![]() |
|
Plagegeister aller Art und deren Bekämpfung: BKA Trojaner XP desktop Sperrung auch im abgesicherten ModusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() BKA Trojaner XP desktop Sperrung auch im abgesicherten Modus Mach mal erst nen Scan, dann FixMBR
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #2 |
![]() | ![]() BKA Trojaner XP desktop Sperrung auch im abgesicherten ModusCode:
ATTFilter aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Run date: 2013-02-14 17:51:07 ----------------------------- 17:51:07.468 OS Version: Windows 5.1.2600 Service Pack 2 17:51:07.468 Number of processors: 1 586 0x602 17:51:07.468 ComputerName: NINE UserName: 17:51:07.937 Initialize success 18:02:00.671 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 18:02:00.671 Disk 0 Vendor: IC35L040AVVN07-0 VA2OAF0C Size: 39266MB BusType: 3 18:02:00.687 Disk 1 MBR read successfully 18:02:00.687 Disk 1 MBR scan 18:02:00.687 Disk 1 Windows XP default MBR code 18:02:00.687 Disk 1 MBR hidden 18:02:00.687 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 24011 MB offset 63 18:02:00.687 Disk 1 Partition - 00 0F Extended LBA 15249 MB offset 49174965 18:02:00.703 Disk 1 Partition 2 00 0B FAT32 MSWIN4.1 15249 MB offset 49175028 18:02:00.781 Disk 1 scanning G:\WINDOWS\system32\drivers 18:02:09.015 Service scanning 18:02:23.703 Modules scanning 18:03:17.328 Disk 1 trace - called modules: 18:03:17.328 ntoskrnl.exe CLASSPNP.SYS disk.sys hal.dll 18:03:17.843 1 nt!IofCallDriver -> \Device\Harddisk1\DR3[0x81eec3c0] 18:03:17.843 Scan finished successfully 18:08:26.859 Disk 1 MBR has been saved successfully to "G:\Dokumente und Einstellungen\Janine\Desktop\MBR.dat" 18:08:26.859 The log file has been saved successfully to "G:\Dokumente und Einstellungen\Janine\Desktop\aswMBRneu.txt" GMER Logfile: Code:
ATTFilter GMER 2.0.18454 - hxxp://www.gmer.net Rootkit scan 2013-02-14 18:28:57 Windows 5.1.2600 Service Pack 2 \Device\Harddisk1\DR3 -> \Device\Ide\IdePort0 HUAWEI__ rev.2.31 0,00MB Running: gmer_2.0.18454.exe; Driver: G:\DOKUME~1\Janine\LOKALE~1\Temp\pxtdqpow.sys ---- Kernel code sections - GMER 2.0 ---- ? G:\DOKUME~1\Janine\LOKALE~1\Temp\aswMBR.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 2.0 ---- .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[360] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[604] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!CallNextHookEx 77D1ED6E 5 Bytes JMP 0122DD81 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!SetWindowsHookExW 77D3E621 5 Bytes JMP 0122DBCB G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!UnhookWindowsHookEx 77D3F29F 5 Bytes JMP 01191CA2 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[608] ole32.dll!CoCreateInstance 774F6009 5 Bytes JMP 0123488E G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!CallNextHookEx 77D1ED6E 5 Bytes JMP 0122DD81 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!CreateWindowExW 77D21AD5 5 Bytes JMP 01234832 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxParamW 77D26702 5 Bytes JMP 01159315 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxParamA 77D288E1 5 Bytes JMP 0134DFBE G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxIndirectParamW 77D32598 5 Bytes JMP 0134E021 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxIndirectA 77D3AEF1 5 Bytes JMP 0134DF51 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!SetWindowsHookExW 77D3E621 5 Bytes JMP 0122DBCB G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!UnhookWindowsHookEx 77D3F29F 5 Bytes JMP 01191CA2 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxExW 77D50559 5 Bytes JMP 0134DE22 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxExA 77D5057D 5 Bytes JMP 0134DE84 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!DialogBoxIndirectParamA 77D56CED 5 Bytes JMP 0134E084 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] USER32.dll!MessageBoxIndirectW 77D660B7 5 Bytes JMP 0134DEE6 G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] ole32.dll!CoCreateInstance 774F6009 5 Bytes JMP 0123488E G:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetSysColor 77D18E50 5 Bytes JMP 0045B9C0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetSysColorBrush 77D18E83 5 Bytes JMP 0045BA20 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollInfo 77D1902C 7 Bytes JMP 0045B8B0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollPos 77D1F66F 5 Bytes JMP 0045B840 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollRange 77D1F6BB 5 Bytes JMP 0045B930 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!SetScrollPos 77D1F780 5 Bytes JMP 0045B8F0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollRange 77D1F7B7 5 Bytes JMP 0045B870 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!ShowScrollBar 77D20142 5 Bytes JMP 0045B980 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!GetScrollInfo 77D23A2F 7 Bytes JMP 0045B800 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) .text G:\Programme\Mobile Partner\Mobile Partner.exe[2112] USER32.dll!EnableScrollBar 77D67BAD 7 Bytes JMP 0045B7C0 G:\Programme\Mobile Partner\SkinMagicU.dll (SkinMagic Toolkit/Appspeed Inc.) ---- User IAT/EAT - GMER 2.0 ---- IAT G:\Programme\Internet Explorer\IEXPLORE.EXE[608] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00C718FD] G:\Programme\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation) IAT G:\Programme\Internet Explorer\IEXPLORE.EXE[1472] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00C718FD] G:\Programme\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation) ---- Disk sectors - GMER 2.0 ---- Disk \Device\Harddisk1\DR3 sector 00: rootkit-like behavior ---- EOF - GMER 2.0 ---- |
![]() |
Themen zu BKA Trojaner XP desktop Sperrung auch im abgesicherten Modus |
abgesicherte, abgesicherten, abgesicherten modus, aktualisierung, bka trojaner, bka trojaner xp, desktop, guten, modus, programmes, rechner, sperrbildschirm, sperrung, troja, trojaner, virenprogrammes |