Hier die neuesten Posts - Gmer Code:
GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-06-05 23:38:54
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5 STM3500418AS rev.CC37
Running: w93ct4ho.exe; Driver: C:\DOKUME~1\Johannes\LOKALE~1\Temp\pxtdqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8F19360, 0x3541AF, 0xE8000020]
? system32\drivers\xpsec.sys Das System kann den angegebenen Pfad nicht finden. !
? system32\drivers\xcpip.sys Das System kann den angegebenen Pfad nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[288] WS2_32.dll!closesocket 71A13E2B 5 Bytes JMP 00ED9E0A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[288] WS2_32.dll!send 71A14C27 5 Bytes JMP 00ED99A7
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[288] WS2_32.dll!WSARecv 71A14CB5 5 Bytes JMP 00ED9CBC
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[288] WS2_32.dll!recv 71A1676F 5 Bytes JMP 00ED9A88
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[288] WS2_32.dll!WSASend 71A168FA 5 Bytes JMP 00ED9B5B
.text C:\WINDOWS\System32\alg.exe[408] WS2_32.dll!closesocket 71A13E2B 5 Bytes JMP 00BA9E0A
.text C:\WINDOWS\System32\alg.exe[408] WS2_32.dll!send 71A14C27 5 Bytes JMP 00BA99A7
.text C:\WINDOWS\System32\alg.exe[408] WS2_32.dll!WSARecv 71A14CB5 5 Bytes JMP 00BA9CBC
.text C:\WINDOWS\System32\alg.exe[408] WS2_32.dll!recv 71A1676F 5 Bytes JMP 00BA9A88
.text C:\WINDOWS\System32\alg.exe[408] WS2_32.dll!WSASend 71A168FA 5 Bytes JMP 00BA9B5B
.text C:\WINDOWS\Explorer.EXE[1056] USER32.dll!DisplayExitWindowsWarnings 7E3A9F91 5 Bytes JMP 02E72758
.text C:\WINDOWS\Explorer.EXE[1056] WS2_32.dll!closesocket 71A13E2B 5 Bytes JMP 01F49E0A
.text C:\WINDOWS\Explorer.EXE[1056] WS2_32.dll!send 71A14C27 5 Bytes JMP 01F499A7
.text C:\WINDOWS\Explorer.EXE[1056] WS2_32.dll!WSARecv 71A14CB5 5 Bytes JMP 01F49CBC
.text C:\WINDOWS\Explorer.EXE[1056] WS2_32.dll!recv 71A1676F 5 Bytes JMP 01F49A88
.text C:\WINDOWS\Explorer.EXE[1056] WS2_32.dll!WSASend 71A168FA 5 Bytes JMP 01F49B5B
.text C:\WINDOWS\system32\winlogon.exe[1340] Secur32.dll!LsaLogonUser 77FC33D8 5 Bytes JMP 01292946
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0xF5 0x6A 0x4A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x55 0x82 0x45 0xCE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x10 0xC1 0x36 0x71 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xBF 0xF4 0xEF 0xF4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x0F 0xDC 0xB6 0xDE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xAF 0x91 0xA1 0xED ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0xF5 0x6A 0x4A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x55 0x82 0x45 0xCE ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x10 0xC1 0x36 0x71 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xBF 0xF4 0xEF 0xF4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x0F 0xDC 0xB6 0xDE ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xAF 0x91 0xA1 0xED ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 976752003
Disk \Device\Harddisk0\DR0 PE file @ sector 976752025
Disk \Device\Harddisk0\DR0 MBRoot/Sinowal@MBR code has been found <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ---- Osam: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 23:48:49 on 05.06.2011
OS: Windows XP Professional Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 6.00.2900.5512
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskUserS-1-5-21-1390067357-1957994488-682003330-1003Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Johannes\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1390067357-1957994488-682003330-1003UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Johannes\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Computer, Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AsIO" (AsIO) - ? - C:\WINDOWS\System32\drivers\AsIO.sys (File found, but it contains no detailed information)
"catchme" (catchme) - ? - C:\DOKUME~1\Johannes\LOKALE~1\Temp\catchme.sys (File not found)
"Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - "Cisco Systems, Inc." - C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
"ElbyCDFL" (ElbyCDFL) - "SlySoft, Inc." - C:\WINDOWS\System32\Drivers\ElbyCDFL.sys
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
"IPSEC-Treiber" (xpsec) - ? - C:\WINDOWS\system32\drivers\xpsec.sys (File not found)
"McAfee Inc." (mfeapfk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfeapfk.sys
"McAfee Inc." (mfeavfk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfeavfk.sys
"McAfee Inc." (mfebopk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfebopk.sys
"McAfee Inc." (mfehidk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfehidk.sys
"McAfee Inc." (mfetdik) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfetdik.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found)
"pxtdqpow" (pxtdqpow) - ? - C:\DOKUME~1\Johannes\LOKALE~1\Temp\pxtdqpow.sys (Hidden registry entry, rootkit activity | File not found)
"Shrew Soft Miniport Filter" (pflt) - "Shrew Soft Inc" - C:\WINDOWS\System32\DRIVERS\vfilter.sys
"Shrew Soft Virtual Adapter" (vnet) - "Shrew Soft Inc" - C:\WINDOWS\System32\DRIVERS\virtualnet.sys
"TCP/IP-Protokolltreiber" (xcpip) - ? - C:\WINDOWS\system32\drivers\xcpip.sys (File not found)
"VSCore mferkdk" (mferkdk) - "McAfee, Inc." - C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys
"vsdatant" (vsdatant) - "Zone Labs LLC" - C:\WINDOWS\system32\vsdatant.sys
