Service" (AVM WLAN Connection Service) - "AVM Berlin" - C:\Programme\avmwlanstick\WlanNetService.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Programme\ut\sicherheit\Malwarebytes' Anti-Malware\mbamservice.exe
"NVIDIA Display Driver Service" (NVSvc) - "NVIDIA Corporation" - C:\WINDOWS\system32\nvsvc32.exe
"WD SmartWare Background Service" (WDSmartWareBackgroundService) - "Memeo" - C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
"WD SmartWare Drive Manager" (WDDMService) - "WDC" - C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"WRQ IAM" (iamServ) - "WRQ, Inc." - C:\Programme\comm\Internet\Atguard\iamserv.exe
[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll (File not found)
===[ Logfile end ]=========================================[ Logfile end ]=== --- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
Und hier COde des Logs von MBRCheck: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000000bd
Kernel Drivers (total 142):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EF000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A7000 ACPI.sys
0xF7989000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF7596000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 PCIIde.sys
0xF7707000 \WINDOWS\System32\Drivers\PCIIDEX.SYS
0xF798B000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D7000 ftdisk.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF74BF000 atapi.sys
0xF7627000 disk.sys
0xF7637000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF749F000 fltmgr.sys
0xF748D000 sr.sys
0xF7647000 KillFile.sys
0xF7717000 PxHelp20.sys
0xF7476000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7449000 NDIS.sys
0xF7657000 Combo-Fix.sys
0xF742F000 Mup.sys
0xF7667000 agp440.sys
0xBA7CC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0xF76B7000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xB9D50000 \SystemRoot\System32\DRIVERS\nv4_mini.sys
0xB9D3C000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF7807000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xB9D18000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xF780F000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xF7817000 \SystemRoot\System32\DRIVERS\fdc.sys
0xF76C7000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF781F000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF76D7000 \SystemRoot\System32\DRIVERS\serial.sys
0xF772F000 \SystemRoot\system32\drivers\actser.sys
0xBA7C8000 \SystemRoot\System32\DRIVERS\serenum.sys
0xB9D04000 \SystemRoot\System32\DRIVERS\parport.sys
0xF76E7000 \SystemRoot\system32\drivers\Imapi.sys
0xBA7C4000 \SystemRoot\system32\drivers\pfc.sys
0xF76F7000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
0xF7586000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF7576000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB9CE1000 \SystemRoot\System32\DRIVERS\ks.sys
0xB9CC1000 \SystemRoot\System32\Drivers\pwd_2k.SYS
0xF7737000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
0xB9C3D000 \SystemRoot\system32\drivers\smwdm.sys
0xB9BE8000 \SystemRoot\system32\drivers\portcls.sys
0xF7566000 \SystemRoot\system32\drivers\drmk.sys
0xF79AB000 \SystemRoot\system32\drivers\aeaudio.sys
0xF7556000 \SystemRoot\System32\DRIVERS\avmcowan.sys
0xF7546000 \SystemRoot\System32\DRIVERS\avmdsloe.sys
0xF79AD000 \SystemRoot\System32\Drivers\RootMdm.sys
0xF773F000 \SystemRoot\System32\Drivers\Modem.SYS
0xF7536000 \SystemRoot\System32\DRIVERS\avmndsl.sys
0xBA2A2000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF7526000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xBA7B8000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB9B31000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF7516000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF7506000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xF7747000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB9B20000 \SystemRoot\System32\DRIVERS\psched.sys
0xF74F6000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF774F000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF7757000 \SystemRoot\System32\DRIVERS\raspti.sys
0xBA798000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF7767000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF79AF000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB9AC2000 \SystemRoot\System32\DRIVERS\update.sys
0xBA6F7000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF776F000 \SystemRoot\System32\Drivers\dvd_2K.SYS
0xBA788000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA778000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF79B3000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xF7777000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xF79B7000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7A6D000 \SystemRoot\System32\Drivers\Null.SYS
0xF79B9000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7787000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF778F000 \SystemRoot\System32\drivers\vga.sys
0xF79BB000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79BD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB884F000 \SystemRoot\System32\Drivers\cdudf_xp.SYS
