RootKitRevealer:
Code:
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40 16.10.2005 08:51 0 bytes Hidden from Windows API.
Blacklight:
Code:
12/02/05 21:26:31 [Info]: BlackLight Engine 1.0.25 initialized
12/02/05 21:26:31 [Info]: OS: 5.1 build 2600 ()
12/02/05 21:26:31 [Note]: 4019 4
12/02/05 21:26:31 [Note]: 4005 0
12/02/05 21:26:37 [Note]: 4006 0
12/02/05 21:26:37 [Note]: 4011 1116
12/02/05 21:26:38 [Note]: FSRAW library version 1.7.1013
12/02/05 21:27:24 [Note]: 4007 0
AS Viewer:
Code:
DiamondCS Autostart Viewer (www.diamondcs.com.au) - Report for Christian@RICHRIS-RSLZOWJ, 12-02-2005
c:\autoexec.bat
PATH=%PATH%;C:\PROGRA~1\GEMEIN~1\MUVEET~1\030625
c:\windows\system32\autoexec.nt
C:\WINDOWS\system32\mscdexnt.exe
C:\WINDOWS\system32\redir.exe
C:\WINDOWS\system32\dosx.exe
c:\windows\system32\config.nt
REM Die EMM-Größe wird in der PIF-Datei (entweder die Datei _DEFAULT.PIF
C:\WINDOWS\system32\himem.sys
c:\windows\system.ini [drivers]
timer=timer.drv
c:\windows\system.ini [boot]\shell
C:\WINDOWS\Explorer.exe
c:\windows\system.ini [boot]\scrnsave.exe
C:\WINDOWS\System32\logon.scr
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
C:\WINDOWS\Explorer.exe
HKCU\Control Panel\Desktop\scrnsave.exe
C:\WINDOWS\System32\logon.scr
HKCR\vbsfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\vbefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\jsfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\jsefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wshfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wsffile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Trojancheck 6 Guard
C:\Programme\Trojancheck 6\tcguard.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AVGCtrl
C:\Programme\AVPersonal\AVGNT.EXE /min
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\!1_pgaccount
C:\Programme\ProcessGuard\pgaccount.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\!1_ProcessGuard_Startup
C:\Programme\ProcessGuard\procguard.exe
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
C:\WINDOWS\System32\CTFMON.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\stobject.dll
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\CAPIControl.lnk
C:\Programme\Telekom\Eumex 404PC\Capictrl.exe
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
HKLM\System\CurrentControlSet\Control\WOW\cmdline
C:\WINDOWS\system32\ntvdm.exe
HKLM\System\CurrentControlSet\Control\WOW\wowcmdline
C:\WINDOWS\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rsvpsp.dll
Process Guard:
Code:
---Process Guard Log Started---
Fri 02 - 20:57:01 [EXECUTION] "c:\windows\system32\svchost.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\services.exe" [540]
[EXECUTION] Commandline - [ c:\windows\system32\svchost.exe -k imgsvc ]
Fri 02 - 20:57:02 [EXECUTION] "c:\windows\system32\wdfmgr.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\services.exe" [540]
[EXECUTION] Commandline - [ c:\windows\system32\wdfmgr.exe ]
Fri 02 - 20:57:03 [EXECUTION] "c:\windows\system32\zonelabs\vsmon.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\services.exe" [540]
[EXECUTION] Commandline - [ c:\windows\system32\zonelabs\vsmon.exe -service ]
Fri 02 - 20:57:07 [EXECUTION] "c:\programme\trojancheck 6\tcguard.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\trojancheck 6\tcguard.exe" ]
Fri 02 - 20:57:07 [EXECUTION] "c:\windows\system32\rundll32.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\windows\system32\rundll32.exe" c:\windows\system32\nvcpl.dll,nvstartup ]
Fri 02 - 20:57:07 [EXECUTION] "c:\programme\avpersonal\avgnt.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\avpersonal\avgnt.exe" /min ]
Fri 02 - 20:57:07 [EXECUTION] "c:\programme\processguard\pgaccount.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\processguard\pgaccount.exe" ]
Fri 02 - 20:57:08 [EXECUTION] "c:\programme\processguard\procguard.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\processguard\procguard.exe" -minimize ]
Fri 02 - 20:57:08 [EXECUTION] "c:\programme\telekom\eumex 404pc\capictrl.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\telekom\eumex 404pc\capictrl.exe" ]
