Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   TR/Kazy.mekml.1 (https://www.trojaner-board.de/98404-tr-kazy-mekml-1-a.html)

xdsgrrrrr 28.04.2011 15:44

TR/Kazy.mekml.1
 
Hallo liebe Leute,

wie es aussieht habe ich mir auch den Trojaner Kazy eingefangen, der hier bereits ausgiebig diskutiert wird :headbang:. Symptome wie üblich schwarzer Bildschirm und Meldungen zu einem Festplattenschaden. LOG's von Malwarebytes und OTL habe ich angehängt. Wer kann mir helfen??

Vielen Dank!

cosinus 29.04.2011 13:46

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.

xdsgrrrrr 29.04.2011 14:42

Hallo,

leider keine weiteren Logs vorhanden, ich habe nochmal eins mit dem Quickscan gemacht (Siehe Anhang), mit neuer Datenbankversion. In der Quarantäne von Malwarebytes wird der Trojaner "Trojan.FakeAlert" angezeigt, ausserdem sind plötzlich die Desktopsymbole wieder da, wenn auch versteckt, d.h. ausgegraut.

Startmenü ist weiterhin leer.

Wie gehts weiter? Vielen Dank schonmal im Voraus!

cosinus 29.04.2011 20:27

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
O4 - HKCU..\Run: [RSxWcWRakP] C:\ProgramData\RSxWcWRakP.exe (WinTrust)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.) - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2009.06.29 18:43:22 | 000,000,048 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{37347c75-0a0a-11e0-b111-001377adacff}\Shell\AutoRun\command - "" = F:\APPInst.exe
O33 - MountPoints2\{c1c7cb79-717a-11e0-b701-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c1c7cb79-717a-11e0-b701-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{caa6f30b-3980-11df-8412-001377adacff}\Shell - "" = AutoRun
O33 - MountPoints2\{caa6f30b-3980-11df-8412-001377adacff}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{caa6f31a-3980-11df-8412-001e101f2c0e}\Shell - "" = AutoRun
O33 - MountPoints2\{caa6f31a-3980-11df-8412-001e101f2c0e}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{d734d297-34cc-11df-bdb6-001377adacff}\Shell - "" = AutoRun
O33 - MountPoints2\{d734d297-34cc-11df-bdb6-001377adacff}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{e23570d8-34c9-11df-83a1-001377adacff}\Shell - "" = AutoRun
O33 - MountPoints2\{e23570d8-34c9-11df-83a1-001377adacff}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{e23570e5-34c9-11df-83a1-001377adacff}\Shell - "" = AutoRun
O33 - MountPoints2\{e23570e5-34c9-11df-83a1-001377adacff}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.29 11:55:52 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

xdsgrrrrr 02.05.2011 08:35

Hallo,

OTL ist mit dem Script durchgelaufen, dann allerdings abgeschmiert. Logfile wurde nicht angezeigt. Auf dem Desktop sind die zuvor ausgegrauten Dateien wieder unsichtbar. Was kann man nun tun?

cosinus 02.05.2011 12:46

Wiederhol den Fix bitte.

xdsgrrrrr 02.05.2011 13:57

Hallo hallo,

dieses mal ist er durchgelaufen ohne Absturz. Log hängt hier an. Scheint mir als hätte es am T-Mobile-Stick gelegen dass er abgeschmiert ist, weil nicht schreibbarer Speicher :headbang:.

cosinus 02.05.2011 15:10

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

xdsgrrrrr 02.05.2011 15:31

Hallo,

Kaspersky sagt: Infection - Not found, LOG-Fenster ist leer. Habe nochmal ein Malwarebytes-Log gemacht wie in der Anleitung zu TDDSKiller angegeben.

cosinus 02.05.2011 15:47

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

xdsgrrrrr 02.05.2011 16:56

Combofix Logfile:
Code:

