Hallo,
hier erst mal die GMER-Logdatei: Code:
GMER Logfile:
Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-22 13:21:19
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 FUJITSU_MHY2200BH rev.0000000B
Running: cqr4b1qs.exe; Driver: C:\Users\Sandra\AppData\Local\Temp\kwdiqpob.sys
---- System - GMER 1.0.15 ----
SSDT 886C5F28 ZwAlertResumeThread
SSDT 886C3500 ZwAlertThread
SSDT 886C3F38 ZwAllocateVirtualMemory
SSDT 87F8D260 ZwAlpcConnectPort
SSDT 886C5C78 ZwCreateMutant
SSDT 886D65E0 ZwCreateThread
SSDT 886C59D8 ZwDebugActiveProcess
SSDT 886C3D98 ZwFreeVirtualMemory
SSDT 886C5D68 ZwImpersonateAnonymousToken
SSDT 886C5E48 ZwImpersonateThread
SSDT 886C3C98 ZwMapViewOfSection
SSDT 886C5B98 ZwOpenEvent
SSDT 886D6520 ZwOpenProcessToken
SSDT 886C39D8 ZwOpenThreadToken
SSDT 886C9498 ZwResumeThread
SSDT 886C38F8 ZwSetContextThread
SSDT 886C3AC8 ZwSetInformationProcess
SSDT 886C3808 ZwSetInformationThread
SSDT 886C5AB8 ZwSuspendProcess
SSDT 886C3648 ZwSuspendThread
SSDT 886CE318 ZwTerminateProcess
SSDT 886C3728 ZwTerminateThread
SSDT 886C3BB8 ZwUnmapViewOfSection
SSDT 886C3E68 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInsertQueue + 30D 828AC8D4 8 Bytes [28, 5F, 6C, 88, 00, 35, 6C, ...]
.text ntoskrnl.exe!KeInsertQueue + 321 828AC8E8 4 Bytes [38, 3F, 6C, 88]
.text ntoskrnl.exe!KeInsertQueue + 32D 828AC8F4 4 Bytes [60, D2, F8, 87]
.text ntoskrnl.exe!KeInsertQueue + 3E5 828AC9AC 4 Bytes [78, 5C, 6C, 88]
.text ntoskrnl.exe!KeInsertQueue + 411 828AC9D8 4 Bytes [E0, 65, 6D, 88]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!IsZoomed + 80 766C0731 7 Bytes JMP 10053940 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!GetClassLongW + 529 766C1EB5 7 Bytes JMP 100537F0 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!DdeUninitialize + 360 766E02A5 7 Bytes JMP 10053920 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxIndirectA + F5 7670D566 7 Bytes JMP 10053990 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxIndirectW + 61 7670D5CC 7 Bytes JMP 10053A60 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxExA + 1F 7670D5F0 7 Bytes JMP 10053A10 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [748C8864] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74909855] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [748CB984] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [748BFB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [748C7A29] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [748BEA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [748FB12D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [748CBC4A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [748C0756] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [748C06BD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748B71B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7494D9E0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [748E7329] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [748BE109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [748B697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [748B69A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [748C2475] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot] [00408590] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExA] [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExA] [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey] [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00352F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00352CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00352C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00352CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01AE2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01AE2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01AE2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01AE2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [000C2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [000C2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [000C2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [000C2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00027875488f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00027875abd1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00197ef0e983 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875488f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875abd1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00197ef0e983 (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875488f
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875abd1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197ef0e983
---- EOF - GMER 1.0.15 ---- --- --- ---
Alles weiter folgt!
Hallo,
hier die OSAM Logdatei und die aswMBR.txt.
Hoffe es passt so!
[code]
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 14:30:12 on 22.09.2012
OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Google Inc. Google Chrome 21.0.1180.89
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"Norton Internet Security Online - Systemprüfung ausführen - Sandra.job" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"BlackBerry-Smartphone" (RimUsb) - ? - C:\Windows\System32\Drivers\RimUsb.sys (File not found)
"catchme" (catchme) - ? - C:\Users\Sandra\AppData\Local\Temp\catchme.sys (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found)
"kwdiqpob" (kwdiqpob) - ? - C:\Users\Sandra\AppData\Local\Temp\kwdiqpob.sys (Hidden registry entry, rootkit activity | File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MTOnlPktAlyX NDIS Protocol Driver" (MTOnlPktAlyX) - "Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH" - C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis1\MTOnlPktAlyX.SYS
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVEX15.SYS
"SPBBCDrv" (SPBBCDrv) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
"SRTSP" (SRTSP) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSP.SYS
"SRTSPL" (SRTSPL) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPL.SYS
"SRTSPX" (SRTSPX) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPX.SYS
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Intrusion Prevention Driver" (IDSvix86) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20120524.001\IDSvix86.sys
"SYMDNS" (SYMDNS) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMDNS.SYS
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\Windows\system32\Drivers\SYMEVENT.SYS
"SYMFW" (SYMFW) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMFW.SYS
"SymIMMP" (SymIMMP) - ? - C:\Windows\System32\DRIVERS\SymIM.sys (File not found)
"SYMNDISV" (SYMNDISV) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMNDISV.SYS
"SYMREDRV" (SYMREDRV) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMREDRV.SYS
"SYMTDI" (SYMTDI) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMTDI.SYS
"T-Online Dialerschutz VoIP Service" (SipIMNDI) - ? - C:\Windows\System32\DRIVERS\SipIMNDI.sys (File not found)
