|
Plagegeister aller Art und deren Bekämpfung: Problem mit java(Java/trojanerDownloader.....)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.06.2011, 21:48 | #16 |
| Problem mit java(Java/trojanerDownloader.....) GMER GMER Logfile: Code:
ATTFilter GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover Rootkit scan 2011-06-01 22:46:42 Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS543216L9A300 rev.FB2OC40C Running: 10p518kg.exe; Driver: C:\Users\Andre\AppData\Local\Temp\kgldypog.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 83689569 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 836AE092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ? System32\drivers\fbwvq.sys Das System kann den angegebenen Pfad nicht finden. ! .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91C06000, 0x2D5378, 0xE8000020] ? C:\Windows\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. ! ? C:\Users\Andre\AppData\Local\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1744] kernel32.dll!SetUnhandledExceptionFilter 772E3162 4 Bytes [C2, 04, 00, 00] ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[1912] @ C:\Windows\system32\ole32.dll [ntdll.dll!EtwRegisterTraceGuidsW] [70F2B0C6] C:\Windows\AppPatch\AcXtrnal.dll (Windows Compatibility DLL/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[5260] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[5260] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[5260] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[5260] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B65E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) ---- EOF - GMER 1.0.15 ---- Rest kommt morgen, hoffe ist ok bin etwas müde gutenacht |
02.06.2011, 15:03 | #17 |
| Problem mit java(Java/trojanerDownloader.....) OSAM log Hoffe ist richtig so
__________________OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 Online Solutions. Complex Protection for Information Systems Saved at 16:01:53 on 02.06.2011 OS: Windows 7 Ultimate Edition (Build 7600), 32-bit Default Browser: Mozilla Corporation Firefox 4.0.1 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Control Panel Objects] -----( %SystemRoot%\system32 )----- "PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "catchme" (catchme) - ? - C:\Users\Andre\AppData\Local\Temp\catchme.sys (File not found) "EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found) "EagleXNt" (EagleXNt) - ? - C:\Windows\system32\drivers\EagleXNt.sys (File not found) "Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys "Mass Storage Filter Driver" (massfilter) - ? - C:\Windows\System32\drivers\massfilter.sys (File not found) "PCCS Mode Change Filter Driver" (pccsmcfd) - ? - C:\Windows\System32\DRIVERS\pccsmcfd.sys (File not found) "ZTE Diagnostic Port" (ZTEusbser6k) - ? - C:\Windows\System32\DRIVERS\ZTEusbser6k.sys (File not found) "ZTE NMEA Port" (ZTEusbnmea) - ? - C:\Windows\System32\DRIVERS\ZTEusbnmea.sys (File not found) "ZTE Proprietary USB Driver" (ZTEusbmdm6k) - ? - C:\Windows\System32\DRIVERS\ZTEusbmdm6k.sys (File not found) [Explorer] -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL {828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL {5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll {5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll {828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )----- {E31004D1-A431-41B8-826F-E902F9D95C81} "Windows DreamScene" - "Microsoft Corporation" - C:\Windows\System32\DreamScene.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll {B089FE88-FB52-11D3-BDF1-0050DA34150D} "ESET Smart Security - Context Menu Shell Extension" - "ESET" - C:\Program Files\ESET\ESET Smart Security\shellExt.dll {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) -----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )----- {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} "McAfee SiteAdvisor Toolbar" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_25.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- "ICQ7.5" - "ICQ, LLC." - C:\Program Files\ICQ7.5\ICQ.exe -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} "McAfee SiteAdvisor Toolbar" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {B164E929-A1B6-4A06-B104-2CD0E90A88FF} "McAfee SiteAdvisor BHO" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll {5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? - (File not found | COM-object registry key not found) [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\Andre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun "ICQ" - "ICQ, LLC." - "C:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4 "msnmsgr" - "Microsoft Corporation" - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "egui" - "ESET" - "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice "iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe" "Launch SilverCrest GML807" - "Siliten" - C:\Program Files\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe "Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript "PLFSetI" - ? - C:\Windows\PLFSetI.exe "QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe "ESET HTTP Server" (EhttpSrv) - "ESET" - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe "ESET Service" (ekrn) - "ESET" - C:\Program Files\ESET\ESET Smart Security\ekrn.