![]() |
|
Plagegeister aller Art und deren Bekämpfung: 3 Trojaner in system32Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() | ![]() 3 Trojaner in system32 GMER 1.0.15.15087 - http://www.gmer.net Rootkit scan 2009-09-28 23:04:29 Windows 5.1.2600 Service Pack 3 Running: wefwefwfwef.exe; Driver: C:\DOKUME~1\***\LOKALE~1\Temp\pxtdypow.sys ---- System - GMER 1.0.15 ---- SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA90887E] SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xB353A794] SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xB353AF1E] SSDT BAF9894C ZwCreateThread SSDT BAF98938 ZwOpenProcess SSDT BAF9893D ZwOpenThread SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA908BFE] SSDT BAF98947 ZwTerminateProcess SSDT BAF98942 ZwWriteVirtualMemory Code \??\C:\WINDOWS\system32\drivers\d3dsgsw.sys (Windows interface driver/Microsoft Corporation) ZwResumeThread [0xB32E5590] ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[144] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\Explorer.EXE[144] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02180001 .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[424] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\ctfmon.exe[424] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D20001 .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Messenger\msmsgs.exe[432] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Messenger\msmsgs.exe[432] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01530001 .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[456] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F70001 .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\RTHDCPL.EXE[484] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\RTHDCPL.EXE[484] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 04D50001 .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AE0001 .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe[520] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\RUNDLL32.EXE[528] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\RUNDLL32.EXE[528] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E20001 .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[552] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01950001 .text C:\Programme\Spyware Doctor\pctsTray.exe[560] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0044A81D C:\Programme\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\iTunes\iTunesHelper.exe[584] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\iTunes\iTunesHelper.exe[584] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02360001 .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE[592] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C90001 .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\csrss.exe[604] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02BE0001 .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\winlogon.exe[628] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\winlogon.exe[628] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01410001 .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[672] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\services.exe[672] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01230001 .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\lsass.exe[684] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C60001 .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00EE0001 |
![]() |
Themen zu 3 Trojaner in system32 |
0 bytes, ad-aware, antivir, antivirus, avgnt.exe, avgntflt.sys, avira, bonjour, content.ie5, diagnostics, einstellungen, free download, google, helper, internet, jusched.exe, logon.exe, malewarbytes, mozilla, neu aufsetzen, nicht sicher, nt.dll, prozesse, realtek, registry, rthdcpl.exe, rundll, sched.exe, security, services.exe, software, spyware, suchlauf, svchost.exe, system, system neu, system neu aufsetzen, teamspeak, trojaner, usb, verweise, virus gefunden, warnung, winlogon.exe, wireless lan |