![]() |
|
Plagegeister aller Art und deren Bekämpfung: TR/Kazy.mekml.1 auf dem Lappi...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #16 |
![]() | ![]() TR/Kazy.mekml.1 auf dem Lappi... GMER Logfile: Code:
ATTFilter GMER 1.0.15.15570 - GMER - Rootkit Detector and Remover Rootkit scan 2011-04-25 17:17:33 Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e WDC_WD800BEVS-07RST0 rev.04.01G04 Running: ljk1mz5b.exe; Driver: C:\DOKUME~1\Admin\LOKALE~1\Temp\awncauow.sys ---- System - GMER 1.0.15 ---- SSDT F7C9DB9E ZwCreateKey SSDT F7C9DB94 ZwCreateThread SSDT F7C9DBA3 ZwDeleteKey SSDT F7C9DBAD ZwDeleteValueKey SSDT F7C9DBB2 ZwLoadKey SSDT F7C9DB80 ZwOpenProcess SSDT F7C9DB85 ZwOpenThread SSDT F7C9DBBC ZwReplaceKey SSDT F7C9DBB7 ZwRestoreKey SSDT F7C9DBA8 ZwSetValueKey ---- Kernel code sections - GMER 1.0.15 ---- ? C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. ! ? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Programme\Mozilla Firefox\firefox.exe[6820] ntdll.dll!LdrLoadDll 7C925CBB 5 Bytes JMP 00401410 C:\Programme\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) .text C:\Programme\Mozilla Firefox\firefox.exe[6820] WS2_32.dll!connect 71A1406A 5 Bytes JMP 074B2850 C:\Programme\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll .text C:\Programme\Mozilla Firefox\firefox.exe[6820] WS2_32.dll!WSARecv 71A14318 5 Bytes JMP 074B41B0 C:\Programme\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll .text C:\Programme\Mozilla Firefox\firefox.exe[6820] WS2_32.dll!WSASend 71A16233 5 Bytes JMP 074B3CD0 C:\Programme\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll .text C:\Programme\Mozilla Firefox\firefox.exe[6820] WS2_32.dll!WSAConnect 71A20C69 5 Bytes JMP 074B2A50 C:\Programme\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Programme\Orbitdownloader\orbitdm.exe[460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00E12F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitdm.exe[460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00E12CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitdm.exe[460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00E12D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitdm.exe[460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00E12CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe[952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009B2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe[952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009B2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe[952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009B2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe[952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009B2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\sistray.exe[1276] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A72F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\sistray.exe[1276] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A72CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\sistray.exe[1276] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A72D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\sistray.exe[1276] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A72CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\WinZip\WZQKPICK.EXE[1480] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009F2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\WinZip\WZQKPICK.EXE[1480] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009F2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\WinZip\WZQKPICK.EXE[1480] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009F2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\WinZip\WZQKPICK.EXE[1480] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009F2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.exe[2172] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.exe[2172] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.exe[2172] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.exe[2172] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.bin[2244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [04ED2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.bin[2244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [04ED2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.bin[2244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [04ED2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\OpenOffice.org 3\program\soffice.bin[2244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [04ED2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitnet.exe[2952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AB2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitnet.exe[2952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AB2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitnet.exe[2952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AB2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Orbitdownloader\orbitnet.exe[2952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AB2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wscntfy.exe[2960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [008D2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wscntfy.exe[2960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [008D2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wscntfy.exe[2960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [008D2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wscntfy.exe[2960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [008D2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wuauclt.exe[3284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009B2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wuauclt.exe[3284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009B2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wuauclt.exe[3284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009B2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\system32\wuauclt.exe[3284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009B2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\RTHDCPL.EXE[3580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01A92F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\RTHDCPL.EXE[3580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01A92CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\RTHDCPL.EXE[3580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01A92D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\RTHDCPL.EXE[3580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01A92CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Avira\AntiVir Desktop\avgnt.exe[3800] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A62F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Avira\AntiVir Desktop\avgnt.exe[3800] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A62CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Avira\AntiVir Desktop\avgnt.exe[3800] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A62D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Avira\AntiVir Desktop\avgnt.exe[3800] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A62CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[3848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A92F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[3848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A92CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[3848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A92D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[3848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A92CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[3928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C32F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[3928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C32CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[3928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C32D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[3928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C32CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C72F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C72CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C72D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C72CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Mozilla Firefox\firefox.exe[6820] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01062F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Mozilla Firefox\firefox.exe[6820] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01062CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Mozilla Firefox\firefox.exe[6820] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01062D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\Programme\Mozilla Firefox\firefox.exe[6820] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01062CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\explorer.exe[7616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C32F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\explorer.exe[7616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C32CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\explorer.exe[7616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C32D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll IAT