[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2} "PixiePack Codec Pack 1.1.1200.0" - ? - C:\Programme\PixiePack Codec Pack\InstallerHelper.exe
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL
{CD00020A-8B95-11D1-82DB-00C04FB1625D} "Microsoft PKM KnowledgePluggable Class" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office10\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
<binary data> "ITBarLayout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_18" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_18.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} "Java Plug-in 1.6.0_18" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_18.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_18" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_18.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
AutorunsDisabled "AutorunsDisabled" - ? - (File not found | COM-object registry key not found)
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Programme\McAfee\VirusScan Enterprise\Scriptcl.dll
[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\Johannes\Startmenü\Programme\Autostart\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"McAfeeUpdaterUI" - "McAfee, Inc." - "C:\Programme\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"QuickTime Task" - "Apple Computer, Inc." - "C:\Programme\QuickTime\qttask.exe" -atboottime
"ShStatEXE" - "McAfee, Inc." - "C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
"Six Engine" - ? - "C:\Programme\ASUS\EPU-4 Engine\FourEngine.exe" -r
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Adobe PDF Port" - "Adobe Systems Incorporated." - C:\WINDOWS\system32\AdobePDF.dll
"VSP1:" - ? - C:\WINDOWS\system32\vsmon1.dll (File found, but it contains no detailed information)
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Cisco Systems, Inc. VPN Service" (CVPND) - ? - "C:\Programme\Cisco Systems\VPN Client\cvpnd.exe" (File not found)
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
"Java Quick Starter" (JavaQuickStarterService) - ? - "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" (File not found)
"Machine Debug Manager" (MDM) - ? - "C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe" (File not found)
"McAfee Framework Service" (McAfeeFramework) - ? - "C:\Programme\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (File not found)
"McAfee McShield" (McShield) - ? - "C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe" (File not found)
"McAfee Task Manager" (McTaskManager) - ? - "C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe" (File not found)
"NVIDIA Display Driver Service" (NVSvc) - ? - C:\WINDOWS\system32\nvsvc32.exe (File not found)
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - C:\Programme\ShrewSoft\VPN Client\dtpd.exe -service (File not found)
"ShrewSoft IKE Daemon" (iked) - ? - C:\Programme\ShrewSoft\VPN Client\iked.exe -service (File not found)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - C:\Programme\ShrewSoft\VPN Client\ipsecd.exe -service (File not found)
"Sony Ericsson OMSI download service" (OMSI download service) - ? - C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe (File not found)
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll (File not found)
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru MBR-Check: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000043c
Kernel Drivers (total 130):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F78000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F67000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9F48000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F22000 dmio.sys
0xBA330000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xB9F0A000 atapi.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9EEA000 fltMgr.sys
0xB9ED8000 sr.sys
0xB9EC1000 KSecDD.sys
0xB9E34000 Ntfs.sys
0xB9E07000 NDIS.sys
0xB9DED000 Mup.sys
0xBA258000 \SystemRoot\system32\DRIVERS\AmdPPM.sys
0xB9676000 \SystemRoot\system32\DRIVERS\parport.sys
0xBA5EC000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0xBA268000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xBA3E8000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xBA278000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA594000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA598000 \SystemRoot\system32\DRIVERS\nvsmu.sys
0xBA3F0000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xB9652000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA3F8000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB962A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xBA288000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA400000 \SystemRoot\System32\Drivers\ElbyCDFL.sys
0xBA298000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB9607000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA2B8000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xB951D000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xB8F19000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB8F05000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xBA5A0000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0xB8EE7000 \SystemRoot\system32\DRIVERS\dne2000.sys
0xBA70B000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA408000 \SystemRoot\system32\DRIVERS\vfilter.sys
