Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 29.03.2010, 15:22   #1
coolxiang
 
TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll - Standard

TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll



Hallo, hab seit zwei tagen immer die Meldung von Avira Antivir, das folgende Datei:

d3dsmnpb.dll mit dem Trojaner TR/Agent.ruo infiziert sein soll.

Wenn ich diese lösche und wieder den Pc neustate ist sie wieder da. Kann mir einer sagen was das sein soll und wie ich es wegbekomme? Danke für die Hilfe im voraus.

Alt 29.03.2010, 15:50   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll - Standard

TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll



Hallo und

Bitte ein OSAM Logfile posten.
__________________

__________________

Alt 29.03.2010, 17:17   #3
coolxiang
 
TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll - Standard

TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll



Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:15:09 on 29.03.2010
OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.2

Scanner Settings
Rootkits detection (hidden registry)
Rootkits detection (hidden files)
Retrieve files information
Check Microsoft signatures

Filters
Trusted entries
Empty entries
Hidden registry entries (rootkit activity)
Exclusively opened files
Not found files
Files without detailed information
Existing files
Non-startable services
Non-startable drivers
Active entries
Disabled entries

Risk Name Publisher Full Path Status
Control Panel Objects
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
|||||| "CreativeAudioConsole" "Creative Technology Ltd" C:\Program Files\Creative\Sound Blaster X-Fi\AudioCS\CTAudCS.cpl File exists
|||||| "lgLcdCpl" "Logitech Inc." C:\Program Files\Logitech\GamePanel Software\LCD Manager\LgLcdCpl.cpl File exists
|||||| "mlcfg32.cpl" "Microsoft Corporation" C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL File exists
Drivers
HKLM\SYSTEM\CurrentControlSet\Services
|||||| "am1zjsxt" (am1zjsxt) "Microsoft Corporation" C:\Windows\system32\drivers\am1zjsxt.sys Hidden registry entry, rootkit activity | File signed by Microsoft
|||||| "atksgt" (atksgt) C:\Windows\System32\DRIVERS\atksgt.sys File found, but it contains no detailed information
|||||| "avgio" (avgio) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avgio.sys File exists
|||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists
|||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists
|||||| "DgiVecp" (DgiVecp) "Samsung Electronics Co., Ltd." C:\Windows\system32\Drivers\DgiVecp.sys File exists
|| "FsUsbExDisk" (FsUsbExDisk) C:\Windows\system32\FsUsbExDisk.SYS File found, but it contains no detailed information
"IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found
"IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
"IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
|||||| "LibUsb-Win32 - Kernel Driver, Version 0.1.10.1" (libusb0) C:\Windows\System32\drivers\libusb0.sys File exists
|||||| "lirsgt" (lirsgt) C:\Windows\System32\DRIVERS\lirsgt.sys File found, but it contains no detailed information
"ntnho" (ntnho) "Microsoft Corporation" C:\Windows\system32\drivers\ntnho.sys File exists
|||||| "PCLEPCI" (PCLEPCI) "Pinnacle Systems GmbH" C:\Windows\system32\drivers\pclepci.sys File exists
|||||| "sptd" (sptd) "Duplex Secure Ltd." C:\Windows\System32\Drivers\sptd.sys File is exclusively opened, access blocked
|||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists
|||||| "SSPORT" (SSPORT) "Samsung Electronics" C:\Windows\system32\Drivers\SSPORT.sys File exists
Explorer
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" File not found | COM-object registry key not found
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" File not found | COM-object registry key not found
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
|| {B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC} "PixiePack Codec Pack 1.0.100.0" C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe File exists
HKLM\Software\Classes\Folder\shellex\ColumnHandlers
|||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists
|||||| {30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
HKLM\Software\Classes\Protocols\Filter
|||||| {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" "Microsoft Corporation" C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL File exists
HKLM\Software\Classes\Protocols\Handler
|||||| {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" "Microsoft Corporation" C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL File exists
|||||| {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll File exists
|||||| {88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
|||||| {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found
|||||| {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" "Igor Pavlov" C:\Program Files\7-Zip\7-zip.dll File exists
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found
|||||| {A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" "NVIDIA Corporation" C:\Windows\system32\nvcpl.dll File exists
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found
|||||| {B28C18DB-6816-4F31-9630-397683E3C2C3} "Filzip Shell Extension" C:\PROGRA~1\Filzip\fzshext.dll File exists
|||||| {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||||| {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" File not found | COM-object registry key not found
|||||| {DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C} "KbLogiExt Class" "Logitech, Inc." C:\Program Files\Logitech\SetPoint\kbcplext.dll File exists
|||||| {B9B9F083-2B04-452A-8691-83694AC1037B} "LogiExt Class" "Logitech, Inc." C:\Program Files\Logitech\SetPoint\mcplext.dll File exists
|||||| {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\msohevi.dll File exists
|||||| {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" "Microsoft Corporation" C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll File exists
|||||| {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" "Microsoft Corporation" C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL File exists
|||||| {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" "Microsoft Corporation" C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll File exists
|||||| {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" "NVIDIA Corporation" C:\Windows\system32\nvshext.dll File exists
|||||| {FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" "NVIDIA Corporation" C:\Windows\system32\nvcpl.dll File exists
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found
|||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists
|||||| {30351346-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {30351347-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {30351348-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134A-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134B-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134C-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134D-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134E-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {3035134F-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {30351350-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll File exists