0xF7797000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF779F000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB880A000 \SystemRoot\System32\Drivers\UdfReadr_xp.SYS
0xF7923000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB87BD000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB87A3000 \??\C:\Programme\comm\Internet\Atguard\iamdrv.sys
0xB874A000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xBA758000 \SystemRoot\System32\Drivers\aswTdi.SYS
0xB8722000 \SystemRoot\System32\DRIVERS\netbt.sys
0xB86EA000 \SystemRoot\system32\DRIVERS\tcpip6.sys
0xF77A7000 \SystemRoot\System32\Drivers\aswRdr.SYS
0xB86C8000 \SystemRoot\System32\drivers\afd.sys
0xBA748000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB869D000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xB862D000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xBA728000 \SystemRoot\System32\Drivers\Fips.SYS
0xB8607000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xBA718000 \SystemRoot\system32\drivers\ip6fw.sys
0xF7687000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xB8595000 \SystemRoot\System32\Drivers\aswSP.SYS
0xB8525000 \SystemRoot\System32\Drivers\aswSnx.SYS
0xB6ED5000 \SystemRoot\system32\DRIVERS\fwlanusb.sys
0xF77BF000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF77C7000 \SystemRoot\System32\Drivers\Aavmker4.SYS
0xB9A6A000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF7697000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xB9A62000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xB9A5E000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xB85EF000 \SystemRoot\System32\drivers\Dxapi.sys
0xF775F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7A73000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBF3CD000 \SystemRoot\System32\ATMFD.DLL
0xB50DF000 \??\C:\WINDOWS\system32\drivers\mbam.sys
0xB50DB000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0xB4EC8000 \SystemRoot\System32\Drivers\aswMon2.SYS
0xB4443000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xB4680000 \SystemRoot\System32\drivers\avmport.sys
0xF79A9000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB503F000 \SystemRoot\System32\DRIVERS\aadev.sys
0xB4283000 \SystemRoot\System32\DRIVERS\srv.sys
0xB40D3000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB3EAE000 \SystemRoot\system32\drivers\wdmaud.sys
0xB401B000 \SystemRoot\system32\drivers\sysaudio.sys
0xB3C4B000 \SystemRoot\System32\Drivers\HTTP.sys
0xB3FEB000 \SystemRoot\System32\DRIVERS\ipfltdrv.sys
0xF77EF000 \??\C:\ComboFix\catchme.sys
0xF799F000 \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
0xAEF87000 \??\C:\DOKUME~1\Admin\LOKALE~1\Temp\kgddyfow.sys
0xAE761000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xACE65000 \SystemRoot\system32\drivers\kmixer.sys
0x7C910000 \WINDOWS\system32\ntdll.dll
Processes (total 44):
0 System Idle Process
4 System
852 C:\WINDOWS\system32\smss.exe
900 csrss.exe
924 C:\WINDOWS\system32\winlogon.exe
968 C:\WINDOWS\system32\services.exe
980 C:\WINDOWS\system32\lsass.exe
1124 C:\WINDOWS\system32\svchost.exe
1172 svchost.exe
1212 C:\WINDOWS\system32\svchost.exe
1260 svchost.exe
1284 svchost.exe
1408 C:\Programme\ut\sicherheit\Alwil Software\Avast5\AvastSvc.exe
1700 C:\WINDOWS\system32\spoolsv.exe
1772 svchost.exe
1816 C:\Programme\avmwlanstick\WLanNetService.exe
1868 C:\Programme\Comm\Internet\Atguard\iamserv.exe
1920 C:\Programme\Java\jre6\bin\jqs.exe
1960 C:\Programme\ut\sicherheit\Malwarebytes' Anti-Malware\mbamservice.exe
1984 C:\WINDOWS\system32\nvsvc32.exe
2016 C:\WINDOWS\system32\svchost.exe
128 wdfmgr.exe
156 C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
232 C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
732 alg.exe
3600 C:\Programme\CD+DVD\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
3852 C:\WINDOWS\system32\rundll32.exe
3864 C:\Programme\avmwlanstick\WLanGUI.exe
3880 C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
3936 C:\Programme\Comm\Microsoft ActiveSync\wcescomm.exe
160 C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe
2408 C:\Programme\Office\OpenOffice.org 3\program\soffice.exe
2648 C:\PROGRA~1\Comm\MICROS~1\rapimgr.exe
2716 C:\WINDOWS\system32\svchost.exe
2840 C:\Programme\Office\OpenOffice.org 3\program\soffice.bin
3224 C:\WINDOWS\explorer.exe
2904 C:\PROGRA~1\ut\SICHER~1\ALWILS~1\Avast5\AvastUI.exe
3448 C:\WINDOWS\system32\wscntfy.exe
3328 wmiprvse.exe
3672 C:\Programme\Office\Crimson Editor\cedt.exe
3236 E:\Programme\sicherheit\osam\osam.exe
2636 C:\Programme\Comm\Mozilla Firefox\firefox.exe
660 C:\Programme\Comm\Mozilla Firefox\plugin-container.exe
3192 F:\SOFTWARE\Sicherheit\MBRCheck\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000002`ed9d7200 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000002`ed9df000 (NTFS)
PhysicalDrive1 Model Number: HDS724040KLAT80, Rev: KFAOA46A
PhysicalDrive0 Model Number: WDCWD2500JB-75GVA0, Rev: 08.02D08
Size Device Name MBR Status
--------------------------------------------
372 GB \\.\PhysicalDrive1 Unknown MBR code
SHA1: 3459A48226A7F4DE7B51FC5D0C39017F89CA4A12
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 3459A48226A7F4DE7B51FC5D0C39017F89CA4A12
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit: |