ComboFix 11-05-01.04 - Sten 02.05.2011  17:40:43.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3066.1799 [GMT 2:00]
ausgeführt von:: c:\users\Sten\Desktop\cofi.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-02 bis 2011-05-02  ))))))))))))))))))))))))))))))
.
.
2011-05-02 14:59 . 2011-05-02 14:59        --------        d-----w-        c:\program files\CCleaner
2011-05-02 07:14 . 2011-05-02 07:14        --------        d-----w-        C:\_OTL
2011-04-29 13:56 . 2011-04-29 13:57        --------        d-----w-        c:\program files\Microsoft Silverlight
2011-04-29 13:49 . 2011-04-29 13:49        89048        ----a-w-        c:\program files\Mozilla Firefox\libEGL.dll
2011-04-29 13:49 . 2011-04-29 13:49        781272        ----a-w-        c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-04-29 13:49 . 2011-04-29 13:49        465880        ----a-w-        c:\program files\Mozilla Firefox\libGLESv2.dll
2011-04-29 13:49 . 2011-04-29 13:49        1874904        ----a-w-        c:\program files\Mozilla Firefox\mozjs.dll
2011-04-29 13:49 . 2011-04-29 13:49        15832        ----a-w-        c:\program files\Mozilla Firefox\mozalloc.dll
2011-04-29 13:49 . 2011-04-29 13:49        1974616        ----a-w-        c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-04-29 13:49 . 2011-04-29 13:49        1892184        ----a-w-        c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-29 13:49 . 2011-04-29 13:49        142296        ----a-w-        c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-29 13:33 . 2011-04-11 07:04        7071056        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{B369C54B-6E5A-48B0-A113-54481AC62F67}\mpengine.dll
2011-04-28 12:54 . 2011-04-28 12:54        --------        d-----w-        c:\users\Sten\AppData\Roaming\Malwarebytes
2011-04-28 10:21 . 2011-03-03 15:40        28672        ----a-w-        c:\windows\system32\Apphlpdm.dll
2011-04-28 10:21 . 2011-03-03 13:35        4240384        ----a-w-        c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-28 10:21 . 2011-03-12 21:55        876032        ----a-w-        c:\windows\system32\XpsPrint.dll
2011-04-28 10:03 . 2011-04-28 10:18        --------        d-----w-        c:\users\Sten\AppData\Roaming\T-Mobile Internet Manager
2011-04-28 09:39 . 2009-10-12 13:22        101120        ----a-w-        c:\windows\system32\drivers\ewusbdev.sys
2011-04-28 09:39 . 2007-08-09 02:06        23424        ----a-w-        c:\windows\system32\drivers\ewdcsc.sys
2011-04-28 09:39 . 2011-04-28 09:39        --------        d-----w-        c:\users\Sten\AppData\Roaming\T-Mobile
2011-04-28 09:39 . 2008-10-09 11:50        22528        ----a-w-        c:\windows\system32\drivers\BMLoad.sys
2011-04-28 09:39 . 2008-10-09 11:50        18816        ----a-w-        c:\windows\system32\drivers\tcpipBM.sys
2011-04-28 09:39 . 2008-02-11 15:05        8464        ----a-w-        c:\windows\system32\sporder.dll
2011-04-28 09:39 . 2008-10-09 11:52        294912        ----a-w-        c:\windows\system32\bminstall.dll
2011-04-28 09:39 . 2008-10-09 11:51        126976        ----a-w-        c:\windows\system32\bmdumpd.bin
2011-04-28 09:39 . 2008-02-11 15:05        719360        ----a-w-        c:\windows\system32\bmutil.dll
2011-04-28 09:38 . 2009-10-20 16:47        112640        ----a-w-        c:\windows\system32\drivers\ewusbnet.sys
2011-04-28 09:38 . 2011-04-28 09:38        --------        d-----w-        c:\program files\T-Mobile
2011-04-28 08:22 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-28 08:22 . 2011-04-28 08:22        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-28 08:22 . 2010-12-20 16:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-04-28 08:22 . 2011-04-28 08:22        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 15:40 . 2011-04-28 10:21        173056        ----a-w-        c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-28 10:21        458752        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-28 10:21        542720        ----a-w-        c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-28 10:21        2159616        ----a-w-        c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-25 18:05        288768        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-25 18:05        1068544        ----a-w-        c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-22 19:17        797696        ----a-w-        c:\windows\system32\FntCache.dll
2011-02-02 16:11 . 2009-10-03 08:41        222080        ------w-        c:\windows\system32\MpSigStub.exe
2011-04-29 13:49 . 2011-04-29 13:49        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-30 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"HW_OPENEYE_OUC_T-Mobile Internet Manager"="c:\program files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe" [2009-12-31 110592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-26 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DataCardMonitor"="c:\program files\Huawei Modems\DataCardMonitor.exe" [2010-03-21 249856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\users\Sten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office Outlook.lnk - c:\program files\Microsoft Office\Office12\OUTLOOK.EXE [2011-2-24 12999536]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 135664]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-10-20 112640]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2009-07-09 17408]
R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-02-03 1155072]
S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2007-05-23 13312]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-08-05 44576]
S3 VMC302;Vimicro Camera Service VMC302;c:\windows\system32\Drivers\VMC302.sys [2008-06-05 242048]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - KLMD25
*Deregistered* - BMLoad
*Deregistered* - klmd25
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
WindowsMobile        REG_MULTI_SZ          wcescomm rapimgr
LocalServiceRestricted        REG_MULTI_SZ          WcesComm RapiMgr
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-17 08:56        451872        ----a-w-        c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 19:13]
.
2011-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 19:13]
.
2011-05-02 c:\windows\Tasks\User_Feed_Synchronization-{01B62102-D129-4B5E-9589-7DDB44047915}.job
- c:\windows\system32\msfeedssync.exe [2011-04-29 14:04]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Sten\AppData\Roaming\Mozilla\Firefox\Profiles\ai7h94nu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.tvino.de/tvpage/_tv/home/index.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-05-02 17:45
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DataCardMonitor = c:\program files\Huawei Modems\DataCardMonitor.exe?rogram Files?PUBLIC=Cz?<y?g???8??p???TJAVA=c:\program files\Q>??>?g???8??????m\QTJava.zip?SystemDrive=C:?SystemRoot=c:\windows?temp=c:\Users\Sten\AppData\Local\Temp?TMP=c:\users\Sten\AppData\Local\Temp?TRA
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2912)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2011-05-02  17:48:08
ComboFix-quarantined-files.txt  2011-05-02 15:47
.
Vor Suchlauf: 11 Verzeichnis(se), 47.735.566.336 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 52.445.036.544 Bytes frei
.
- - End Of File - - F1184D02644F8E2E4723A4E38951D37B

