Grafiktreiber zerschossen, beim 2. Durchlauf keine Funde mehr: Code:
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
Database version: v2013.06.22.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16540
Xaver :: XAVER-PC [administrator]
22.06.2013 22:16:47
mbar-log-2013-06-22 (22-16-47).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 223640
Time elapsed: 5 minute(s), 15 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
c:\Program Files (x86)\Microsoft Office\Office12\GrooveUtil.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
Registry Keys Detected: 21
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Microsoft Office Groove Audit Service (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{7086AD76-44BD-11D0-81ED-00A0C90FC491} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\DiskManagement.UITasks (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\DiskManagement.UITasks (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7086AD76-44BD-11D0-81ED-00A0C90FC491} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{5D02926A-212E-11D0-9DF9-00A0C922E6EC} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\MSITFS (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\MSITFS (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5D02926A-212E-11D0-9DF9-00A0C922E6EC} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{9D148290-B9C8-11D0-A4CC-0000F80149F6} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\MSITStore (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\MSITStore (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9D148290-B9C8-11D0-A4CC-0000F80149F6} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{9D148291-B9C8-11D0-A4CC-0000F80149F6} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\ITSProtocol (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\ITSProtocol (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9D148291-B9C8-11D0-A4CC-0000F80149F6} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{D54EEE56-AAAB-11D0-9E1D-00A0C922E6EC} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\MSFSStore (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\MSFSStore (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D54EEE56-AAAB-11D0-9E1D-00A0C922E6EC} (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 17
C:\Windows\system32\drivers\atikmdag.sys (Unknown.Rootkit.Driver) -> Replace on reboot.
c:\Program Files (x86)\Microsoft Office\Office12\GrooveUtil.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\dmdlgs.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\itss.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\msihnd.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\pcwrun.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\PkgMgr.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\remotesp.tsp (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\sdhcinst.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\System32\wimserv.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\SysWOW64\odbc32.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\SysWOW64\odbcjt32.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Windows\SysWOW64\url.dll (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Replace on reboot.
c:\Users\Xaver\AppData\Local\Temp\Win7-64_Win7(7044)\WIN7\32\RtNicprop32.DLL (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
c:\Users\Xaver\Desktop\Goldvarb\GoldVarb.exe (Trojan.Dropper.bs ㄦ& RᝅSOUɒCE=핒T_D͉ALO瑇, 1器0, 35006500720079006500720079006500挷200贳4 &㜦 ST콒ING굓=%E%, 谶A60栠&& STRINGS=%PE2% + 3667, 446F776E6CF61㸶45C欷065넶C64瀷234☵C70퀶56C턶47239) -> Delete on reboot.
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
Database version: v2013.06.22.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16540
Xaver :: XAVER-PC [administrator]
22.06.2013 22:28:21
mbar-log-2013-06-22 (22-28-21).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 223297
Time elapsed: 7 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) |