[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2} "PixiePack Codec Pack 1.1.1200.0" - ? - C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll (File found, but it contains no detailed information)
{5574006C-28F5-4a65-A28C-74DE6BFBE0BB} "Haali Matroska Shell Property Page" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll (File found, but it contains no detailed information)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Extractor" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll (File found, but it contains no detailed information)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{5BD933E7-F18F-4D3B-A16B-B1A40B04764E} "KodakPrintShellExtensionNative" - "Eastman Kodak Company" - C:\Program Files\Kodak\AiO\Center\Inkjet.ShellExtension.Native_Win32.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "Norton-Symbolleiste anzeigen" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
<binary data> "{855F3B16-6D32-4FE6-8A56-BBB695989046}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? - (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
"ICQ6" - "ICQ, LLC." - C:\Program Files\ICQ6.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{8dcb7100-df86-4384-8842-8fa844297b3f} "Bing Bar" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} "Norton-Symbolleiste anzeigen" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} "Bing Bar Helper" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
{4E52A6BF-3F10-45E7-A6D8-93E4890ADFA9} "CouponAlerterBHO Class" - ? - C:\Program Files\GuteGutscheine\1.0.0.11\CouponAlerter.dll (File not found)
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} "Symantec Intrusion Prevention" - "Symantec Corporation" - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} "{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"PMB Medien-Prüfung.lnk" - "Sony Corporation" - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Adobe Reader - Schnellstart.lnk" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (Shortcut exists | File exists)
"Tevion Scanner Finder.lnk" - ? - C:\Program Files\Tevion\ScanWizard 5\ScannerFinder.exe (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Device Detection" - ? - C:\Program Files\LIDL Fotoservice\dd.exe
"InfoCockpit" - "Deutsche Telekom AG, T-Com" - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE /nosplash
"ISUSPM" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"Logitech Vid" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
"Nero MediaHome 4" - "Nero AG" - "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
"Sony PC Companion" - "Sony" - "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
"swg" - "Google Inc." - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"T-Online_Software_6\WLAN-Access Finder" - "Deutsche Telekom AG, Marmiko IT-Solutions GmbH" - C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe /StartMinimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Photo Downloader" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ccApp" - "Symantec Corporation" - "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
"DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"LogitechQuickCamRibbon" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
"Nero MediaHome 4" - "Nero AG" - "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"StartCCC" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (File found, but it contains no detailed information)
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Adobe LM Service" (Adobe LM Service) - "Adobe Systems" - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Automatisches LiveUpdate - Scheduler" (Automatic LiveUpdate Scheduler) - "Symantec Corporation" - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
"BBUpdate" (BBUpdate) - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
"BingBar Service" (BBSvc) - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
"COM Host" (comHost) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Kodak AiO Network Discovery Service" (Kodak AiO Network Discovery Service) - "Eastman Kodak Company" - C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
"LiveShare P2P Server 9" (RoxLiveShare9) - ? - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" (File not found)
"LiveUpdate" (LiveUpdate) - "Symantec Corporation" - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
"LiveUpdate Notice" (LiveUpdate Notice) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Nero MediaHome 4 Service" (NeroMediaHomeService.4) - "Nero AG" - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe (File found, but it contains no detailed information)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"Symantec Core LC" (Symantec Core LC) - ? - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
"Symantec Event Manager" (ccEvtMgr) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec Lic NetConnect service" (CLTNetCnService) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec Settings Manager" (ccSetMgr) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
===[ Logfile end ]=========================================[ Logfile end ]=== --- --- --- Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-22 14:36:37
-----------------------------
14:36:37.837 OS Version: Windows 6.0.6001 Service Pack 1
14:36:37.837 Number of processors: 2 586 0xF0D
14:36:37.839 ComputerName: SANDRA-PC UserName: Sandra
14:36:39.185 Initialize success
14:41:21.381 AVAST engine defs: 12092100
14:43:27.362 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:43:27.365 Disk 0 Vendor: FUJITSU_MHY2200BH 0000000B Size: 190782MB BusType: 3
14:43:27.786 Disk 0 MBR read successfully
14:43:27.789 Disk 0 MBR scan
14:43:27.796 Disk 0 unknown MBR code
14:43:27.893 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10240 MB offset 2048
14:43:27.996 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 90429 MB offset 20973568
14:43:28.111 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 90111 MB offset 206172160
14:43:28.371 Disk 0 scanning sectors +390719488
14:43:29.083 Disk 0 scanning C:\Windows\system32\drivers
14:44:52.696 Service scanning
14:45:28.644 Modules scanning
14:46:59.998 Disk 0 trace - called modules:
14:47:00.117 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
14:47:00.122 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x857dcac8]
14:47:00.127 3 CLASSPNP.SYS[8b449745] -> nt!IofCallDriver -> [0x85667a48]
14:47:00.133 5 acpi.sys[8ae336a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8566c5e8]
14:47:01.105 AVAST engine scan C:\Windows
14:48:16.665 AVAST engine scan C:\Windows\system32
14:59:08.812 AVAST engine scan C:\Windows\system32\drivers
14:59:29.763 AVAST engine scan C:\Users\Sandra
15:39:13.210 AVAST engine scan C:\ProgramData
15:53:30.814 Scan finished successfully
19:12:42.998 Disk 0 MBR has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\MBR.dat"
19:12:43.005 The log file has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\aswMBR.txt"
Viele Grüße Sandi |