--- --- ---

cosinus 02.05.2011 19:04

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

xdsgrrrrr 03.05.2011 08:47

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 08:57:23 on 03.05.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile Device Ethernet Service" (Netaapl) - "Apple Inc." - C:\Windows\System32\DRIVERS\netaapl.sys
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"Bytemobile Boot Time Load Driver" (BMLoad) - "Bytemobile, Inc." - C:\Windows\System32\drivers\BMLoad.sys
"Bytemobile Kernel Network Provider" (tcpipBM) - "Bytemobile, Inc." - C:\Windows\system32\drivers\tcpipBM.sys
"catchme" (catchme) - ? - C:\Users\Sten\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Vimicro Camera Service VMC326" (VMC326) - ? - C:\Windows\System32\Drivers\VMC326.sys  (File not found)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} "EPUImageControl Class" - "eBay, Inc." - C:\Windows\Downloaded Program Files\EPUWALcontrol.dll / hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} "Office Genuine Advantage Validation Tool" - ? - C:\Windows\system32\OGACheckControl.DLL / hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "@C:\Windows\WindowsMobile\INetRepl.dll,-222" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "ClsidExtension" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
{77BF5300-1474-4EC7-9980-D32B190E9B07} "ClsidExtension" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{77BF5300-1474-4EC7-9980-D32B190E9B07} "Skype" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} "Skype add-on (mastermind)" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Sten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Microsoft Office Outlook.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"HW_OPENEYE_OUC_T-Mobile Internet Manager" - "Huawei Technologies Co., Ltd." - "C:\Program Files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe"
"LightScribe Control Panel" - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"swg" - "Google Inc." - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"DataCardMonitor" - "Huawei Technologies Co., Ltd." - C:\Program Files\Huawei Modems\DataCardMonitor.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Canon BJNP Port" - "CANON INC." - C:\Windows\system32\CNMNPPM.DLL
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Scheduler" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"SQL Server-Startdienst für Business Contact Manager" (BcmSqlStartupSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

xdsgrrrrr 03.05.2011 08:48

GMER Logfile:
Code:

GMER 1.0.15.15572 - hxxp://www.gmer.net
Rootkit scan 2011-05-03 09:41:06
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: e4uuyzd4.exe; Driver: C:\Users\***\AppData\Local\Temp\kxldypog.sys


---- System - GMER 1.0.15 ----

SSDT            8D8E0584                                                                                            ZwCreateThread
SSDT            8D8E0570                                                                                            ZwOpenProcess
SSDT            8D8E0575                                                                                            ZwOpenThread
SSDT            8D8E057F                                                                                            ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!KeInsertQueue + 411                                                                    82477A08 4 Bytes  [84, 05, 8E, 8D]
.text          ntoskrnl.exe!KeInsertQueue + 5E1                                                                    82477BD8 4 Bytes  [70, 05, 8E, 8D]
.text          ntoskrnl.exe!KeInsertQueue + 5FD                                                                    82477BF4 4 Bytes  [75, 05, 8E, 8D]
.text          ntoskrnl.exe!KeInsertQueue + 811                                                                    82477E08 4 Bytes  [7F, 05, 8E, 8D]
.text          C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                            section is writeable [0x8EC0A340, 0x3EE687, 0xE8000020]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            \SystemRoot\System32\drivers\dxgkrnl.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\HDAudBus.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\CmBatt.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\i8042prt.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\kbdclass.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\mouclass.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\storport.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndistapi.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\termdd.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\swenum.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ks.sys[ntoskrnl.exe!IoCreateDevice]                                    [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\mssmbios.sys[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\usbhub.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\drivers\portcls.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Fs_Rec.SYS[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Beep.SYS[ntoskrnl.exe!IoCreateDevice]                                  [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\drivers\VIDEOPRT.SYS[ntoskrnl.exe!IoCreateDevice]                              [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Msfs.SYS[ntoskrnl.exe!IoCreateDevice]                                  [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Npfs.SYS[ntoskrnl.exe!IoCreateDevice]                                  [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\DRIVERS\rasacd.sys[ntoskrnl.exe!IoCreateDevice]                                [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tdx.sys[ntoskrnl.exe!IoCreateDevice]                                    [8AED263E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tdx.sys[TDI.SYS!TdiRegisterDeviceObject]                                [8AED2FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\smb.sys[TDI.SYS!TdiRegisterDeviceObject]                                [8AED2FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject]                              [8AED2FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [73637817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [7368A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [7363BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [7362F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [736375E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [7362E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [73668395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [7363DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [7362FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [7362FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [736271CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [736BCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [7365C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [7362D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [73626853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [7362687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3512] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [73632AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                              tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002787923ce                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1f37b91                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1f5d89c                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269cdd0c4                         
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0002787923ce (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001fe1f37b91 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001fe1f5d89c (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269cdd0c4 (not active ControlSet)     

---- EOF - GMER 1.0.15 ----

--- --- ---

cosinus 03.05.2011 10:45

Wieso denn 2x GMER?

xdsgrrrrr 03.05.2011 11:01

Oh mist, hab die falsche Datei genommen. Sorry! Hier nun einmal MBRCheck

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer: Phoenix Technologies Ltd.
System Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
System Product Name: R510/P510
Logical Drives Mask: 0x0000007c

