![]() |
|
Diskussionsforum: Bootkit Nemesis- Bios/Firmware Malware im VBR , alle Systeme infiziertWindows 7 Hier sind ausschließlich fachspezifische Diskussionen erwünscht. Bitte keine Log-Files, Hilferufe oder ähnliches posten. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Bereinigungen von nicht ausgebildeten Usern sind hier untersagt. Wenn du dir einen Virus doer Trojaner eingefangen hast, eröffne ein Thema in den Bereinigungsforen oben. |
![]() | #36 |
![]() ![]() | ![]() Bootkit Nemesis- Bios/Firmware Malware im VBR , alle Systeme infiziert aber hallo, zumal ich beteits mind 2 mal erwähnt habe -unabhängig von veröffentlichten daten- das wir in berlin wohnen und der veröffentlichte auszug mehrere wochen alt ist, die ip aber alle 24 std wechselt.. aber das weist du ja alles. zudem hast du als mod sowiso meine aktuelle ip, guck mal genau in deinen überarbeitsungsbereich... Hier nochmals ein bischen nichts aussagender Dünschüss vom aktuellen System: sysinternals via WSCC logonSessions.exe Code:
ATTFilter [CONSOLE] 14.04.2016 01:00:21 - C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe started [0] Logon session 00000000:000003e7: User name: BBS-GROUP\BBS-SERVER$ Auth package: NTLM Logon type: (none) Session: 0 Sid: S-1-5-18 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [1] Logon session 00000000:00009220: User name: Auth package: NTLM Logon type: (none) Session: 0 Sid: (none) Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [2] Logon session 00000000:000003e4: User name: BBS-GROUP\BBS-SERVER$ Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-20 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [3] Logon session 00000000:000003e5: User name: NT-AUTORITÄT\Lokaler Dienst Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-19 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [4] Logon session 00000000:000003e3: User name: NT-AUTORITÄT\IUSR Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-17 Logon time: 13.04.2016 23:09:20 Logon server: DNS Domain: UPN: [5] Logon session 00000000:000a8fee: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [6] Logon session 00000000:000a9024: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [7] Logon session 00000000:00d4d966: User name: IIS APPPOOL\DefaultAppPool Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 Logon time: 13.04.2016 23:35:40 Logon server: DNS Domain: UPN: [8] Logon session 00000000:011beb11: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [9] Logon session 00000000:011beb25: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [10] Logon session 00000000:011c51ac: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: [11] Logon session 00000000:011c51e6: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: Logonsessions v1.3 Copyright (C) 2004-2015 Mark Russinovich Sysinternals - wwww.sysinternals.com [CONSOLE] 14.04.2016 01:00:27 - "C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe" finished [CONSOLE] 14.04.2016 01:01:01 - C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe started [0] Logon session 00000000:000003e7: User name: BBS-GROUP\BBS-SERVER$ Auth package: NTLM Logon type: (none) Session: 0 Sid: S-1-5-18 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [1] Logon session 00000000:00009220: User name: Auth package: NTLM Logon type: (none) Session: 0 Sid: (none) Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [2] Logon session 00000000:000003e4: User name: BBS-GROUP\BBS-SERVER$ Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-20 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [3] Logon session 00000000:000003e5: User name: NT-AUTORITÄT\Lokaler Dienst Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-19 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [4] Logon session 00000000:000003e3: User name: NT-AUTORITÄT\IUSR Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-17 Logon time: 13.04.2016 23:09:20 Logon server: DNS Domain: UPN: [5] Logon session 00000000:000a8fee: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [6] Logon session 00000000:000a9024: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [7] Logon session 00000000:00d4d966: User name: IIS APPPOOL\DefaultAppPool Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 Logon time: 13.04.2016 23:35:40 Logon server: DNS Domain: UPN: [8] Logon session 00000000:011beb11: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [9] Logon session 00000000:011beb25: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [10] Logon session 00000000:011c51ac: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: [11] Logon session 00000000:011c51e6: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: Logonsessions v1.3 Copyright (C) 2004-2015 Mark Russinovich Sysinternals - wwww.sysinternals.com [CONSOLE] 14.04.2016 01:01:02 - "C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe" finished Code:
ATTFilter [CONSOLE] 14.04.2016 01:25:27 - C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe started [0] Logon session 00000000:000003e7: User name: BBS-GROUP\BBS-SERVER$ Auth package: NTLM Logon type: (none) Session: 0 Sid: S-1-5-18 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [1] Logon session 00000000:00009220: User name: Auth package: NTLM Logon type: (none) Session: 0 Sid: (none) Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [2] Logon session 00000000:000003e4: User name: BBS-GROUP\BBS-SERVER$ Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-20 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [3] Logon session 00000000:000003e5: User name: NT-AUTORITÄT\Lokaler Dienst Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-19 Logon time: 13.04.2016 23:09:16 Logon server: DNS Domain: UPN: [4] Logon session 00000000:000003e3: User name: NT-AUTORITÄT\IUSR Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-17 Logon time: 13.04.2016 23:09:20 Logon server: DNS Domain: UPN: [5] Logon session 00000000:000a8fee: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [6] Logon session 00000000:000a9024: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 1 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:12:07 Logon server: DNS Domain: UPN: [7] Logon session 00000000:00d4d966: User name: IIS APPPOOL\DefaultAppPool Auth package: Negotiate Logon type: Service Session: 0 Sid: S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 Logon time: 13.04.2016 23:35:40 Logon server: DNS Domain: UPN: [8] Logon session 00000000:011beb11: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [9] Logon session 00000000:011beb25: User name: Window Manager\DWM-2 Auth package: Negotiate Logon type: Interactive Session: 2 Sid: S-1-5-90-0-2 Logon time: 13.04.2016 23:46:26 Logon server: DNS Domain: UPN: [10] Logon session 00000000:011c51ac: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: [11] Logon session 00000000:011c51e6: User name: BBS-SERVER\BBSS Auth package: CloudAP Logon type: Interactive Session: 2 Sid: S-1-5-21-4091997533-1736783634-658159155-1001 Logon time: 13.04.2016 23:46:36 Logon server: DNS Domain: UPN: Logonsessions v1.3 Copyright (C) 2004-2015 Mark Russinovich Sysinternals - wwww.sysinternals.com [CONSOLE] 14.04.2016 01:25:28 - "C:\Users\BBSS\AppData\Roaming\Sysinternals Suite\logonSessions.exe" finished
__________________ --> Bootkit Nemesis- Bios/Firmware Malware im VBR , alle Systeme infiziert Geändert von dennissteins (14.04.2016 um 01:27 Uhr) |
Themen zu Bootkit Nemesis- Bios/Firmware Malware im VBR , alle Systeme infiziert |
anderen, bootkit, desktop, festplatte, folge, folgen, foren, hardware, hilft, infiziert, links, linux, löschen, malware, nemesis, neuinstallation, ordner, partition, platte, rechner, rootkit, sichtbar, systeme, thema, unmöglich, versteckte, ähnliches |