Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Alles in Ordnung bei mir?HiJack-Log

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 27.08.2009, 04:26   #1
w00tw00t
 
Alles in Ordnung bei mir?HiJack-Log - Standard

Alles in Ordnung bei mir?HiJack-Log



Hey Leute. Ich wollt nur einmal wissen ob bei mir noch alles in Ordnung ist oder ob ihr irgendwelche Auffälligkeiten findet, bzw Optimierungstips für mich habt!!
Vielen Dank schonmal im Voraus=)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:16:59, on 27.08.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ICQ Away Reader\ICQ Away Reader.exe
C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Program Files\No-IP\DUC20.exe
C:\Program Files\Metasploit\Framework3\bin\ruby.exe
C:\Windows\system32\cmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: kikin Plugin - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ICQ Away Reader 1.4] C:\Program Files\ICQ Away Reader\ICQ Away Reader.exe
O4 - HKCU\..\Run: [ElcomSoft DPR Server] C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: (no name) - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll
O9 - Extra 'Tools' menuitem: My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f85b771c\aestsrv.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c9f5a6de289e70) (gupdate1c9f5a6de289e70) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f85b771c\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

--
End of file - 11525 bytes

Alt 27.08.2009, 05:40   #2
w00tw00t
 
Alles in Ordnung bei mir?HiJack-Log - Standard

Alles in Ordnung bei mir?HiJack-Log



Hier noch ein GMER log. GMER hat behauptet, dass es veränderungen durch Rootkits gefunden hat. =/

GMER 1.0.15.15077 [yucj4unq.exe] - http://www.gmer.net
Rootkit scan 2009-08-27 05:33:59
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.15 ----

SSDT 81478214 ZwCreateThread
SSDT 81478200 ZwOpenProcess
SSDT 81478205 ZwOpenThread
SSDT 8147820F ZwTerminateProcess

INT 0x52 ? 8704FBF8
INT 0x62 ? 85CF9BF8
INT 0x62 ? 85CF9BF8
INT 0x62 ? 85CF9BF8
INT 0x62 ? 85CF9BF8
INT 0x72 ? 8704FBF8
INT 0x92 ? 8704FBF8
INT 0xA2 ? 8704FBF8
INT 0xB3 ? 8704FBF8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetTimerEx + 454 81F00A68 4 Bytes [14, 82, 47, 81]
.text ntkrnlpa.exe!KeSetTimerEx + 624 81F00C38 4 Bytes [00, 82, 47, 81]
.text ntkrnlpa.exe!KeSetTimerEx + 640 81F00C54 4 Bytes [05, 82, 47, 81]
.text ntkrnlpa.exe!KeSetTimerEx + 854 81F00E68 4 Bytes [0F, 82, 47, 81]
? System32\Drivers\spev.sys Das System kann den angegebenen Pfad nicht finden. !
PAGE ataport.SYS!DllUnload 837ECB2E 5 Bytes JMP 85CF91D8
.text USBPORT.SYS!DllUnload 8B3CC46F 5 Bytes JMP 8704F1D8
.text ah6a6fe5.SYS 8FA63000 22 Bytes [26, C2, E1, 81, 10, C1, E1, ...]
.text ah6a6fe5.SYS 8FA63017 181 Bytes [00, 32, 87, 59, 83, 3D, 85, ...]
.text ah6a6fe5.SYS 8FA630CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...]
.text ah6a6fe5.SYS 8FA630DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
.text ah6a6fe5.SYS 8FA630E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
.text ...

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8348E6D6] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8348E042] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8348E800] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [8348E0C0] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8348E13E] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8349DE9C] \SystemRoot\System32\Drivers\spev.sys
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortNotification] CC358B04
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortWritePortUchar] 838FA88F
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8FA860
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortStallExecution] 54771129
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortRequestCallback] [8B55CC00] \SystemRoot\System32\Drivers\spldr.sys (loader for security processor/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortMoveMemory] [8B108910] \SystemRoot\System32\drivers\tcpip.sys (TCP/IP Driver/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortInitialize] B18D0502
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8
IAT \SystemRoot\System32\Drivers\ah6a6fe5.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 85D1F1F8
Device \FileSystem\fastfat \FatCdrom 8689A1F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 85CFB1F8
Device \Driver\usbuhci \Device\USBPDO-0 870491F8
Device \Driver\usbuhci \Device\USBPDO-1 870491F8
Device \Driver\usbehci \Device\USBPDO-2 8704A500
Device \Driver\usbuhci \Device\USBPDO-3 870491F8
Device \Driver\usbuhci \Device\USBPDO-4 870491F8
Device \Driver\usbuhci \Device\USBPDO-5 870491F8
Device \Driver\usbehci \Device\USBPDO-6 8704A500
Device \Driver\volmgr \Device\HarddiskVolume1 85CFB1F8
Device \Driver\volmgr \Device\HarddiskVolume2 85CFB1F8
Device \Driver\cdrom \Device\CdRom0 870821F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85CFE1F8
Device \Driver\atapi \Device\Ide\IdePort0 85CFE1F8
Device \Driver\atapi \Device\Ide\IdePort1 85CFE1F8
Device \Driver\atapi \Device\Ide\IdePort2 85CFE1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 85CFE1F8
Device \Driver\msahci \Device\Ide\PciIde0Channel0 85D001F8
Device \Driver\msahci \Device\Ide\PciIde0Channel4 85D001F8
Device \Driver\msahci \Device\Ide\PciIde0Channel5 85D001F8
Device \Driver\netbt \Device\NetBT_Tcpip_{24409E21-CA89-4726-A055-CD1F8AA5186F} 895101F8
Device \Driver\netbt \Device\NetBt_Wins_Export 895101F8
Device \Driver\Smb \Device\NetbiosSmb 8950F500
Device \Driver\sptd \Device\3311936653 spev.sys
Device \Driver\iScsiPrt \Device\RaidPort0 8724F500
Device \Driver\PCI_PNP8610 \Device\00000088 spev.sys
Device \Driver\usbuhci \Device\USBFDO-0 870491F8
Device \Driver\usbuhci \Device\USBFDO-1 870491F8
Device \Driver\usbehci \Device\USBFDO-2 8704A500
Device \Driver\usbuhci \Device\USBFDO-3 870491F8
Device \Driver\usbuhci \Device\USBFDO-4 870491F8
Device \Driver\netbt \Device\NetBT_Tcpip_{61D16A7C-4BB5-49ED-8F12-DFE3DDA25E5A} 895101F8
Device \Driver\usbuhci \Device\USBFDO-5 870491F8
Device \Driver\usbehci \Device\USBFDO-6 8704A500
Device \Driver\ah6a6fe5 \Device\Scsi\ah6a6fe51 870FD1F8
Device \FileSystem\fastfat \Fat 8689A1F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