Kernel Drivers (total 148):
0x8240A000 \SystemRoot\system32\ntoskrnl.exe
0x827B5000 \SystemRoot\system32\hal.dll
0x8A40E000 \SystemRoot\system32\kdcom.dll
0x8A415000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8A485000 \SystemRoot\system32\PSHED.dll
0x8A496000 \SystemRoot\system32\BOOTVID.dll
0x8A49E000 \SystemRoot\system32\CLFS.SYS
0x8A4DF000 \SystemRoot\system32\CI.dll
0x8A5BF000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8A63B000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8A648000 \SystemRoot\system32\drivers\acpi.sys
0x8A68E000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8A697000 \SystemRoot\system32\drivers\msisadrv.sys
0x8A69F000 \SystemRoot\system32\drivers\pci.sys
0x8A6C6000 \SystemRoot\System32\drivers\partmgr.sys
0x8A6D5000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8A6D8000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8A6E2000 \SystemRoot\system32\drivers\volmgr.sys
0x8A6F1000 \SystemRoot\System32\drivers\volmgrx.sys
0x8A73B000 \SystemRoot\System32\drivers\mountmgr.sys
0x8A80B000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8A8DB000 \SystemRoot\system32\drivers\atapi.sys
0x8A8E3000 \SystemRoot\system32\drivers\ataport.SYS
0x8A901000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A933000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A943000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8A9B4000 \SystemRoot\system32\drivers\ndis.sys
0x8AABF000 \SystemRoot\system32\drivers\msrpc.sys
0x8AAEA000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AC0B000 \SystemRoot\System32\drivers\tcpip.sys
0x8ACF5000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8AD10000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8AE20000 \SystemRoot\system32\drivers\volsnap.sys
0x8AE59000 \SystemRoot\System32\Drivers\spldr.sys
0x8AE61000 \SystemRoot\System32\Drivers\mup.sys
0x8AE70000 \SystemRoot\System32\drivers\ecache.sys
0x8AE97000 \SystemRoot\system32\drivers\disk.sys
0x8AEA8000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8AEC9000 \SystemRoot\system32\drivers\crcdisk.sys
0x8AED2000 \SystemRoot\system32\drivers\BMLoad.sys
0x8AFB5000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8AFC0000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8EC0A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8F33D000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F3DD000 \SystemRoot\System32\drivers\watchdog.sys
0x8F3E9000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8AB25000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8AFC9000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8AB63000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F800000 \SystemRoot\system32\DRIVERS\athr.sys
0x8F929000 \SystemRoot\system32\DRIVERS\yk60x86.sys
0x8F975000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8F979000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8F98C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F997000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8F9C5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F9C7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F9D2000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8F9EA000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8F9F0000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8F9FF000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8FA2E000 \SystemRoot\system32\DRIVERS\storport.sys
0x8FA6F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8FA7A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8FA91000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8FA9C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8FABF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8FACE000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8FAE2000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8FAF7000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FB07000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8FB09000 \SystemRoot\system32\DRIVERS\ks.sys
0x8FB33000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8FB3D000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8FB4A000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8FB7F000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8FC00000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8FE00000 \SystemRoot\system32\drivers\portcls.sys
0x8FE2D000 \SystemRoot\system32\drivers\drmk.sys
0x8FE52000 \SystemRoot\system32\drivers\nvhda32v.sys
0x8FE60000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8FE69000 \SystemRoot\System32\Drivers\Null.SYS
0x8FE70000 \SystemRoot\System32\Drivers\Beep.SYS
0x8FE80000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8FE87000 \SystemRoot\System32\drivers\vga.sys
0x8FE93000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8FEB4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8FEBC000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8FEC4000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8FECF000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8FEDD000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8FEE6000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8FEFC000 \SystemRoot\System32\Drivers\tcpipBM.SYS
0x8FF01000 \SystemRoot\system32\DRIVERS\smb.sys
0x8FF15000 \SystemRoot\system32\drivers\afd.sys
0x8FF5D000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8FF8F000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8FFA5000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8FFB3000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8FFC6000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8FB90000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8FFCC000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8FFD6000 \SystemRoot\System32\Drivers\dfsc.sys
0x8FBCC000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8FFED000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x8FFEF000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8FBE8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8FFF8000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8AFD8000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8AED8000 \SystemRoot\system32\DRIVERS\ewusbmdm.sys
0x8AF33000 \SystemRoot\System32\Drivers\VMC302.sys
0x8AF6F000 \SystemRoot\System32\Drivers\crashdmp.sys
0x94C0F000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9B470000 \SystemRoot\System32\win32k.sys
0x94CDF000 \SystemRoot\System32\drivers\Dxapi.sys
0x9B690000 \SystemRoot\System32\TSDDD.dll
0x9B6B0000 \SystemRoot\System32\cdd.dll
0x94CF8000 \SystemRoot\system32\drivers\luafv.sys
0x94D13000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x94D27000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
0x94D2F000 \SystemRoot\system32\drivers\spsys.sys
0x94DDF000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x94DEF000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x94E19000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x94E23000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x94E36000 \SystemRoot\system32\drivers\HTTP.sys
0x94EA3000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x94EB9000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x94ED6000 \SystemRoot\system32\DRIVERS\bowser.sys
0x94EEF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x94F04000 \SystemRoot\system32\drivers\mrxdav.sys
0x94F25000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x94F44000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x94F7D000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x94F95000 \SystemRoot\System32\DRIVERS\srv2.sys
0x8A74B000 \SystemRoot\System32\DRIVERS\srv.sys
0xA300C000 \SystemRoot\system32\drivers\peauth.sys
0xA30EA000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA30F4000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA31F7000 \SystemRoot\system32\DRIVERS\monitor.sys
0xA3206000 \SystemRoot\system32\DRIVERS\ewusbdev.sys
0xA3287000 \??\C:\Users\Sten\AppData\Local\Temp\kxldypog.sys
0xA32A0000 \SystemRoot\system32\drivers\modem.sys
0xA32AD000 \SystemRoot\system32\DRIVERS\ewusbnet.sys
0xA32CC000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xA32E1000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA32F6000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x771C0000 \Windows\System32\ntdll.dll