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "McAfee SiteAdvisor Service" (McAfee SiteAdvisor Service) - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\McSACore.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "SQL Server (SQLEXPRESS)" (MSSQL$SQLEXPRESS) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe "SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [Winsock Providers] -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )----- "mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit Online Solutions :: Index |
02.06.2011, 15:07 | #18 |
| Problem mit java(Java/trojanerDownloader.....) MBR log
__________________MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows 7 Ultimate Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: Acer BIOS Manufacturer: Acer System Manufacturer: Acer System Product Name: Aspire 5530 Logical Drives Mask: 0x0000009c Kernel Drivers (total 203): 0x8363F000 \SystemRoot\system32\ntkrnlpa.exe 0x83608000 \SystemRoot\system32\halmacpi.dll 0x80BA6000 \SystemRoot\system32\kdcom.dll 0x88811000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll 0x8881C000 \SystemRoot\system32\PSHED.dll 0x8882D000 \SystemRoot\system32\BOOTVID.dll 0x88835000 \SystemRoot\system32\CLFS.SYS 0x88877000 \SystemRoot\system32\CI.dll 0x88922000 \SystemRoot\system32\drivers\Wdf01000.sys 0x88993000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x889A1000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x889E9000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x889F2000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x88A12000 \SystemRoot\system32\DRIVERS\pci.sys 0x88A3C000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x88A47000 \SystemRoot\System32\drivers\partmgr.sys 0x88A58000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x88A60000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x88A6B000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x88A7B000 \SystemRoot\System32\drivers\volmgrx.sys 0x88AC6000 \SystemRoot\System32\drivers\mountmgr.sys 0x88ADC000 \SystemRoot\system32\DRIVERS\atapi.sys 0x88AE5000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x88B08000 \SystemRoot\system32\DRIVERS\msahci.sys 0x88B12000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x88B20000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x88B29000 \SystemRoot\system32\drivers\fltmgr.sys 0x88B5D000 \SystemRoot\system32\drivers\fileinfo.sys 0x88C0A000 \SystemRoot\System32\Drivers\Ntfs.sys 0x88D39000 \SystemRoot\System32\Drivers\msrpc.sys 0x88D64000 \SystemRoot\System32\Drivers\ksecdd.sys 0x88D77000 \SystemRoot\System32\Drivers\cng.sys 0x88DD4000 \SystemRoot\System32\drivers\pcw.sys 0x88DE2000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x88E3A000 \SystemRoot\system32\drivers\ndis.sys 0x88EF1000 \SystemRoot\system32\drivers\NETIO.SYS 0x88F2F000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8903A000 \SystemRoot\System32\drivers\tcpip.sys 0x89183000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x891B4000 \SystemRoot\system32\DRIVERS\vmstorfl.sys 0x891BD000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x89000000 \SystemRoot\System32\Drivers\spldr.sys 0x89008000 \SystemRoot\System32\drivers\rdyboost.sys 0x88F54000 \SystemRoot\System32\Drivers\mup.sys 0x88F64000 \SystemRoot\System32\drivers\hwpolicy.sys 0x88F6C000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x88F9E000 \SystemRoot\system32\DRIVERS\disk.sys 0x88FAF000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x88FD4000 \SystemRoot\system32\DRIVERS\AtiPcie.sys 0x88E11000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x88E30000 \SystemRoot\System32\Drivers\Null.SYS 0x88DEB000 \SystemRoot\System32\Drivers\Beep.SYS 0x88B6E000 \SystemRoot\system32\DRIVERS\ehdrv.sys 0x88DF2000 \SystemRoot\System32\drivers\vga.sys 0x88B8D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x88BAE000 \SystemRoot\System32\drivers\watchdog.sys 0x88C00000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x88BBB000 \SystemRoot\system32\drivers\rdpencdd.sys 0x88BC3000 \SystemRoot\system32\drivers\rdprefmp.sys 0x88BCB000 \SystemRoot\System32\Drivers\Msfs.SYS 0x88BD6000 \SystemRoot\System32\Drivers\Npfs.SYS 0x88BE4000 \SystemRoot\system32\DRIVERS\tdx.sys 0x88A00000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8E624000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8E808000 \SystemRoot\system32\DRIVERS\kl1.sys 0x8ED28000 \SystemRoot\system32\drivers\afd.sys 0x8ED82000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8ED89000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8EDA8000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8EDB9000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8E656000 \SystemRoot\system32\DRIVERS\dtsoftbus01.sys 