Device \FileSystem\cdfs \Cdfs 94B4D1F8

---- Processes - GMER 1.0.15 ----

Process hidden process (*** hidden *** ) 5920
Process hidden process (*** hidden *** ) 6404
Process hidden process (*** hidden *** ) 12476
Process hidden process (*** hidden *** ) 12568
Process hidden process (*** hidden *** ) 13880
Process hidden process (*** hidden *** ) 13936

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002186dc4083
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x76 0x02 0x51 0x72 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x06 0xF7 0xF0 0x89 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCA 0x97 0x3F 0xBF ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002186dc4083 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x76 0x02 0x51 0x72 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x06 0xF7 0xF0 0x89 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCA 0x97 0x3F 0xBF ...

---- EOF - GMER 1.0.15 ----
__________________


Alt 29.08.2009, 13:36   #3
w00tw00t
 
Alles in Ordnung bei mir?HiJack-Log - Standard

Alles in Ordnung bei mir?HiJack-Log



Darf man hier pushen?
__________________

Antwort

Themen zu Alles in Ordnung bei mir?HiJack-Log
adobe, antivir, antivir guard, ask toolbar, ask.com, avg, avira, bho, defender, desktop, explorer, firefox, google, gupdate, hijack, hijackthis, internet, internet explorer, internet security, launch, menu.exe, mozilla, mp3, no-ip, nvidia, rundll, security, software, solution, system, vista, windows



Ähnliche Themen: Alles in Ordnung bei mir?HiJack-Log


  1. ist bei mir alles in ordnung?
    Log-Analyse und Auswertung - 17.11.2010 (15)
  2. Alles In Ordnung?
    Log-Analyse und Auswertung - 07.08.2009 (23)
  3. Ist alles in Ordnung?
    Log-Analyse und Auswertung - 03.02.2009 (0)
  4. Alles in Ordnung ?
    Mülltonne - 03.11.2008 (0)
  5. Alles in Ordnung ?
    Mülltonne - 22.09.2008 (0)
  6. Ist alles in ordnung?
    Log-Analyse und Auswertung - 09.05.2008 (2)
  7. Hijack Logfile Scan Ist alles in Ordnung?
    Mülltonne - 12.04.2008 (1)
  8. Hijack Log - Alles in Ordnung ?
    Log-Analyse und Auswertung - 20.08.2007 (6)
  9. Alles in Ordnung ??
    Log-Analyse und Auswertung - 03.04.2007 (4)
  10. alles in ordnung?
    Log-Analyse und Auswertung - 07.12.2006 (2)
  11. ist alles in ordnung???
    Mülltonne - 14.11.2006 (0)
  12. Alles in Ordnung?
    Mülltonne - 30.10.2006 (1)
  13. Alles In Ordnung??
    Plagegeister aller Art und deren Bekämpfung - 15.10.2006 (5)
  14. Alles in Ordnung bei mir?
    Log-Analyse und Auswertung - 21.01.2006 (1)
  15. Ist da alles in Ordnung?
    Log-Analyse und Auswertung - 14.04.2005 (2)
  16. Alles in Ordnung
    Log-Analyse und Auswertung - 04.12.2004 (1)
  17. Ist das alles in Ordnung?
    Log-Analyse und Auswertung - 09.11.2004 (3)

Zum Thema Alles in Ordnung bei mir?HiJack-Log - Hey Leute. Ich wollt nur einmal wissen ob bei mir noch alles in Ordnung ist oder ob ihr irgendwelche Auffälligkeiten findet, bzw Optimierungstips für mich habt!! Vielen Dank schonmal im - Alles in Ordnung bei mir?HiJack-Log...
Archiv
Du betrachtest: Alles in Ordnung bei mir?HiJack-Log auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.