0xBA2C8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB9DC5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8ED0000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA2D8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA2E8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA410000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB8EBF000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA2F8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA418000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA420000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB8DEF000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA318000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA428000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA430000 \SystemRoot\system32\DRIVERS\seehcri.sys
0xBA5F0000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8D91000 \SystemRoot\system32\DRIVERS\update.sys
0xB9DA9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA138000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA148000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xBA5F4000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA158000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
0xB6672000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xB664E000 \SystemRoot\system32\drivers\portcls.sys
0xBA178000 \SystemRoot\system32\drivers\drmk.sys
0xBA188000 \SystemRoot\system32\drivers\nvhda32.sys
0xBA5FC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA7AC000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5FE000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA460000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA468000 \SystemRoot\System32\drivers\vga.sys
0xBA600000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA602000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA470000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA478000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA580000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xB6586000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB652D000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xBA198000 \SystemRoot\system32\drivers\mfetdik.sys
0xB6507000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xB64DF000 \SystemRoot\system32\DRIVERS\netbt.sys
0xBA1A8000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xB64BD000 \SystemRoot\System32\drivers\afd.sys
0xBA1B8000 \SystemRoot\system32\DRIVERS\netbios.sys
0xB63F2000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xB6382000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA480000 \??\C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys
0xBA1D8000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA488000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0xBA604000 \SystemRoot\system32\drivers\AsIO.sys
0xBA490000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xB6C85000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xBA208000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xB6C7D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xBA498000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xB6349000 \SystemRoot\System32\Drivers\Udfs.SYS
0xB6331000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA606000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB663E000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA4A8000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA6F0000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xB610D000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xB5F92000 \SystemRoot\system32\drivers\xpsec.sys
0xB5FB9000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xB5E49000 \SystemRoot\system32\drivers\xcpip.sys
0xB5BC4000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xBA5BA000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB5B0C000 \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
0xB597A000 \SystemRoot\system32\DRIVERS\srv.sys
0xBA3A0000 \SystemRoot\System32\Drivers\TDTCP.SYS
0xB5817000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xB5802000 \SystemRoot\system32\drivers\wdmaud.sys
0xB5A4C000 \SystemRoot\system32\drivers\sysaudio.sys
0xB53B1000 \SystemRoot\System32\Drivers\HTTP.sys
0xB5168000 \??\C:\DOKUME~1\Johannes\LOKALE~1\Temp\pxtdqpow.sys
0xB513D000 \SystemRoot\system32\drivers\kmixer.sys
0x7C910000 \WINDOWS\system32\ntdll.dll
Processes (total 19):
0 System Idle Process
4 System
1264 C:\WINDOWS\system32\smss.exe
1312 csrss.exe
1340 C:\WINDOWS\system32\winlogon.exe
1384 C:\WINDOWS\system32\services.exe
1396 C:\WINDOWS\system32\lsass.exe
1576 C:\WINDOWS\system32\svchost.exe
1644 svchost.exe
1792 C:\WINDOWS\system32\svchost.exe
1880 svchost.exe
224 svchost.exe
424 C:\WINDOWS\system32\spoolsv.exe
1216 C:\WINDOWS\system32\svchost.exe
408 alg.exe
1252 C:\WINDOWS\system32\wscntfy.exe
2268 C:\WINDOWS\system32\rundll32.exe
1064 C:\WINDOWS\explorer.exe
3628 C:\Dokumente und Einstellungen\Johannes\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000009`c3dcd400 (NTFS)
\\.\F: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)
\\.\K: --> \\.\PhysicalDrive0 at offset 0x00000022`2dc26c00 (NTFS)
PhysicalDrive0 Model Number: STM3500418AS, Rev: CC37
PhysicalDrive1 Model Number: WD5000AAV External, Rev: 1.65
Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked (known infection: Whistler / Black Internet)!
SHA1: F2D69AC1D2BB63F5714B514748C7EBBD7C6A806B
465 GB \\.\PhysicalDrive1 RE: Western Digital MBR code detected
SHA1: CCCF1B32EE08ECFB66B30883CFF6110F69219FEA
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done! Merci und schönen Wochenauftakt!
Jo |