Processes (total 87):
0 System Idle Process
4 System
524 C:\Windows\System32\smss.exe
644 csrss.exe
696 C:\Windows\System32\wininit.exe
708 csrss.exe
740 C:\Windows\System32\services.exe
752 C:\Windows\System32\lsass.exe
760 C:\Windows\System32\lsm.exe
924 C:\Windows\System32\svchost.exe
988 C:\Windows\System32\nvvsvc.exe
1016 C:\Windows\System32\svchost.exe
1052 C:\Windows\System32\svchost.exe
1104 C:\Windows\System32\svchost.exe
1144 C:\Windows\System32\svchost.exe
1176 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\audiodg.exe
1256 C:\Windows\System32\svchost.exe
1272 C:\Windows\System32\SLsvc.exe
1320 C:\Windows\System32\svchost.exe
1416 C:\Windows\System32\winlogon.exe
1496 C:\Windows\System32\svchost.exe
1676 C:\Windows\System32\rundll32.exe
1812 C:\Windows\System32\wlanext.exe
1892 C:\Windows\System32\spoolsv.exe
1900 C:\Windows\System32\taskeng.exe
1932 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1992 C:\Windows\System32\svchost.exe
1000 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1172 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
688 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
1468 C:\Program Files\Bonjour\mDNSResponder.exe
1492 C:\Windows\System32\svchost.exe
1756 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
408 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
2124 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2140 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
2248 C:\Windows\System32\svchost.exe
2304 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
2340 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2408 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
2440 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2500 C:\Windows\System32\svchost.exe
2532 C:\Windows\System32\svchost.exe
2592 C:\Windows\System32\SearchIndexer.exe
3436 C:\Windows\System32\dwm.exe
3444 C:\Windows\System32\taskeng.exe
3496 C:\Windows\System32\taskeng.exe
3512 C:\Windows\explorer.exe
3520 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
3568 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
3644 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
3700 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
3936 C:\Windows\System32\rundll32.exe
3944 C:\Windows\RtHDVCpl.exe
3952 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3964 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
4052 C:\Windows\WindowsMobile\wmdc.exe
4068 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2288 C:\Program Files\Huawei Modems\DataCardMonitor.exe
2404 C:\Program Files\iTunes\iTunesHelper.exe
2952 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
1440 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
2928 C:\Windows\System32\wbem\unsecapp.exe
3424 WmiPrvSE.exe
3852 C:\Windows\System32\svchost.exe
3760 C:\Users\Sten\AppData\Roaming\T-Mobile Internet Manager\ouc.exe
3912 C:\Program Files\iPod\bin\iPodService.exe
4280 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5004 C:\Windows\System32\svchost.exe
516 C:\Windows\System32\VSSVC.exe
5588 C:\Windows\System32\svchost.exe
5864 C:\Windows\System32\wuauclt.exe
5176 C:\Users\Sten\Desktop\e4uuyzd4.exe
4440 C:\Windows\System32\notepad.exe
4340 C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe
4908 WUDFHost.exe
4364 C:\Program Files\T-Mobile\T-Mobile Internet Manager\bmctl.exe
4560 C:\Program Files\T-Mobile\T-Mobile Internet Manager\bmop.exe
4992 C:\Program Files\Mozilla Firefox\firefox.exe
2184 C:\Windows\System32\SearchProtocolHost.exe
5272 C:\Windows\System32\SearchFilterHost.exe
2036 C:\Windows\System32\conime.exe
4604 C:\Windows\explorer.exe
3864 dllhost.exe
5464 dllhost.exe
5496 C:\Users\***\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000026`85d00000 (NTFS)

PhysicalDrive0 Model Number: WDCWD3200BEVT-35ZCT0, Rev: 11.01A11

Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 898F3CF28E8EC7228D29035E39B672E205D702F2


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit: .

cosinus 03.05.2011 11:03

Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Vista installiert?
Wenn nicht: Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten).

