![]() |
|
Log-Analyse und Auswertung: Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELPWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #27 |
![]() | ![]() Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELP Hi arne! Hier die logs nach dem genannten vorgang: aswmbr: aswMBR version 0.9.8.978 Copyright(c) 2011 AVAST Software Run date: 2011-08-26 12:17:28 ----------------------------- 12:17:28.690 OS Version: Windows 6.1.7600 12:17:28.690 Number of processors: 2 586 0x170A 12:17:28.690 ComputerName: HAUKES-THINK UserName: HaukeS 12:17:29.719 Initialize success 12:17:32.668 AVAST engine defs: 11082600 12:17:38.689 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 12:17:38.689 Disk 0 Vendor: WDC_WD25 14.0 Size: 238475MB BusType: 3 12:17:38.736 Disk 0 MBR read successfully 12:17:38.752 Disk 0 MBR scan 12:17:38.752 Disk 0 Windows 7 default MBR code 12:17:38.767 Disk 0 scanning sectors +488394752 12:17:38.861 Disk 0 scanning C:\Windows\system32\drivers 12:17:48.268 Service scanning 12:17:50.046 Modules scanning 12:17:58.361 Disk 0 trace - called modules: 12:17:58.376 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys 12:17:58.376 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8651b030] 12:17:58.392 3 CLASSPNP.SYS[891d359e] -> nt!IofCallDriver -> [0x85af1958] 12:17:58.891 5 ACPI.sys[88a3e3b2] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x856ec028] 12:18:00.264 AVAST engine scan C:\Windows 12:18:03.306 AVAST engine scan C:\Windows\system32 12:19:52.899 AVAST engine scan C:\Windows\system32\drivers 12:20:03.260 AVAST engine scan C:\Users\HaukeS 12:22:48.126 File: C:\Users\HaukeS\AppData\Local\Temp\jar_cache7161096472331229318.tmp **INFECTED** Win32:Banker-IID [Trj] 12:23:01.075 File: C:\Users\HaukeS\AppData\Roaming\appconf32.exe **INFECTED** Win32:Banker-IJD [Drp] 12:24:22.139 AVAST engine scan C:\ProgramData 12:25:18.730 Scan finished successfully 12:25:43.889 Disk 0 MBR has been saved successfully to "C:\Users\HaukeS\Desktop\MBR.dat" 12:25:43.896 The log file has been saved successfully to "C:\Users\HaukeS\Desktop\logaswmbr.txt" und gmer: GMER Logfile: Code:
ATTFilter GMER 1.0.15.15641 - GMER - Rootkit Detector and Remover Rootkit scan 2011-08-26 12:42:14 Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.14.0 Running: m2pto3ov.exe; Driver: C:\Users\HaukeS\AppData\Local\Temp\kwrorpob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E5A579 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E7EF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ? C:\Users\HaukeS\AppData\Local\Temp\aswMBR.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[1856] ntdll.dll!LdrLoadDll 773AF585 5 Bytes JMP 00DD1410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5184] USER32.dll!SetWindowLongA 766DB1E3 5 Bytes JMP 61D4A2FB C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5184] USER32.dll!SetWindowLongW 766E6614 5 Bytes JMP 61D4A28D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5184] USER32.dll!GetWindowInfo 766E6A82 5 Bytes JMP 61B51BD2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5184] USER32.dll!TrackPopupMenu 76704B3B 5 Bytes JMP 61B5219D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2076] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7352250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73522494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73505624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [735056E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73518573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73514D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [735150CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [735151A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [735166D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [735182CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73518819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7351907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7351E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73514C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\System32\rundll32.exe[3932] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\System32\rundll32.exe[3932] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\System32\rundll32.exe[3932] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\System32\rundll32.exe[3932] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3996] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3996] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3996] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3996] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT c:\Program Files\Lenovo\System Update\SUService.exe[4912] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT c:\Program Files\Lenovo\System Update\SUService.exe[4912] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT c:\Program Files\Lenovo\System Update\SUService.exe[4912] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT c:\Program Files\Lenovo\System Update\SUService.exe[4912] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT c:\Program Files\Lenovo\System Update\SUService.exe[4912] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [753F5D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation) Device \Driver\ACPI_HAL \Device\00000052 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f3ad3f68b Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c607688b5f7 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f3ad3f68b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c607688b5f7 (not active ControlSet) ---- Files - GMER 1.0.15 ---- File C:\Users\HaukeS\AppData\Local\Temp\flaEED6.tmp 22754707 bytes ---- EOF - GMER 1.0.15 ---- Ich bekomme zur Zeit oft einen bluescreen mit der Meldung: Page_fault_on_nonpage_area Grüße Hauke |
Themen zu Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELP |
5 minuten, antivir, bho, bonjour, boo/tdss.d, c:\windows\system32\rundll32.exe, converter, disabletaskmgr, excel.exe, firefox, help, kaspersky, keine dateien, langsam, lenovo, logfile, malware, malware gefunden, mozilla, mp3, plug-in, problem, programm, registry, rootkit, scan, security, sehr langsam, software, start menu, starten, system, taskmanager, temporär, trojaner, trojaner board, version=1.0, webcheck, windows |