Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch...

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 25.01.2012, 20:26   #1
Paclib
 
BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch... - Standard

BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch...



Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-01-25 20:15:06
Windows 6.1.7600  Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1600BEVS-22RST0 rev.04.01G04
Running: nbxrj9v3.exe; Driver: C:\Users\MR\AppData\Local\Temp\pxldypoc.sys


---- System - GMER 1.0.15 ----

SSDT            8DF0812E                                                                                                             ZwCreateSection
SSDT            8DF08138                                                                                                             ZwRequestWaitReplyPort
SSDT            8DF08133                                                                                                             ZwSetContextThread
SSDT            8DF0813D                                                                                                             ZwSetSecurityObject
SSDT            8DF08142                                                                                                             ZwSystemDebugControl
SSDT            8DF080CF                                                                                                             ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!ZwSaveKeyEx + 13AD                                                                                      82A8D5D9 1 Byte  [06]
.text           ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                               82AB2092 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text           ntkrnlpa.exe!RtlSidHashLookup + 370                                                                                  82AB99B0 4 Bytes  [2E, 81, F0, 8D]
.text           ntkrnlpa.exe!RtlSidHashLookup + 6CC                                                                                  82AB9D0C 4 Bytes  [38, 81, F0, 8D]
.text           ntkrnlpa.exe!RtlSidHashLookup + 710                                                                                  82AB9D50 4 Bytes  [33, 81, F0, 8D]
.text           ntkrnlpa.exe!RtlSidHashLookup + 78C                                                                                  82AB9DCC 4 Bytes  [3D, 81, F0, 8D]
.text           ntkrnlpa.exe!RtlSidHashLookup + 7E0                                                                                  82AB9E20 4 Bytes  [42, 81, F0, 8D]
.text           ...                                                                                                                  

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]     [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]   [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress]   [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\Real\RealPlayer\realplay.exe[376] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]   [75085E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                               fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                               rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                               fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                               rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                               fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                               rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000004c                                                                                    halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----
         
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:23:06 on 25.01.2012

OS: Windows 7  (Build 7600), 32-bit
Default Browser: Mozilla Corporation Firefox 9.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"prefscpl.cpl" - "RealNetworks, Inc." - C:\Windows\system32\prefscpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AVerMedia USB Polaris Series Capture Service" (AVerPola) - "AVerMedia TECHNOLOGIES, Inc." - C:\Windows\System32\DRIVERS\AVerPola.sys
"AVerMedia USB Polaris Series Custom IR Service" (AVPolCIR) - "AVerMedia TECHNOLOGIES, Inc." - C:\Windows\System32\DRIVERS\AVPolCIR.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\MR\AppData\Local\Temp\catchme.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"pxldypoc" (pxldypoc) - ? - C:\Users\MR\AppData\Local\Temp\pxldypoc.sys  (Hidden registry entry, rootkit activity | File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "LibreOffice Property Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\propertyhdl.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - "The Document Foundation" - C:\Program Files\LibreOffice 3.4\Basis\program\shlxthdl\shlxthdl.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} "Java Plug-in 1.7.0_01" - "Oracle Corporation" - C:\Program Files\Java\jre7\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.7.0_01" - "Oracle Corporation" - C:\Program Files\Java\jre7\bin\npjpi170_01.dll / hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 10.1.0" - "Oracle Corporation" - C:\Program Files\Java\jre7\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files\Java\jre7\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\MR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe  (Shortcut exists | File exists)
"AutoStart IR.lnk" - "Hauppauge Computer Works" - C:\Program Files\WinTV\Ir.exe  (Shortcut exists | File exists)
"WinTV Recording Status..lnk" - "Hauppauge Computer Works, Inc." - C:\Program Files\WinTV\WinTV7\WinTVTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"uTorrent" - "BitTorrent, Inc." - "C:\Program Files\uTorrent\uTorrent.exe"  /MINIMIZED
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"QCDriverInstaller" - "Logitech Inc." - C:\PROGRA~1\COMMON~1\Logitech\QCDriver\Lqdsw.exe /addrun /l 1031 /LaunchAtStart
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RealTray" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"HP Discovery Port Monitor (HP Deskjet 3050 J610 series)" - "Hewlett-Packard Co." - C:\Windows\system32\HPDiscoPM9311.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"HauppaugeTVServer" (HauppaugeTVServer) - "Hauppauge Computer Works" - C:\PROGRA~1\WinTV\TVServer\HAUPPA~1.EXE
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
         

aswmbr folgt noch. =)

Alt 25.01.2012, 21:23   #2
Paclib
 
BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch... - Standard

BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch...