|||||| {C5994560-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994561-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994562-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994563-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994564-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994565-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994566-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994567-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {C5994568-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" "hxxp://tortoisesvn.net" C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll File exists
|||||| {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" "Microsoft Corporation" C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL File exists
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found
|||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File exists
Internet Explorer
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
ITBar7Height "ITBar7Height" File not found | COM-object registry key not found
"ITBar7Layout" File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units
|| {F6ACF75C-C32C-447B-9BEF-46B766368D29} "Creative Software AutoUpdate Support Package"
hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab "Creative Technology Ltd" C:\PROGRA~1\Creative\SHARED~1\SOFTWA~1\CTPID.ocx File exists
|||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists
|||| {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists
|||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_17.dll File exists
|||||| {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object"
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab "Adobe Systems, Inc." C:\Windows\system32\Macromed\Flash\Flash10b.ocx File exists
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
|||| "ICQ6" "ICQ, LLC." C:\Program Files\ICQ6.5\ICQ.exe File exists
|||| {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" "Microsoft Corporation" C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
|||||| {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File exists
|||| {31FF080D-12A3-439A-A2EF-4BA95A3148E8} "bho2gr Class" "Headlight Software, Inc." C:\Program Files\GetRight\xx2gr.dll File exists
|||||| {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll File exists
|||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists
|||||| {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll File exists
Logon
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
|||| "OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE Shortcut exists | File exists
|||||| "desktop.ini" C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup
|||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists
|||| "Logitech SetPoint.lnk" "Logitech, Inc." C:\Program Files\Logitech\SetPoint\SetPoint.exe Shortcut exists | File exists
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"{Default}" C:\Users\Daniel\AppData\Local\Temp\jvwtjb17.exe File not found
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
"StartupPrograms" rdpclip File not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
|||| "Adobe ARM" "Adobe Systems Incorporated" "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File exists
|||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" File exists
|||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists
|||| "GrooveMonitor" "Microsoft Corporation" "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" File exists
"Kone" "ROCCAT" "C:\Program Files\ROCCAT\Kone Mouse\KoneHID.EXE" File exists
|||| "Launch LCDMon" "Logitech Inc." "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" File exists
|||| "Launch LGDCore" "Logitech Inc." "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE File exists
|||| "Launch LgDeviceAgent" "Logitech Inc." "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" File exists
|||| "NapsterShell" "Napster" C:\Program Files\Napster\napster.exe /systray File exists
|||| "Samsung PanelMgr" C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun File exists
|||| "Start WingMan Profiler" "Logitech Inc." C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui File exists
|||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Java\jre6\bin\jusched.exe" File exists
|||| "VolPanel" "Creative Technology Ltd" "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r File exists
Print Monitors
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
|||||| "Send To Microsoft OneNote Monitor" "Microsoft Corporation" C:\Windows\system32\msonpmon.dll File exists
Services
HKLM\SYSTEM\CurrentControlSet\Services
"Adobe Active File Monitor V8" (AdobeActiveFileMonitor8.0) "Adobe Systems Incorporated" C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe File exists
|||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists
|||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists
|||||| "Creative ALchemy AL6 Licensing Service" (Creative ALchemy AL6 Licensing Service) "Creative Labs" C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe File exists
|||||| "Creative Audio Engine Licensing Service" (Creative Audio Engine Licensing Service) "Creative Labs" C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe File exists
|||||| "Creative Audio Service" (CTAudSvcService) "Creative Technology Ltd" C:\Program Files\Creative\Shared Files\CTAudSvc.exe File exists
|||||| "Defragmentation-Service" (DfSdkS) "mst software GmbH, Germany" C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe File exists
|||||| "FLEXnet Licensing Service" (FLEXnet Licensing Service) "Acresso Software Inc." C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File exists
|||||| "FsUsbExService" (FsUsbExService) "Teruten" C:\Windows\system32\FsUsbExService.Exe File exists
|||| "InstallDriver Table Manager" (IDriverT) "Macrovision Corporation" C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe File exists
|||||| "LibUsb-Win32 - Daemon, Version 0.1.10.1" (libusbd) "hxxp://libusb-win32.sourceforge.net" C:\Windows\System32\libusbd-nt.exe File exists
|||||| "Logitech Bluetooth Service" (LBTServ) "Logitech, Inc." C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe File exists
|||||| "Microsoft Office Diagnostics Service" (odserv) "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE File exists
|||||| "Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) "Microsoft Corporation" C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe File exists
|||||| "Net Driver HPZ12" (Net Driver HPZ12) "Hewlett-Packard" C:\Windows\system32\HPZinw12.dll File exists
|||||| "NVIDIA Display Driver Service" (nvsvc) "NVIDIA Corporation" C:\Windows\system32\nvvsvc.exe File exists
|||||| "Office Source Engine" (ose) "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE File exists
|||||| "Pml Driver HPZ12" (Pml Driver HPZ12) "Hewlett-Packard" C:\Windows\system32\HPZipm12.dll File exists
|||||| "PnkBstrA" (PnkBstrA) C:\Windows\system32\PnkBstrA.exe File found, but it contains no detailed information
|| "rTop100Factor Service" (rTop100Factor) E:\Games\rFactor\rTop100Factor\wrapper.exe File found, but it contains no detailed information
|||||| "Steam Client Service" (Steam Client Service) "Valve Corporation" C:\Program Files\Common Files\Steam\SteamService.exe File exists
|||||| "Windows Live ID Sign-in Assistant" (wlidsvc) "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE File exists