Falls Du eine normale Vista-Installations-DVD hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der Vista-DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.

xdsgrrrrr 03.05.2011 15:47

Wird gemacht.

xdsgrrrrr 03.05.2011 15:53

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer: Phoenix Technologies Ltd.
System Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
System Product Name: R510/P510
Logical Drives Mask: 0x0000007c

Kernel Drivers (total 147):
0x8243C000 \SystemRoot\system32\ntoskrnl.exe
0x82409000 \SystemRoot\system32\hal.dll
0x8A409000 \SystemRoot\system32\kdcom.dll
0x8A410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8A480000 \SystemRoot\system32\PSHED.dll
0x8A491000 \SystemRoot\system32\BOOTVID.dll
0x8A499000 \SystemRoot\system32\CLFS.SYS
0x8A4DA000 \SystemRoot\system32\CI.dll
0x8A5BA000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8A636000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8A643000 \SystemRoot\system32\drivers\acpi.sys
0x8A689000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8A692000 \SystemRoot\system32\drivers\msisadrv.sys
0x8A69A000 \SystemRoot\system32\drivers\pci.sys
0x8A6C1000 \SystemRoot\System32\drivers\partmgr.sys
0x8A6D0000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8A6D3000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8A6DD000 \SystemRoot\system32\drivers\volmgr.sys
0x8A6EC000 \SystemRoot\System32\drivers\volmgrx.sys
0x8A736000 \SystemRoot\System32\drivers\mountmgr.sys
0x8A802000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8A8D2000 \SystemRoot\system32\drivers\atapi.sys
0x8A8DA000 \SystemRoot\system32\drivers\ataport.SYS
0x8A8F8000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A92A000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A93A000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8A9AB000 \SystemRoot\system32\drivers\ndis.sys
0x8AAB6000 \SystemRoot\system32\drivers\msrpc.sys
0x8AAE1000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AC02000 \SystemRoot\System32\drivers\tcpip.sys
0x8ACEC000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8AD07000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8AE17000 \SystemRoot\system32\drivers\volsnap.sys
0x8AE50000 \SystemRoot\System32\Drivers\spldr.sys
0x8AE58000 \SystemRoot\System32\Drivers\mup.sys
0x8AE67000 \SystemRoot\System32\drivers\ecache.sys
0x8AE8E000 \SystemRoot\system32\drivers\disk.sys
0x8AE9F000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8AEC0000 \SystemRoot\system32\drivers\crcdisk.sys
0x8AEC9000 \SystemRoot\system32\drivers\BMLoad.sys
0x8AFAC000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8AFB7000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8E40B000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8EB3E000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8EBDE000 \SystemRoot\System32\drivers\watchdog.sys
0x8EBEA000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8AFC0000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8AB1C000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8AB2B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F000000 \SystemRoot\system32\DRIVERS\athr.sys
0x8F129000 \SystemRoot\system32\DRIVERS\yk60x86.sys
0x8F175000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8F179000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8F18C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F197000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8F1C5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F1C7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F1D2000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8F1EA000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8F1F0000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8F1FF000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8F22E000 \SystemRoot\system32\DRIVERS\storport.sys
0x8F26F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8F27A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8F291000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8F29C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8F2BF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8F2CE000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F2E2000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8F2F7000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8F307000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8F309000 \SystemRoot\system32\DRIVERS\ks.sys
0x8F333000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8F33D000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8F34A000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8F37F000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8F404000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8F604000 \SystemRoot\system32\drivers\portcls.sys
0x8F631000 \SystemRoot\system32\drivers\drmk.sys
0x8F656000 \SystemRoot\system32\drivers\nvhda32v.sys
0x8F664000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F66D000 \SystemRoot\System32\Drivers\Null.SYS
0x8F674000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F684000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F68B000 \SystemRoot\System32\drivers\vga.sys
0x8F697000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F6B8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F6C0000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F6C8000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F6D3000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F6E1000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F6EA000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F700000 \SystemRoot\System32\Drivers\tcpipBM.SYS
0x8F705000 \SystemRoot\system32\DRIVERS\smb.sys
0x8F719000 \SystemRoot\system32\drivers\afd.sys
0x8F761000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F793000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8F7A9000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F7B7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F7CA000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8F390000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8F7D0000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F7DA000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F3CC000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8F7F1000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x8F7F3000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8F3E8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F67B000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8AECF000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8AEE6000 \SystemRoot\System32\Drivers\VMC302.sys
0x8AF22000 \SystemRoot\System32\Drivers\crashdmp.sys
0x90C0F000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x98870000 \SystemRoot\System32\win32k.sys
0x90CDF000 \SystemRoot\System32\drivers\Dxapi.sys
0x90CE9000 \SystemRoot\system32\DRIVERS\monitor.sys
0x98A90000 \SystemRoot\System32\TSDDD.dll
0x98AB0000 \SystemRoot\System32\cdd.dll
0x90CF8000 \SystemRoot\system32\drivers\luafv.sys
0x90D13000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x90D27000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
0x90D2F000 \SystemRoot\system32\drivers\spsys.sys
0x90DDF000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x90DEF000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x90E19000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x90E23000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x90E36000 \SystemRoot\system32\drivers\HTTP.sys
0x90EA3000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x90EC0000 \SystemRoot\system32\DRIVERS\bowser.sys
0x90ED9000 \SystemRoot\System32\drivers\mpsdrv.sys
0x90EEE000 \SystemRoot\system32\drivers\mrxdav.sys
0x90F0F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x90F2E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x90F67000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x90F7F000 \SystemRoot\System32\DRIVERS\srv2.sys
0x90FA7000 \SystemRoot\System32\DRIVERS\srv.sys
0xA0802000 \SystemRoot\system32\drivers\peauth.sys
0xA08E0000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA08EA000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA08F6000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xA090C000 \SystemRoot\system32\DRIVERS\ewusbdev.sys
0xA0925000 \SystemRoot\system32\DRIVERS\ewusbmdm.sys
0xA093F000 \SystemRoot\system32\drivers\modem.sys
0xA094C000 \SystemRoot\system32\DRIVERS\ewusbnet.sys
0xA096B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xA0980000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA0995000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x77B20000 \Windows\System32\ntdll.dll

