![]() |
"TR/Crypt.XPACK.Gen" Hallo! Wie der Threadkopf schon zeigt, sagt Avira mir dass mein Laptop mit dem Trojaner(?) "TR/Crypt.XPACK.Gen" befallen sei. Die befallene Datei soll C:\Users\NameXY\AppData\Local\Temp\EADC225.exe sein. Wenn ich auf entfernen klicke, sagt er mir, dass es nicht geht! Bitte um Hilfe! Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:25:38, on 17.11.2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v7.00 (7.00.6002.18005) Boot mode: Normal Running processes: C:\Windows\BisonCam\BisonAPP.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Athan\Athan.exe C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe C:\Windows\SysWOW64\mfpmp.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe C:\Windows\SysWOW64\DllHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2613802 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.1\pdfforgeToolbarIE.dll F2 - REG:system.ini: UserInit=userinit.exe O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: CacherBHO - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files (x86)\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.1\pdfforgeToolbarIE.dll O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.1\pdfforgeToolbarIE.dll O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Athan] "C:\Program Files (x86)\Athan\Athan.exe" O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 7588 bytes Danke! |
Hallo, diese Funde mit EADC-Dateien im Tempordner hatte ich letztens hier auch in einem Fall, die entpuppten sich soweit als Fehlalarm. Aber trotzdem mal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
|
Vielen Danke erstmal! MBAM Scan läuft, bisher 11 infizierte Dateien. Wollte eigentlich nur anmerken, dass Avira eben eine neue Meldung brachte : C:\Users\XY\AppData\Local\Temp\EADFE2C.exe soll wohl auch infiziert sein. Mfg |
Hier die Ergebnisse von MBAM Zitat:
|
OTL Logfile: Code: OTL logfile created on: 17.11.2010 21:20:58 - Run 1 |
OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 17.11.2010 21:20:58 - Run 1 |
Kann man vllt mal drüberschauen ? =) |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! File move failed. D:\AUTORUN.INF scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\AOESETUP.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\DIRECTX\DXSETUP.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\DIRECTX\DPLAY61A.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\AR40DEU.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\DIRECTX\DXINFO.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\DIRECTX\DXDIAG.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\DIRECTX\DXTOOL.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\MACHINE\MACHINE.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\MACHINE\MACHINE.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\AOESETUP.EXE scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48edc911-8124-11df-b7a4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48edc911-8124-11df-b7a4-806e6f6e6963}\ not found. File move failed. D:\GOODIES\MSZONE\ZONEA600.EXE scheduled to be moved on reboot. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: XY ->Temp folder emptied: 20302757 bytes ->Temporary Internet Files folder emptied: 130333225 bytes ->FireFox cache emptied: 72094575 bytes ->Flash cache emptied: 23613 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 55941 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 485765960 bytes Total Files Cleaned = 676,00 mb OTL by OldTimer - Version 3.2.17.3 log created on 11192010_200024 Files\Folders moved on Reboot... File move failed. D:\AUTORUN.INF scheduled to be moved on reboot. File move failed. D:\AOESETUP.EXE scheduled to be moved on reboot. File move failed. D:\DIRECTX\DXSETUP.EXE scheduled to be moved on reboot. File move failed. D:\DIRECTX\DPLAY61A.EXE scheduled to be moved on reboot. File move failed. D:\GOODIES\AR40DEU.EXE scheduled to be moved on reboot. File move failed. D:\GOODIES\DIRECTX\DXINFO.EXE scheduled to be moved on reboot. File move failed. D:\DIRECTX\DXDIAG.EXE scheduled to be moved on reboot. File move failed. D:\GOODIES\DIRECTX\DXTOOL.EXE scheduled to be moved on reboot. File move failed. D:\GOODIES\MACHINE\MACHINE.EXE scheduled to be moved on reboot. File move failed. D:\GOODIES\MSZONE\ZONEA600.EXE scheduled to be moved on reboot. File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. C:\Users\XY\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot... |
Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows Vista Ultimate Edition Windows Information: Service Pack 2 (build 6002), 64-bit Base Board Manufacturer: FUJITSU SIEMENS BIOS Manufacturer: Phoenix System Manufacturer: FUJITSU SIEMENS System Product Name: AMILO Xa 2528 Logical Drives Mask: 0x0000001c Kernel Drivers (total 157): 0x0244A000 \SystemRoot\system32\ntoskrnl.exe 0x02404000 \SystemRoot\system32\hal.dll 0x0060F000 \SystemRoot\system32\kdcom.dll 0x00619000 \SystemRoot\system32\PSHED.dll 0x0062D000 \SystemRoot\system32\CLFS.SYS 0x0068A000 \SystemRoot\system32\CI.dll 0x0080A000 \SystemRoot\system32\drivers\Wdf01000.sys 0x008E4000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x00A06000 \SystemRoot\System32\Drivers\sppu.sys 0x00B3A000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x00B43000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x00B71000 \SystemRoot\system32\drivers\acpi.sys 0x00BC7000 \SystemRoot\system32\drivers\msisadrv.sys 0x008F2000 \SystemRoot\system32\drivers\pci.sys 0x00BD1000 \SystemRoot\System32\drivers\partmgr.sys 0x00BE6000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x00BEA000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x00922000 \SystemRoot\system32\drivers\volmgr.sys 0x00936000 \SystemRoot\System32\drivers\volmgrx.sys 0x00BF6000 \SystemRoot\system32\drivers\pciide.sys 0x0099C000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x009AC000 \SystemRoot\System32\drivers\mountmgr.sys 0x009BF000 \SystemRoot\system32\drivers\atapi.sys 0x009C7000 \SystemRoot\system32\drivers\ataport.SYS 0x009EB000 \SystemRoot\system32\drivers\nvstor.sys 0x0073C000 \SystemRoot\system32\drivers\storport.sys 0x00799000 \SystemRoot\system32\drivers\fltmgr.sys 0x007E0000 \SystemRoot\system32\drivers\fileinfo.sys 0x00C03000 \SystemRoot\System32\Drivers\ksecdd.sys 0x00E0F000 \SystemRoot\system32\drivers\ndis.sys 0x00C8A000 \SystemRoot\system32\drivers\msrpc.sys 0x00CDA000 \SystemRoot\system32\drivers\NETIO.SYS 0x0100D000 \SystemRoot\System32\drivers\tcpip.sys 0x01183000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x01208000 \SystemRoot\System32\Drivers\Ntfs.sys 0x01388000 \SystemRoot\system32\drivers\volsnap.sys 0x013CC000 \SystemRoot\System32\Drivers\spldr.sys 0x013D4000 \SystemRoot\System32\Drivers\mup.sys 0x011AF000 \SystemRoot\System32\drivers\ecache.sys 0x00FD2000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x013E6000 \SystemRoot\system32\drivers\disk.sys 0x00D33000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x011DB000 \SystemRoot\system32\drivers\crcdisk.sys 0x01000000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x00E00000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x00D82000 \SystemRoot\system32\DRIVERS\amdk8.sys 0x02C0F000 \SystemRoot\system32\DRIVERS\athrx.sys 0x02E0E000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x03804000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x038E7000 \SystemRoot\System32\drivers\watchdog.sys 0x038F7000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x0390D000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x0391B000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x03927000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x0392C000 \SystemRoot\system32\DRIVERS\smscirrx64.sys 0x0393E000 \SystemRoot\system32\DRIVERS\nvsmu.sys 0x03948000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x03953000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x03999000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x039AA000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x039C6000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x039D8000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x03A0E000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x03C02000 \SystemRoot\system32\DRIVERS\nvm60x64.sys 0x03D22000 \SystemRoot\System32\Drivers\a3xb3rnx.SYS 