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
__________________

Antwort

Themen zu TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll
antivir, avira, avira antivir, c:\windows, datei, folge, folgende, infiziert, meldung, system, system32, tagen, tr/agent.ruo, troja, trojaner, wegbekomme, windows




Ähnliche Themen: TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll


  1. TR/Agent.ruo in C:\Windows\system32\ntnmdm.dll
    Plagegeister aller Art und deren Bekämpfung - 31.05.2010 (55)
  2. Drop.Agent.amh in C:\Windows\System32\help.txt
    Plagegeister aller Art und deren Bekämpfung - 15.05.2010 (2)
  3. TR/Agent.ruo C:\Windows\System32\ntnzwdg.dll
    Plagegeister aller Art und deren Bekämpfung - 15.04.2010 (23)
  4. TR/Agent.RUO.3 in der Datei 'C:\Windows\System32\wineon.dll' und DR/Agent.ruo ...
    Plagegeister aller Art und deren Bekämpfung - 13.04.2010 (6)
  5. TR/Agent.ruo in C:\Windows\system32\ntnluj.dll
    Plagegeister aller Art und deren Bekämpfung - 08.04.2010 (9)
  6. TR/Agent.ruo in C:/WINDOWS/System32/winevpn.dll
    Plagegeister aller Art und deren Bekämpfung - 07.04.2010 (32)
  7. TR/Agent.RUO.4 in 'C:\Windows\System32\d3dshtr.dll'
    Plagegeister aller Art und deren Bekämpfung - 03.04.2010 (11)
  8. TR/Agent.ruo in C:\Windows\system32\winepnb.dll
    Mülltonne - 01.04.2010 (1)
  9. Tr/Agent.ruo in C:\WINDOWS\System32\ntnltk.dll
    Plagegeister aller Art und deren Bekämpfung - 31.03.2010 (5)
  10. TR/Agent.ruo in in C:\Windows\system32\d3dsnpq.dll
    Plagegeister aller Art und deren Bekämpfung - 31.03.2010 (10)
  11. tr/agent.ruo in C:\Windows\System32\winexxqd.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (10)
  12. TR/Agent.ruo in Windows System32 d3dszdmd.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (3)
  13. TR/Agent.ruo C:\WINDOWS\system32\ntnbk.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (1)
  14. TR/Agent.ruo C:\WINDOWS\system32\ntnaeu.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (26)
  15. TR/Agent.ruo in in C:\Windows\system32\wineayy.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (4)
  16. TR/agent.ruo in C:WINDOWS\System32\ntnyjop.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2010 (1)
  17. Tr/Agent.ruo in: C\Windows\System32\wineqd.dll
    Plagegeister aller Art und deren Bekämpfung - 28.03.2010 (3)

Zum Thema TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll - Hallo, hab seit zwei tagen immer die Meldung von Avira Antivir, das folgende Datei: d3dsmnpb.dll mit dem Trojaner TR/Agent.ruo infiziert sein soll. Wenn ich diese lösche und wieder den Pc - TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll...
Archiv
Du betrachtest: TR/Agent.ruo in C:\Windows\System32\d3dsmnpb.dll auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.