Processes (total 89):
0 System Idle Process
4 System
440 C:\Windows\System32\smss.exe
508 csrss.exe
560 C:\Windows\System32\wininit.exe
572 csrss.exe
604 C:\Windows\System32\services.exe
616 C:\Windows\System32\lsass.exe
628 C:\Windows\System32\lsm.exe
788 C:\Windows\System32\svchost.exe
852 C:\Windows\System32\nvvsvc.exe
880 C:\Windows\System32\svchost.exe
940 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1004 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\svchost.exe
1104 C:\Windows\System32\audiodg.exe
1124 C:\Windows\System32\svchost.exe
1140 C:\Windows\System32\SLsvc.exe
1168 C:\Windows\System32\svchost.exe
1292 C:\Windows\System32\winlogon.exe
1452 C:\Windows\System32\rundll32.exe
1540 C:\Windows\System32\svchost.exe
1700 C:\Windows\System32\wlanext.exe
1776 C:\Windows\System32\taskeng.exe
1784 C:\Windows\System32\spoolsv.exe
1856 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1868 C:\Windows\System32\svchost.exe
300 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
324 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
476 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
488 C:\Program Files\Bonjour\mDNSResponder.exe
500 C:\Windows\System32\svchost.exe
716 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
1548 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
284 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2076 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
2160 C:\Windows\System32\svchost.exe
2188 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
2220 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2268 C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
2288 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
2324 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2344 C:\Windows\System32\svchost.exe
2392 C:\Windows\System32\svchost.exe
2420 C:\Windows\System32\SearchIndexer.exe
2884 C:\Windows\servicing\TrustedInstaller.exe
3588 C:\Windows\System32\taskeng.exe
3680 C:\Windows\System32\dwm.exe
3700 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
3720 C:\Windows\System32\taskeng.exe
3744 C:\Windows\explorer.exe
3852 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
3964 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
3996 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
2660 C:\Windows\System32\rundll32.exe
2668 C:\Windows\RtHDVCpl.exe
1368 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1272 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
1692 C:\Windows\WindowsMobile\wmdc.exe
696 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
2780 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2228 C:\Program Files\Huawei Modems\DataCardMonitor.exe
1528 C:\Program Files\iTunes\iTunesHelper.exe
2984 C:\Program Files\Windows Sidebar\sidebar.exe
972 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
2756 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
1152 C:\Program Files\Skype\Phone\Skype.exe
316 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
3280 C:\Windows\System32\svchost.exe
3076 C:\Windows\System32\SearchProtocolHost.exe
3732 C:\Windows\System32\wbem\unsecapp.exe
4080 WmiPrvSE.exe
3548 C:\Users\***\AppData\Roaming\T-Mobile Internet Manager\ouc.exe
2520 C:\Windows\System32\svchost.exe
3080 C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe
4036 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1516 C:\Program Files\iPod\bin\iPodService.exe
3256 WmiPrvSE.exe
2872 C:\Program Files\Skype\Plugin Manager\skypePM.exe
5656 C:\Program Files\T-Mobile\T-Mobile Internet Manager\bmctl.exe
5784 WUDFHost.exe
3572 C:\Program Files\T-Mobile\T-Mobile Internet Manager\bmop.exe
4188 C:\Program Files\Mozilla Firefox\firefox.exe
4212 C:\Windows\System32\wbem\WMIADAP.exe
5504 dllhost.exe
4228 dllhost.exe
5572 C:\Users\***\Desktop\MBRCheck.exe
4512 C:\Windows\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000026`85d00000 (NTFS)

PhysicalDrive0 Model Number: WDCWD3200BEVT-35ZCT0, Rev: 11.01A11

Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!

xdsgrrrrr 03.05.2011 16:57

GMER Logfile:
Code:

GMER 1.0.15.15572 - hxxp://www.gmer.net
Rootkit scan 2011-05-03 17:57:07
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: e4uuyzd4.exe; Driver: C:\Users\***\AppData\Local\Temp\kxldypog.sys