0x03D64000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x03D9D000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x03DAA000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x03DCD000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x03AFB000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x03DD9000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x03B2C000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x03B4A000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x03B62000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0x03DE9000 \SystemRoot\system32\DRIVERS\termdd.sys 0x03DFC000 \SystemRoot\system32\DRIVERS\swenum.sys 0x0373E000 \SystemRoot\system32\DRIVERS\ks.sys 0x039E8000 \SystemRoot\system32\DRIVERS\circlass.sys 0x03A00000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x03772000 \SystemRoot\system32\DRIVERS\umbus.sys 0x03782000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x037CA000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x0420D000 \SystemRoot\system32\drivers\RTKVHD64.sys 0x04301000 \SystemRoot\system32\drivers\portcls.sys 0x0433C000 \SystemRoot\system32\drivers\drmk.sys 0x0435F000 \SystemRoot\system32\drivers\ksthunk.sys 0x04365000 \SystemRoot\system32\DRIVERS\VSTAZL6.SYS 0x0440B000 \SystemRoot\system32\DRIVERS\VSTDPV6.SYS 0x04609000 \SystemRoot\system32\DRIVERS\VSTCNXT6.SYS 0x046D0000 \SystemRoot\system32\drivers\modem.sys 0x046DF000 \SystemRoot\system32\DRIVERS\hidir.sys 0x046EA000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x046FC000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x04704000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x0470F000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x0471A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x04724000 \SystemRoot\System32\Drivers\Null.SYS 0x0472D000 \SystemRoot\System32\drivers\vga.sys 0x0473B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x04760000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x04769000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x0476B000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x04774000 \SystemRoot\system32\drivers\rdpencdd.sys 0x0477D000 \SystemRoot\System32\Drivers\Msfs.SYS 0x04788000 \SystemRoot\System32\Drivers\Npfs.SYS 0x04799000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x047A2000 \SystemRoot\system32\DRIVERS\tdx.sys 0x047BF000 \SystemRoot\system32\DRIVERS\smb.sys 0x04589000 \SystemRoot\system32\drivers\afd.sys 0x043B6000 \SystemRoot\System32\DRIVERS\netbt.sys 0x047DA000 \SystemRoot\system32\DRIVERS\pacer.sys 0x037DE000 \SystemRoot\system32\DRIVERS\netbios.sys 0x047F8000 \??\C:\Windows\system32\WinIo.sys 0x02D74000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x02D8F000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x045F4000 \SystemRoot\system32\drivers\nsiproxy.sys 0x04A0A000 \SystemRoot\system32\drivers\csc.sys 0x04A80000 \SystemRoot\System32\Drivers\dfsc.sys 0x04A9D000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x04ABF000 \SystemRoot\System32\Drivers\BTHUSB.sys 0x04ACD000 \SystemRoot\System32\Drivers\bthport.sys 0x04B7B000 \SystemRoot\system32\DRIVERS\rfcomm.sys 0x04BAC000 \SystemRoot\system32\DRIVERS\BthEnum.sys 0x04BB9000 \SystemRoot\system32\DRIVERS\bthpan.sys 0x04ECA000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x04EE6000 \SystemRoot\System32\Drivers\crashdmp.sys 0x04EF4000 \SystemRoot\System32\Drivers\dump_diskdump.sys 0x04EFE000 \SystemRoot\System32\Drivers\dump_nvstor.sys 0x04F0E000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x000D0000 \SystemRoot\System32\win32k.sys 0x04F21000 \SystemRoot\System32\drivers\Dxapi.sys 0x04F2D000 \SystemRoot\system32\DRIVERS\monitor.sys 0x004A0000 \SystemRoot\System32\TSDDD.dll 0x00670000 \SystemRoot\System32\cdd.dll 0x04F40000 \SystemRoot\system32\drivers\luafv.sys 0x04F62000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x09802000 \SystemRoot\system32\drivers\spsys.sys 0x0989C000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x098B0000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x098E4000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x098EF000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x09907000 \SystemRoot\system32\drivers\HTTP.sys 0x099AA000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x099D3000 \SystemRoot\system32\DRIVERS\bowser.sys 0x04F7F000 \SystemRoot\System32\drivers\mpsdrv.sys 0x04F99000 \SystemRoot\system32\drivers\mrxdav.sys 