nun habe ich den detect log gefunden: Code:
2014-11-20 11:38:36,125 - detector - INFO - Starting with process ID 9696
2014-11-20 11:38:36,125 - detector - ERROR - The user is not an Administrator, aborting
2014-11-20 11:40:07,681 - detector - INFO - Starting with process ID 9060
2014-11-20 11:40:07,681 - detector - ERROR - The user is not an Administrator, aborting
2014-11-20 11:42:20,371 - detector - INFO - Starting with process ID 1488
2014-11-20 11:42:20,371 - detector - INFO - Selected Profile Name: Win7SP1x64
2014-11-20 11:42:20,371 - detector - INFO - Selected Driver: C:\Users\Lange\AppData\Local\Temp\_MEI95202\drivers\winpmem64.sys
2014-11-20 11:42:20,371 - detector.service - INFO - Launching service destroyer...
2014-11-20 11:42:20,371 - detector.service - DEBUG - Unable to OpenService: (1060, 'OpenService', 'Der angegebene Dienst ist kein installierter Dienst.')
2014-11-20 11:42:20,387 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 11:42:20,387 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 11:42:20,387 - detector.service - DEBUG - Unable to delete the service: (6, 'DeleteService', 'Das Handle ist ung\xfcltig.')
2014-11-20 11:42:20,496 - detector.service - INFO - Trying to start the winpmem service...
2014-11-20 11:42:20,558 - detector - INFO - Service started
2014-11-20 11:42:20,558 - detector - INFO - Selected Yara signature file at C:\Users\Lange\AppData\Local\Temp\_MEI95202\rules\signatures.yar
2014-11-20 11:42:20,558 - detector - INFO - Obtaining address space and generating config for volatility
2014-11-20 11:42:21,917 - detector - INFO - Address space: <volatility.plugins.addrspaces.amd64.AMD64PagedMemory object at 0x0A390670>, Base: <volatility.plugins.addrspaces.win32pmem.Win32FileAddressSpace object at 0x08682D70>
2014-11-20 11:42:21,917 - detector - INFO - Profile: <volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0x0963F130>, DTB: 0x1a7000
2014-11-20 11:42:21,917 - detector - INFO - Starting yara scanner...
2014-11-20 12:01:32,157 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x1A3A2E48, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 4b 00 65 00 X.t.r.e.m.e.K.e.
79 00 6c 00 6f 00 67 00 67 00 65 00 72 00 00 00 y.l.o.g.g.e.r...
ca a8 86 4e 10 00 00 88 63 b3 5e 5c 27 d2 30 0f ...N....c.^\'.0.
27 d2 30 0f 27 d2 30 0f 00 00 00 00 07 00 00 00 '.0.'.0.........
00 00 00 00 00 00 00 00 d5 a8 86 4e 00 00 00 88 ...........N....
65 00 78 00 65 00 00 17 73 00 76 00 63 00 68 00 e.x.e...s.v.c.h.
6f 00 73 00 74 00 2e 00 65 00 78 00 65 00 00 00 o.s.t...e.x.e...
d0 a8 86 4e 00 00 00 88 48 b6 9f 1a 00 00 00 00 ...N....H.......
0a 00 00 00 10 00 00 00 20 00 00 00 27 00 00 00 ............'...
58 10 00 00 00 00 00 00 db a8 86 4e 00 00 00 88 X..........N....
50 41 44 44 49 4e 47 58 58 50 41 44 44 49 4e 47 PADDINGXXPADDING
00 00 00 00 07 00 00 00 00 00 30 00 00 00 00 00 ..........0.....
e6 a8 86 4e 00 b2 00 88 38 b4 9f 1a 47 00 53 00 ...N....8...G.S.
56 00 52 00 33 00 32 00 20 00 00 00 27 00 00 00 V.R.3.2.....'...
00 00 00 00 00 00 00 00 e1 a8 86 4e 00 00 00 88 ...........N....
37 30 63 34 33 38 61 62 00 00 00 00 55 8b ec 51 70c438ab....U..Q
2014-11-20 12:01:33,622 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x1AF6C808, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 8d 4e 00 00 00 80 f4 1c 00 00 00 00 4f 00 T..N..........O.
0a dd 71 4e 00 00 00 88 68 02 fb 1a 00 00 00 00 ..qN....h.......
07 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
1e 6e 8d 4e 00 00 00 00 05 dd 71 4e 00 d2 00 88 .n.N......qN....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 00 00 00 00 10 00 00 00 00 00 00 00 CO..............
00 dd 71 4e 00 00 00 88 70 03 fb 1a 00 d2 fa 1a ..qN....p.......
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
0f 00 00 00 00 00 00 00 1b dd 71 4e 00 00 00 88 ..........qN....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CO..............
16 dd 71 4e 00 00 00 88 c8 03 fb 1a 00 00 00 00 ..qN............
0c 6e 8d 4e 00 00 00 80 20 00 00 00 27 00 00 00 .n.N........'...
