![]() |
|
Plagegeister aller Art und deren Bekämpfung: 3 Trojaner in system32Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #12 |
![]() | ![]() 3 Trojaner in system32 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3024] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3024] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3024] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 007A0001 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3024] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Downloads\Software\wefwefwfwef.exe[3280] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Downloads\Software\wefwefwfwef.exe[3280] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001 .text C:\Downloads\Software\wefwefwfwef.exe[3280] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00980001 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3620] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\iPod\bin\iPodService.exe[3792] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\iPod\bin\iPodService.exe[3792] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 008B0001 .text C:\Programme\iPod\bin\iPodService.exe[3792] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CC0001 .text C:\WINDOWS\system32\wbem\unsecapp.exe[5244] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01020001 .text C:\PROGRA~1\FREEDO~1\fdm.exe[5536] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F40001 .text C:\Programme\Lavasoft\Ad-Aware\AAWService.exe[6108] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\wscntfy.exe[6140] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\WINDOWS\system32\wscntfy.exe[6140] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A00001 .text C:\WINDOWS\system32\wscntfy.exe[6140] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtCreateSection 7C91D17E 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtCreateSection + 4 7C91D182 2 Bytes [05, 5F] .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtTerminateProcess 7C91DE6E 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtTerminateProcess + 4 7C91DE72 2 Bytes [0B, 5F] .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 3 Bytes [FF, 25, 1E] .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] ntdll.dll!NtWriteVirtualMemory + 4 7C91DFB2 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001 .text C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe[7216] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D ---- EOF - GMER 1.0.15 ---- |
Themen zu 3 Trojaner in system32 |
0 bytes, ad-aware, antivir, antivirus, avgnt.exe, avgntflt.sys, avira, bonjour, content.ie5, diagnostics, einstellungen, free download, google, helper, internet, jusched.exe, logon.exe, malewarbytes, mozilla, neu aufsetzen, nicht sicher, nt.dll, prozesse, realtek, registry, rthdcpl.exe, rundll, sched.exe, security, services.exe, software, spyware, suchlauf, svchost.exe, system, system neu, system neu aufsetzen, teamspeak, trojaner, usb, verweise, virus gefunden, warnung, winlogon.exe, wireless lan |