---- System - GMER 1.0.15 ----

SSDT            9CF8730C                                                                                                            ZwCreateThread
SSDT            9CF872F8                                                                                                            ZwOpenProcess
SSDT            9CF872FD                                                                                                            ZwOpenThread
SSDT            9CF87307                                                                                                            ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!KeInsertQueue + 411                                                                                    824A9A08 4 Bytes  [0C, 73, F8, 9C] {OR AL, 0x73; CLC ; PUSHF }
.text          ntoskrnl.exe!KeInsertQueue + 5E1                                                                                    824A9BD8 4 Bytes  [F8, 72, F8, 9C] {CLC ; JB 0xfffffffffffffffb; PUSHF }
.text          ntoskrnl.exe!KeInsertQueue + 5FD                                                                                    824A9BF4 4 Bytes  [FD, 72, F8, 9C] {STD ; JB 0xfffffffffffffffb; PUSHF }
.text          ntoskrnl.exe!KeInsertQueue + 811                                                                                    824A9E08 4 Bytes  [07, 73, F8, 9C] {POP ES; JAE 0xfffffffffffffffb; PUSHF }
.text          C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                                            section is writeable [0x8E40B340, 0x3EE687, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!SetScrollRange    7646D185 5 Bytes  JMP 001DB940 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!GetSysColorBrush  7646E21C 5 Bytes  JMP 001DBA30 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!GetScrollInfo    7646F073 7 Bytes  JMP 001DB810 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!ShowScrollBar    7646F8AE 5 Bytes  JMP 001DB990 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!SetScrollInfo    764771D8 7 Bytes  JMP 001DB8C0 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!GetSysColor      76479BF6 5 Bytes  JMP 001DB9D0 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!EnableScrollBar  7648AF53 7 Bytes  JMP 001DB7D0 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!GetScrollPos      7649337D 5 Bytes  JMP 001DB850 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!GetScrollRange    764934A5 5 Bytes  JMP 001DB880 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\T-Mobile\T-Mobile Internet Manager\T-Mobile Internet Manager.exe[3080] USER32.dll!SetScrollPos      76493602 5 Bytes  JMP 001DB900 C:\Program Files\T-Mobile\T-Mobile Internet Manager\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.)
.text          C:\Program Files\Mozilla Firefox\firefox.exe[4188] ntdll.dll!LdrLoadDll                                              77B493A8 5 Bytes  JMP 00241410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            \SystemRoot\System32\drivers\dxgkrnl.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\HDAudBus.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\CmBatt.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\i8042prt.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\kbdclass.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\mouclass.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\storport.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndistapi.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\termdd.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\swenum.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ks.sys[ntoskrnl.exe!IoCreateDevice]                                                    [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\mssmbios.sys[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\usbhub.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\drivers\portcls.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Fs_Rec.SYS[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Null.SYS[ntoskrnl.exe!IoCreateDevice]                                                  [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Beep.SYS[ntoskrnl.exe!IoCreateDevice]                                                  [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\drivers\VIDEOPRT.SYS[ntoskrnl.exe!IoCreateDevice]                                              [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Msfs.SYS[ntoskrnl.exe!IoCreateDevice]                                                  [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\Drivers\Npfs.SYS[ntoskrnl.exe!IoCreateDevice]                                                  [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\DRIVERS\rasacd.sys[ntoskrnl.exe!IoCreateDevice]                                                [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tdx.sys[ntoskrnl.exe!IoCreateDevice]                                                    [8AEC963E] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tdx.sys[TDI.SYS!TdiRegisterDeviceObject]                                                [8AEC9FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\system32\DRIVERS\smb.sys[TDI.SYS!TdiRegisterDeviceObject]                                                [8AEC9FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
IAT            \SystemRoot\System32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject]                                              [8AEC9FE6] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                [73D27817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                [73D7A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                            [73D2BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                      [73D1F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                [73D275E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                              [73D1E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                  [73D58395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                    [73D2DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                            [73D1FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                              [73D1FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                              [73D171CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                      [73DACAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                          [73D4C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                            [73D1D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                      [73D16853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                      [73D1687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3744] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                        [73D22AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                              tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002787923ce                                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1f37b91                                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1f5d89c                                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269cdd0c4                                         
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0002787923ce (not active ControlSet)                     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001fe1f37b91 (not active ControlSet)                     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001fe1f5d89c (not active ControlSet)                     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269cdd0c4 (not active ControlSet)                     

---- EOF - GMER 1.0.15 ----

--- --- ---

cosinus 04.05.2011 09:05

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

xdsgrrrrr 04.05.2011 16:39

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6504

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

04.05.2011 15:18:06
mbam-log-2011-05-04 (15-18-06).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 305778
Laufzeit: 1 Stunde(n), 10 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

cosinus 04.05.2011 17:55

Und das andere?

xdsgrrrrr 05.05.2011 10:24

Sorry hat leider etwas länger gedauert

SUPERAntiSpyware Scann-Protokoll
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generiert 05/05/2011 bei 11:16 AM

Version der Applikation : 4.51.1000

Version der Kern-Datenbank : 6985
Version der Spur-Datenbank : 4797

Scan Art : kompletter Scann
Totale Scann-Zeit : 01:56:02

Gescannte Speicherelemente : 751
Erfasste Speicher-Bedrohungen : 0
Gescannte Register-Elemente : 9642
Erfasste Register-Bedrohungen : 0
Gescannte Datei-Elemente : 149097
Erfasste Datei-Elemente : 0

cosinus 05.05.2011 11:25

Keine Funde :daumenhoc
Rechner wieder ok oder noch Probleme offen?

xdsgrrrrr 05.05.2011 12:25

Sieht gut aus, alles funktioniert und ist sichtbar. Vielen Dank !!!!! :dankeschoen: Jetzt erstmal das ganze Arbeitsgerät löschen ;-)

cosinus 05.05.2011 14:01

Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 23:46 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131