0x04FC0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x00D96000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x04BD8000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x09E01000 \SystemRoot\System32\DRIVERS\srv2.sys 0x09E33000 \SystemRoot\System32\DRIVERS\srv.sys 0x09EC7000 \SystemRoot\system32\drivers\peauth.sys 0x09F7D000 \SystemRoot\System32\Drivers\secdrv.SYS 0x09F88000 \SystemRoot\System32\drivers\tcpipreg.sys 0x04E00000 \SystemRoot\System32\Drivers\BisonCam.sys 0x09FBA000 \SystemRoot\System32\Drivers\STREAM.SYS 0x77AF0000 \Windows\System32\ntdll.dll Processes (total 62): 0 System Idle Process 4 System 492 C:\Windows\System32\smss.exe 560 csrss.exe 604 C:\Windows\System32\wininit.exe 624 csrss.exe 660 C:\Windows\System32\services.exe 688 C:\Windows\System32\winlogon.exe 704 C:\Windows\System32\lsass.exe 716 C:\Windows\System32\lsm.exe 872 C:\Windows\System32\svchost.exe 952 C:\Windows\System32\svchost.exe 992 C:\Windows\System32\svchost.exe 304 C:\Windows\System32\svchost.exe 380 C:\Windows\System32\svchost.exe 432 C:\Windows\System32\svchost.exe 616 C:\Windows\System32\audiodg.exe 880 C:\Windows\System32\SLsvc.exe 1060 C:\Windows\System32\svchost.exe 1324 C:\Windows\System32\svchost.exe 1580 C:\Windows\System32\spoolsv.exe 1624 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 1632 C:\Windows\System32\taskeng.exe 1640 C:\Windows\System32\dwm.exe 1648 C:\Windows\explorer.exe 1680 C:\Windows\System32\svchost.exe 1956 C:\Program Files\Windows Defender\MSASCui.exe 1964 C:\Windows\RAVCpl64.exe 1972 C:\Windows\BisonCam\BisonAPP.exe 1308 C:\Windows\System32\rundll32.exe 1316 C:\Program Files (x86)\Power Manager\PM.exe 1508 C:\Windows\WindowsMobile\wmdSync.exe 1512 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe 2072 C:\Windows\System32\rundll32.exe 2080 C:\Windows\ehome\ehtray.exe 2144 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe 2224 C:\Windows\ehome\ehmsas.exe 2376 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 2384 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe 2444 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe 2640 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 2704 C:\Program Files (x86)\Athan\Athan.exe 2716 C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe 2752 C:\Windows\System32\svchost.exe 2784 C:\Windows\SysWOW64\svchost.exe 2844 C:\Windows\System32\svchost.exe 2952 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe 2968 C:\Windows\System32\svchost.exe 2984 C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe 3012 C:\Windows\System32\svchost.exe 2688 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe 3000 C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe 2120 C:\Windows\System32\svchost.exe 3724 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe 1900 C:\Program Files\Windows Media Player\wmpnscfg.exe 3004 C:\Program Files\Windows Media Player\wmpnetwk.exe 2104 C:\Windows\System32\taskeng.exe 4368 C:\Windows\System32\svchost.exe 3284 C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2892 C:\Windows\explorer.exe 1912 C:\Users\XY\Downloads\MBRCheck.exe 4648 C:\Windows\SysWOW64\conime.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: WDC WD2500BEVS-00UST, Rev: 01.0 Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979 Done! |
Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! |
SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 11/21/2010 at 04:59 PM Application Version : 4.45.1000 Core Rules Database Version : 5894 Trace Rules Database Version: 3706 Scan type : Complete Scan Total Scan Time : 01:39:50 Memory items scanned : 558 Memory threats detected : 0 Registry items scanned : 12207 Registry threats detected : 0 File items scanned : 112178 File threats detected : 2 Adware.Tracking Cookie C:\Users\XY\AppData\Roaming\Microsoft\Windows\Cookies\XY@atdmt.combing[2].txt C:\Users\XY\AppData\Roaming\Microsoft\Windows\Cookies\XY@atdmt[2].txt |
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 5138 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 21.11.2010 18:20:29 mbam-log-2010-11-21 (18-20-29).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 234026 Laufzeit: 58 Minute(n), 47 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
Zitat:
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:10 Uhr. |
Copyright ©2000-2025, Trojaner-Board