C:\WINDOWS\explorer.exe[7616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C32CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll ---- Processes - GMER 1.0.15 ---- Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Orbitdownloader\orbitdm.exe [460] 0x00E10000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe [952] 0x009B0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\WINDOWS\system32\sistray.exe [1276] 0x00A70000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\WinZip\WZQKPICK.EXE [1480] 0x009F0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\OpenOffice.org 3\program\soffice.exe [2172] 0x003D0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\OpenOffice.org 3\program\soffice.bin [2244] 0x04ED0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Orbitdownloader\orbitnet.exe [2952] 0x00AB0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\WINDOWS\system32\wscntfy.exe [2960] 0x008D0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\WINDOWS\system32\wuauclt.exe [3284] 0x009B0000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\WINDOWS\RTHDCPL.EXE [3580] 0x01A90000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Avira\AntiVir Desktop\avgnt.exe [3800] 0x00A60000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe [3848] 0x00A90000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [3928] 0x00C30000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [3960] 0x00C70000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\Programme\Mozilla Firefox\firefox.exe [6820] 0x01060000 Library C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (*** hidden *** ) @ C:\WINDOWS\explorer.exe [7616] 0x00C30000 ---- EOF - GMER 1.0.15 ---- danach kam diese meldung "WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity." und es war beendet OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 Online Solutions. Complex Protection for Information Systems Saved at 17:33:37 on 25.04.2011 OS: Windows XP Home Edition Service Pack 2 (Build 2600) Default Browser: Microsoft Corporation Internet Explorer 8.00.6001.18702 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "GoogleUpdateTaskUserS-1-5-21-1229272821-1957994488-839522115-1004Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe "GoogleUpdateTaskUserS-1-5-21-1229272821-1957994488-839522115-1004UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl "javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "Avira AntiVir Personal" - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys "avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys "awncauow" (awncauow) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\awncauow.sys (Hidden registry entry, rootkit activity | File not found) "catchme" (catchme) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys (File not found) "Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found) "i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys (File not found) "lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found) "mbr" (mbr) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\mbr.sys (Hidden registry entry, rootkit activity | File not found) "PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found) "PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found) "PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found) "PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found) "PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found) "Secdrv" (Secdrv) - ? - C:\WINDOWS\System32\DRIVERS\secdrv.sys (File signed by Microsoft | File found, but it contains no detailed information) "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys "WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found) [Explorer] -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )----- {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll -----( HKLM\Software\Classes\Protocols\Filter )----- {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll -----( HKLM\Software\Classes\Protocols\Handler )----- {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL {91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll {42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll (File not found) {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found) {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found) {32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? - (File not found | COM-object registry key not found) {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll {764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found) {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll {E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Programme\WinZip\wzshlstb.dll {E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Programme\WinZip\wzshlstb.dll {E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Programme\WinZip\wzshlstb.dll {E0D79307-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Programme\WinZip\wzshlstb.dll [Internet Explorer] -----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )----- {32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? - (File not found | COM-object registry key not found) -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- <binary data> "Google Toolbar" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) <binary data> "ITBarLayout" - ? - (File not found | COM-object registry key not found) -----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )----- "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? - (File not found | COM-object registry key not found) {855F3B16-6D32-4fe6-8A56-BBB695989046} "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- "ICQ7.4" - "ICQ, LLC." - C:\Programme\ICQ7.4\ICQ.exe {898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Plug-In" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- <binary data> "Google Toolbar" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll <binary data> "Grab Pro" - ? - C:\Programme\Orbitdownloader\GrabPro.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll {AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Programme\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll {E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll {000123B4-9B42-4900-B3F7-F4B073EFC214} "Octh Class" - "Orbitdownloader.com" - C:\Programme\Orbitdownloader\orbitcth.dll {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Plug-In" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [Logon] -----( %AllUsersProfile%\Startmenü\Programme\Autostart )----- "Adobe Reader - Schnellstart.lnk" - "Adobe Systems Incorporated" - C:\Programme\Adobe\Reader 8.0\Reader\reader_sl.exe (Shortcut exists | File exists) "Adobe Reader Synchronizer.lnk" - "Adobe Systems Incorporated" - C:\Programme\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe (Shortcut exists | File exists) "desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini "Orbit.lnk" - "Orbitdownloader.com" - C:\Programme\Orbitdownloader\orbitdm.exe (Shortcut exists | File exists) "Utility Tray.lnk" - "Silicon Integrated Systems Corporation" - C:\WINDOWS\system32\sistray.exe (Shortcut exists | File exists) "WinZip Quick Pick.lnk" - "WinZip Computing, S.L." - C:\Programme\WinZip\WZQKPICK.EXE (Shortcut exists | File exists) -----( %UserProfile%\Startmenü\Programme\Autostart )----- "desktop.ini" - ? - C:\Dokumente und Einstellungen\Admin\Startmenü\Programme\Autostart\desktop.ini "OpenOffice.org 3.3.lnk" - ? - C:\Programme\OpenOffice.org 3\program\quickstart.exe (Shortcut exists | File found, but it contains no detailed information | File exists) -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "swg" - "Google Inc." - "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "avgnt" - "Avira GmbH" - "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min "LogitechCommunicationsManager" - "Logitech Inc." - "C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe" "SiSPower" - "Silicon Integrated Systems Corporation" - Rundll32.exe SiSPower.dll,ModeAgent "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe "Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll (File not found) "ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe "Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe "Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe "Google Software Updater" (gusvc) - "Google" - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe "Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe "ICQ Service" (ICQ Service) - ? - C:\Programme\ICQ6Toolbar\ICQ Service.exe "Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe "LVCOMSer" (LVCOMSer) - "Logitech Inc." - C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe "Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe "Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe "Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [Winlogon] -----( HKCU\Control Panel\IOProcs )----- "MVB" - ? - mvfs32.dll (File not found) -----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )----- {c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll (File not found) ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit Online Solutions :: Index |
Themen zu TR/Kazy.mekml.1 auf dem Lappi... |
antivir, bli, computer, computern, critical hard disk drive error, datei, error, fehler, fenster, festplatte, geräusch, hard disk, hardware, hilflos, ide, min, neu, platte, problem, proggi, rechts, sachen, software, speicher, stimme, system, system neu, system32, tr/kazy.mekml.1, täglich, verursacht |