0x8EDC7000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8EDDA000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8E691000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8EDEA000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8EDF4000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8E6D2000 \SystemRoot\System32\drivers\discache.sys 0x8E6DE000 \SystemRoot\system32\drivers\csc.sys 0x8E742000 \SystemRoot\System32\Drivers\dfsc.sys 0x8E75A000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8E768000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8E789000 \SystemRoot\system32\DRIVERS\amdppm.sys 0x8E79A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x91A30000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x91F45000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8E7A3000 \SystemRoot\System32\drivers\dxgmms1.sys 0x91A00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x92C06000 \SystemRoot\system32\DRIVERS\athr.sys 0x92D16000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x92D20000 \SystemRoot\system32\DRIVERS\b57nd60x.sys 0x92D5C000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x92D62000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x92D6C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x92DB7000 \SystemRoot\system32\DRIVERS\usbfilter.sys 0x92DBD000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x92DCC000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x92DE4000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x92DF1000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8E7DC000 \SystemRoot\system32\DRIVERS\enecir.sys 0x92C00000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x91A1F000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x8E7F4000 \SystemRoot\system32\DRIVERS\Epfwndis.sys 0x8E600000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x9300A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x93022000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x9302D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x9304F000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x93067000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x9307E000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x93095000 \SystemRoot\system32\DRIVERS\rdpbus.sys 0x9309F000 \SystemRoot\system32\DRIVERS\swenum.sys 0x930A1000 \SystemRoot\system32\DRIVERS\ks.sys 0x930D5000 \SystemRoot\system32\DRIVERS\circlass.sys 0x930E3000 \SystemRoot\system32\DRIVERS\umbus.sys 0x930F1000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x93135000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x93146000 \SystemRoot\system32\drivers\AtiHdmi.sys 0x93163000 \SystemRoot\system32\drivers\portcls.sys 0x93192000 \SystemRoot\system32\drivers\drmk.sys 0x97007000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x97246000 \SystemRoot\system32\DRIVERS\VSTAZL3.SYS 0x97283000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS 0x8201D000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS 0x820D2000 \SystemRoot\system32\drivers\modem.sys 0x820DF000 \SystemRoot\system32\DRIVERS\hidir.sys 0x820EE000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x82101000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x82108000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x82114000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x82FA0000 \SystemRoot\System32\win32k.sys 0x8211F000 \SystemRoot\System32\drivers\Dxapi.sys 0x82129000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x82140000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x82142000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8214D000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8215A000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x82165000 \SystemRoot\System32\Drivers\dump_msahci.sys 0x8216F000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x82180000 \SystemRoot\System32\Drivers\usbvideo.sys 0x821A4000 \SystemRoot\system32\DRIVERS\monitor.sys 0x82E00000 \SystemRoot\System32\TSDDD.dll 0x82E30000 \SystemRoot\System32\cdd.dll 0x821AF000 \SystemRoot\system32\drivers\luafv.sys 0x9263E000 \SystemRoot\system32\DRIVERS\eamonm.sys 0x926E4000 \SystemRoot\system32\drivers\WudfPf.sys 0x926FE000 \SystemRoot\system32\DRIVERS\epfw.sys 0x92720000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x92730000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x92776000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x92786000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x99002000 \SystemRoot\system32\drivers\HTTP.sys 0x99087000 \SystemRoot\system32\DRIVERS\bowser.sys 0x990A0000 \SystemRoot\System32\drivers\mpsdrv.sys 0x990B2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x990D5000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x99110000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x99143000 \SystemRoot\system32\DRIVERS\epfwwfp.sys 0x99151000 \SystemRoot\system32\drivers\peauth.sys 0x991E8000 \SystemRoot\System32\Drivers\secdrv.SYS 0x92799000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x991F2000 \SystemRoot\System32\drivers\tcpipreg.sys 0x931AB000 \SystemRoot\System32\DRIVERS\srv2.sys 0x9C63D000 \SystemRoot\System32\DRIVERS\srv.sys 0x9C68F000 \SystemRoot\system32\DRIVERS\InputFilter_FlexDef2c.sys 0x771B0000 \Windows\System32\ntdll.dll 0x47FC0000 \Windows\System32\smss.exe 0x773F0000 \Windows\System32\apisetschema.dll 0x008B0000 \Windows\System32\autochk.exe 0x77300000 \Windows\System32\kernel32.dll 0x77110000 \Windows\System32\advapi32.dll 0x772F0000 \Windows\System32\normaliz.dll 0x76FB0000 \Windows\System32\ole32.dll 0x76EE0000 \Windows\System32\msctf.dll 0x76CE0000 \Windows\System32\iertutil.dll 0x76C50000 \Windows\System32\clbcatq.dll 0x76000000 \Windows\System32\shell32.dll 0x75F70000 \Windows\System32\oleaut32.dll 0x75F40000 \Windows\System32\imagehlp.dll 0x75E90000 \Windows\System32\msvcrt.dll 0x75E10000 \Windows\System32\comdlg32.dll 0x75CD0000 \Windows\System32\urlmon.dll 0x75C80000 \Windows\System32\gdi32.dll 0x75C70000 \Windows\System32\lpk.dll 0x75C60000 \Windows\System32\psapi.dll 0x75C10000 \Windows\System32\Wldap32.dll 0x75B70000 \Windows\System32\usp10.dll 0x759D0000 \Windows\System32\setupapi.dll 0x759B0000 \Windows\System32\sechost.dll 0x75970000 \Windows\System32\ws2_32.dll 0x758A0000 \Windows\System32\user32.dll 0x75890000 \Windows\System32\nsi.dll 0x75830000 \Windows\System32\shlwapi.dll 0x757D0000 \Windows\System32\difxapi.dll 0x756D0000 \Windows\System32\wininet.dll 0x75620000 \Windows\System32\rpcrt4.dll 0x75600000 \Windows\System32\imm32.dll 0x754E0000 \Windows\System32\crypt32.dll 0x75450000 \Windows\System32\comctl32.dll 0x75420000 \Windows\System32\cfgmgr32.dll 0x75400000 \Windows\System32\devobj.dll 0x753D0000 \Windows\System32\wintrust.dll 0x75380000 \Windows\System32\KernelBase.dll 0x75370000 \Windows\System32\msasn1.dll Processes (total 58): 0 System Idle Process 4 System 276 C:\Windows\System32\smss.exe 420 csrss.exe 496 C:\Windows\System32\wininit.exe 504 csrss.exe 556 C:\Windows\System32\services.exe 564 C:\Windows\System32\lsass.exe 572 C:\Windows\System32\lsm.exe 608 C:\Windows\System32\winlogon.exe 720 C:\Windows\System32\svchost.exe 800 C:\Windows\System32\svchost.exe 844 C:\Windows\System32\atiesrxx.exe 928 C:\Windows\System32\svchost.exe 976 C:\Windows\System32\svchost.exe 1028 C:\Windows\System32\svchost.exe 1184 C:\Windows\System32\svchost.exe 1284 C:\Windows\System32\atieclxx.exe 1416 C:\Windows\System32\svchost.exe 1552 C:\Windows\System32\spoolsv.exe 1580 C:\Windows\System32\svchost.exe 1668 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1696 C:\Program Files\Bonjour\mDNSResponder.exe 1740 C:\Program Files\ESET\ESET Smart Security\ekrn.exe 1772 C:\PROGRA~1\McAfee\SITEAD~1\McSACore.exe 1856 C:\Windows\System32\rundll32.exe 1864 C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe 340 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 1024 C:\Windows\System32\svchost.exe 2620 C:\Windows\System32\dwm.exe 2628 C:\Windows\System32\taskhost.exe 2672 C:\Windows\explorer.exe 2936 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2964 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe 2988 C:\Windows\PLFSetI.exe 2996 C:\Program Files\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe 3012 C:\Program Files\iTunes\iTunesHelper.exe 3020 C:\Program Files\ESET\ESET Smart Security\egui.exe 3132 C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3252 C:\Program Files\DAEMON Tools Lite\DTLite.exe 3272 C:\Program Files\ICQ7.4\ICQ.exe 3296 C:\Users\Andre\AppData\Local\temp\RtkBtMnt.exe 3460 C:\Program Files\iPod\bin\iPodService.exe 3540 C:\Windows\System32\SearchIndexer.exe 3664 C:\Program Files\Windows Media Player\wmpnetwk.exe 3848 C:\Windows\System32\svchost.exe 2400 C:\Program Files\Windows Live\Contacts\wlcomm.exe 2888 C:\Windows\System32\svchost.exe 4568 C:\Windows\servicing\TrustedInstaller.exe 4772 C:\Windows\System32\svchost.exe 5528 C:\Program Files\Mozilla Firefox\firefox.exe 5720 C:\Windows\System32\wuauclt.exe 2772 C:\Windows\System32\audiodg.exe 5932 C:\Windows\System32\SearchProtocolHost.exe 4120 C:\Windows\System32\SearchFilterHost.exe 4492 C:\Windows\System32\dllhost.exe 152 C:\Users\Andre\Desktop\MBRCheck.exe 2252 C:\Windows\System32\conhost.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80500000 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000013`e1d00000 (NTFS) PhysicalDrive0 Model Number: HitachiHTS543216L9A300, Rev: FB2OC40C Size Device Name MBR Status -------------------------------------------- 149 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 Done! |
03.06.2011, 10:07 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Problem mit java(Java/trojanerDownloader.....) Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Problem mit java(Java/trojanerDownloader.....) |
antiviren, bild, download, downloader, eset, eset smart security, folge, folgendes, gestartet, gestoppt, java, kein download, leute, meldung, problem, programm, rechts, security, smart, smart security, trojandownloader, trojaner, unterbrochen, verbindung, verhindert, vermeide, zukunft |