Fri 02 - 20:57:45 [EXECUTION] "c:\windows\system32\rundll32.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\windows\system32\rundll32.exe" shell32.dll,control_rundll "c:\windows\system32\appwiz.cpl",software ]
Fri 02 - 20:58:06 [EXECUTION] "c:\programme\regcleaner\regcleanr.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\regcleaner\regcleanr.exe" ]
Fri 02 - 20:59:12 [EXECUTION] "c:\programme\rootkitrevealer\rootkitrevealer.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\rootkitrevealer\rootkitrevealer.exe" ]
Fri 02 - 20:59:12 [EXECUTION] "c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\services.exe" [540]
[EXECUTION] Commandline - [ c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe ]
Fri 02 - 21:00:01 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe" [1632]
[EXECUTION] Commandline - [ cmd /c chcp 65001 && set dircmd= && "cmd /c dir /4 /a /s c:\ > c:\windows\system32\averc" ]
Fri 02 - 21:00:02 [EXECUTION] "c:\windows\system32\chcp.com" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [1672]
[EXECUTION] Commandline - [ chcp 65001 ]
Fri 02 - 21:00:02 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [1672]
[EXECUTION] Commandline - [ "cmd /c dir /4 /a /s c:\ > c:\windows\system32\averc" ]
Fri 02 - 21:07:19 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp57\a0039237.exe" "ist das trojanische pferd tr/dldr.sma.bfy.5.a" 0 sound 0 0 ]
Fri 02 - 21:08:16 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp57\a0039240.exe" "ist das trojanische pferd tr/drop.age.abo.1.b" 0 sound 0 0 ]
Fri 02 - 21:08:22 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp57\a0039241.exe" "enthält signatur des droppers dr/small.bws" 0 sound 0 0 ]
Fri 02 - 21:08:26 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp58\a0039481.exe" "ist das trojanische pferd tr/pakes.a.231" 0 sound 0 0 ]
Fri 02 - 21:08:39 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp62\a0041634.sys" "ist das trojanische pferd tr/rootkit.l" 0 sound 0 0 ]
Fri 02 - 21:08:45 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp62\a0041642.exe" "enthält signatur des wurmes worm/agobot.60928.3" 0 sound 0 0 ]
Fri 02 - 21:08:48 [EXECUTION] "c:\programme\avpersonal\guardgui.exe" was allowed to run
[EXECUTION] Started by "c:\programme\avpersonal\avguard.exe" [1360]
[EXECUTION] Commandline - [ c:\programme\avpersonal\guardgui.exe rtvirus "
%s
%s" "c:\system volume information\_restore{d8a47826-d784-45a4-8ed9-0fd84cf728e8}\rp62\a0041673.sys" "ist das trojanische pferd tr/rootkit.l" 0 sound 0 0 ]
Fri 02 - 21:08:56 [EXECUTION] "c:\programme\zone labs\zonealarm\zlclient.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\zone labs\zonealarm\zlclient.exe" ]
Fri 02 - 21:14:16 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe" [1632]
[EXECUTION] Commandline - [ cmd /c chcp 65001 && set dircmd= && "cmd /c dir /4 /a /s d:\ > c:\windows\system32\zgmsfjx" ]
Fri 02 - 21:14:17 [EXECUTION] "c:\windows\system32\chcp.com" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [752]
[EXECUTION] Commandline - [ chcp 65001 ]
Fri 02 - 21:14:17 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [752]
[EXECUTION] Commandline - [ "cmd /c dir /4 /a /s d:\ > c:\windows\system32\zgmsfjx" ]
Fri 02 - 21:20:54 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe" [1632]
[EXECUTION] Commandline - [ cmd /c chcp 65001 && set dircmd= && "cmd /c dir /4 /a /s e:\ > c:\windows\system32\bqtblbm" ]
Fri 02 - 21:20:55 [EXECUTION] "c:\windows\system32\chcp.com" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [1076]
[EXECUTION] Commandline - [ chcp 65001 ]
Fri 02 - 21:20:55 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [1076]
[EXECUTION] Commandline - [ "cmd /c dir /4 /a /s e:\ > c:\windows\system32\bqtblbm" ]
Fri 02 - 21:24:27 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\dokume~1\christ~1\lokale~1\temp\rimdg.exe" [1632]
[EXECUTION] Commandline - [ cmd /c chcp 65001 && set dircmd= && "cmd /c dir /4 /a /s f:\ > c:\windows\system32\ciqbyl" ]