Code:
ATTFilter
 aswMBR version 0.9.9.1509 Copyright(c) 2011 AVAST Software
Run date: 2012-01-25 20:28:09
-----------------------------
20:28:09.595    OS Version: Windows 6.1.7600 
20:28:09.595    Number of processors: 2 586 0xF02
20:28:09.595    ComputerName: MR-PC  UserName: MR
20:28:10.859    Initialize success
20:30:26.312    AVAST engine defs: 12012500
20:33:13.700    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:33:13.700    Disk 0 Vendor: WDC_WD1600BEVS-22RST0 04.01G04 Size: 152627MB BusType: 3
20:33:13.887    Disk 0 MBR read successfully
20:33:13.887    Disk 0 MBR scan
20:33:13.903    Disk 0 Windows 7 default MBR code
20:33:13.918    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
20:33:13.965    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        89900 MB offset 206848
20:33:14.059    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        62625 MB offset 184322048
20:33:14.277    Disk 0 scanning sectors +312578048
20:33:14.745    Disk 0 scanning C:\Windows\system32\drivers
20:33:55.336    Service scanning
20:33:56.865    Modules scanning
20:35:15.536    Disk 0 trace - called modules:
20:35:15.614    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 
20:35:15.614    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85630948]
20:35:15.630    3 CLASSPNP.SYS[88ba059e] -> nt!IofCallDriver -> [0x85557a18]
20:35:15.630    5 ACPI.sys[8861b3b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8489f610]
20:35:16.612    AVAST engine scan C:\Windows
20:36:19.481    AVAST engine scan C:\Windows\system32
20:51:26.685    AVAST engine scan C:\Windows\system32\drivers
20:53:49.612    AVAST engine scan C:\Users\MR
21:00:58.769    AVAST engine scan C:\ProgramData
21:03:59.121    Scan finished successfully
21:21:12.119    Disk 0 MBR has been saved successfully to "C:\Users\MR\Downloads\Scan-Virus-Programme\MBR.dat"
21:21:12.119    The log file has been saved successfully to "C:\Users\MR\Downloads\Scan-Virus-Programme\aswMBR.txt"
         
__________________


Antwort

Themen zu BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch...
.dll, andere, anderen, avira, check, ebenfalls, eset, fehlermeldung, hoffe, keine viren, konnte, laptop, malwarebytes, neu, nicht mehr, nichts, nutzen, programm, quarantäne, seite, starte, texte, viren, virus, wisst, wpbt0.dll




Ähnliche Themen: BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch...


  1. Offline Scanner 64Bit UEFI only via USB?
    Diskussionsforum - 13.11.2015 (12)
  2. Trojaner durch ESET Online Scanner gefunden
    Log-Analyse und Auswertung - 26.03.2015 (10)
  3. Scanner findet nach öffnen von infizierter Datei keinen Trojaner
    Log-Analyse und Auswertung - 01.03.2015 (6)
  4. Eset Online Scanner findet Win32/Bundled. Toolbar Google
    Plagegeister aller Art und deren Bekämpfung - 28.08.2014 (3)
  5. ESET Online Scanner findet 18 Infizierte Dateien
    Plagegeister aller Art und deren Bekämpfung - 20.06.2014 (3)
  6. Windows 8: PC auf einmal enorm Langsam, Avira findet jedoch keine Viren oder ähnliches
    Plagegeister aller Art und deren Bekämpfung - 10.05.2014 (7)
  7. Snapdo Trojaner entdeckt, ESET Online Scanner läuft, was muss isch jetzt tun?
    Log-Analyse und Auswertung - 24.04.2014 (3)
  8. Eset Online Scanner findet ava/Exploit.Agent.OEX Trojaner
    Plagegeister aller Art und deren Bekämpfung - 12.05.2013 (5)
  9. AntiVir Echtzeit Scanner meldete Trojaner, findet jetzt aber nichts mehr
    Log-Analyse und Auswertung - 23.11.2012 (16)
  10. Problem mit ESET Online scanner bei Fund einer Variante von Win32 SpyZBot ZR Trojaner
    Plagegeister aller Art und deren Bekämpfung - 28.10.2011 (25)
  11. Problem mit ESET Online scanner bei Fund einer Variante von Win32 SpyZBot ZR Trojaner
    Antiviren-, Firewall- und andere Schutzprogramme - 23.10.2011 (1)
  12. Kaspersky Online Scanner
    Plagegeister aller Art und deren Bekämpfung - 11.01.2007 (6)
  13. Würmer,Viren und kein scanner findet was!
    Log-Analyse und Auswertung - 10.05.2005 (1)

Zum Thema BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch... - Code: Alles auswählen Aufklappen ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-01-25 20:15:06 Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1600BEVS-22RST0 rev.04.01G04 Running: nbxrj9v3.exe; Driver: C:\Users\MR\AppData\Local\Temp\pxldypoc.sys ---- System - GMER 1.0.15 ---- - BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch......
Archiv
Du betrachtest: BKA-Trojaner; Offline-Scanner findet keine Viren, Online-Scanner jedoch... auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.