Fri 02 - 21:24:27 [EXECUTION] "c:\windows\system32\chcp.com" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [824]
[EXECUTION] Commandline - [ chcp 65001 ]
Fri 02 - 21:24:27 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run
[EXECUTION] Started by "c:\windows\system32\cmd.exe" [824]
[EXECUTION] Commandline - [ "cmd /c dir /4 /a /s f:\ > c:\windows\system32\ciqbyl" ]
Fri 02 - 21:25:49 [EXECUTION] "c:\windows\system32\notepad.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ c:\windows\system32\notepad.exe c:\rootkitreveal.txt ]
Fri 02 - 21:26:25 [EXECUTION] "c:\programme\blacklight\blbeta.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\blacklight\blbeta.exe" ]
Fri 02 - 21:26:26 [EXECUTION] "c:\programme\blacklight\blbeta.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [1856]
[EXECUTION] Commandline - [ "c:\programme\blacklight\blbeta.exe" /q ]
Fri 02 - 21:27:27 [EXECUTION] "c:\windows\system32\notepad.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ c:\windows\system32\notepad.exe c:\programme\blacklight\fsbl-20051202202631.log ]
Fri 02 - 21:27:53 [EXECUTION] "c:\programme\process explorer\procexp.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\process explorer\procexp.exe" ]
Fri 02 - 21:28:51 [EXECUTION] "c:\windows\system32\notepad.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ c:\windows\system32\notepad.exe c:\dokumente und einstellungen\christian\desktop\procexp.txt ]
Fri 02 - 21:29:06 [EXECUTION] "c:\programme\autostart viewer\asviewer.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\autostart viewer\asviewer.exe" ]
Fri 02 - 21:29:21 [EXECUTION] "c:\windows\system32\notepad.exe" was allowed to run
[EXECUTION] Started by "c:\programme\autostart viewer\asviewer.exe" [464]
[EXECUTION] Commandline - [ notepad.exe "c:\programme\autostart viewer\asviewer.txt" ]
Fri 02 - 21:29:56 [EXECUTION] "c:\programme\processguard\procguard.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1116]
[EXECUTION] Commandline - [ "c:\programme\processguard\procguard.exe" ]
Process Explorer:
Code:
Process PID CPU Description Company Name
System Idle Process 0 81.43
Interrupts n/a Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4 1.43
smss.exe 404 Windows NT Session Manager Microsoft Corporation
csrss.exe 472 Client Server Runtime Process Microsoft Corporation
winlogon.exe 496 Windows NT Logon Application Microsoft Corporation
services.exe 540 1.43 Anwendung für Dienste und Controller Microsoft Corporation
svchost.exe 728 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 772 Generic Host Process for Win32 Services Microsoft Corporation
InCDsrv.exe 796 incdsrv Ahead Software AG
svchost.exe 1040 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1124 Generic Host Process for Win32 Services Microsoft Corporation
LEXBCES.EXE 1164 LexBce Service Lexmark International, Inc.
LEXPPS.EXE 1196 LEXPPS.EXE Lexmark International, Inc.
spoolsv.exe 1204 Spooler SubSystem App Microsoft Corporation
AVGUARD.EXE 1360 5.71 Antivirus Service for Windows XP/2000/NT H+BEDV Datentechnik GmbH
AVWUPSRV.EXE 1376 AntiVir Software Update Service for Windows H+BEDV Datentechnik GmbH, Germany
DCSUserProt.exe 1432 DiamondCS ProcessGuard Service DiamondCS
nvsvc32.exe 1496 NVIDIA Driver Helper Service, Version 66.93 NVIDIA Corporation
svchost.exe 1548 Generic Host Process for Win32 Services Microsoft Corporation
wdfmgr.exe 1584 Windows User Mode Driver Manager Microsoft Corporation
vsmon.exe 1628 TrueVector Service Zone Labs, LLC
lsass.exe 552 LSA Shell (Export Version) Microsoft Corporation
explorer.exe 1116 Windows Explorer Microsoft Corporation
AVGNT.EXE 1748 AntiVir Guard/XP Control Program H+BEDV Datentechnik GmbH
pgaccount.exe 1756 pgaccount DiamondCS
procguard.exe 1764 GUI Aspect of ProcessGuard DiamondCS
Capictrl.exe 1772 CAPIControl DeTeWe AG & Co.
zlclient.exe 340 Zone Labs Client Zone Labs, LLC
procexp.exe 848 10.00 Sysinternals Process Explorer Sysinternals
Process: Procexp Pid: -2
Type Name
Hallo Ruby,
also ich hab die Logfiles wie von dir beschrieben gepostet, vielleicht kannst du ja mal ne blicke bitte drauf werfen.
Gruss
Chris