00 00 00 00 00 00 00 00 11 dd 71 4e 00 00 00 88 ..........qN....
d5 32 96 79 ac 17 3e b3 a4 ab 62 50 a3 c3 e0 3d .2.y..>...bP...=
2014-11-20 12:01:33,622 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x1B090EB0, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 76 00 23 00 2e 00 23 00 20 00 2a 00 20 00 T.v.#...#...*...
49 00 6e 00 73 00 74 00 61 00 6c 00 6c 00 61 00 I.n.s.t.a.l.l.a.
74 00 69 00 6f 00 6e 00 2a 00 00 00 00 00 00 00 t.i.o.n.*.......
89 52 5a 4e 00 00 00 88 58 21 00 00 00 00 97 03 .RZN....X!......
58 21 97 03 57 0d 00 00 00 47 6f 6c 64 20 41 6e X!..W....Gold.An
74 69 76 69 72 75 73 00 47 6f 6c 64 20 41 6e 74 tivirus.Gold.Ant
69 76 69 72 75 73 2e 65 78 65 00 6d 73 63 6f 72 ivirus.exe.mscor
6c 69 62 00 72 75 73 00 b0 52 5a 4e 00 00 00 88 lib.rus..RZN....
e8 5b 28 1a 00 00 00 00 00 00 00 00 00 00 00 00 .[(.............
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
50 11 28 1a 00 00 00 00 00 00 00 00 00 00 00 00 P.(.............
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
a7 52 5a 4e 00 00 00 88 90 53 27 1a 00 00 00 00 .RZN.....S'.....
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 f8 f7 28 1a 00 00 00 00 ..........(.....
2014-11-20 12:01:36,401 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x19932E04, Value:
58 74 72 65 6d 65 52 41 54 76 32 2e 39 5c 48 75 XtremeRATv2.9\Hu
6c 6b 6d 6f 64 49 6e 73 74 61 6c 6c 65 72 2e 65 lkmodInstaller.e
78 65 23 23 24 24 23 23 00 6f 66 74 00 3f 70 ef xe##$$##.oft.?p.
b9 68 0d f8 00 00 63 b5 b4 87 1a 95 7f 28 50 c7 .h....c......(P.
43 47 df 3a 20 12 2a fd d7 6d 6b 6d 7b 79 0a 74 CG.:..*..mkm{y.t
8d 80 4c b4 f7 25 af d4 d4 cf 49 5e 98 d2 0c ea ..L..%....I^....
37 bb 03 2b a6 2a fa ce d6 38 9d da 7d b1 d1 e5 7..+.*...8..}...
40 c7 b8 3c 10 75 2d ae 4e 7b 9f f8 4e 33 b5 6e @..<.u-.N{..N3.n
75 6f 8b 1c 11 ec 9c 77 67 1d 9c 91 04 11 e5 f9 uo.....wg.......
01 6e 5a 00 00 2e 46 03 00 f4 f0 a2 63 2a 48 cf .nZ...F.....c*H.
01 54 91 d5 74 2a 48 cf 01 d5 ab db 74 6d fb fa .T..t*H.....tm..
03 b3 88 ff 2b 9f f5 78 8e 35 de ea 0c 78 d2 f9 ....+..x.5...x..
b2 28 9e 55 3f 6a 9f f5 ab a0 24 97 31 b8 23 b1 .(.U?j....$.1.#.
7e 98 5c 08 09 85 f8 d7 b6 84 3c 2e 6f d7 a8 cc ~.\.......<.o...
7d 87 6b a5 b5 2e 24 01 d7 75 2c 70 bb 1d 32 e1 }.k...$..u,p..2.
39 f0 66 47 14 89 ad d9 8f b3 63 4d 00 00 68 00 9.fG......cM..h.
2014-11-20 12:01:36,401 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x19E8B98A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 47 35 2e 23 23 40 29 16 60 58 58 58 58 T..G5.##@).`XXXX
e0 61 61 61 9a c6 f7 ff ff ff ff ff ff ff 00 8c .aaa............
76 c5 9c a4 87 53 3e f9 15 31 a4 e9 ea 38 83 92 v....S>..1...8..
26 35 6d 8b ed f7 13 c9 ae f0 53 3c b9 09 3f 3f &5m.......S<..??
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f ????????????????
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 38 00 00 00 ????????????8...
00 00 00 00 00 00 00 00 00 00 00 00 00 00 a6 fa ................
fc 4e 00 00 00 88 47 77 00 58 00 58 5a 00 32 7a .N....Gw.X.XZ.2z
00 00 35 00 56 59 52 49 35 45 37 44 77 59 31 4a ..5.VYRI5E7DwY1J
00 00 3e 00 41 00 40 00 ef 00 4c 0e 00 00 00 53 ..>.A.@...L....S
65 72 76 65 72 2e 70 61 63 6b 65 64 2e 70 61 63 erver.packed.pac
6b 65 64 2e 65 78 65 00 53 65 72 76 65 72 2e 70 ked.exe.Server.p
61 63 6b 65 64 2e 00 00 00 00 00 00 00 00 00 00 acked...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2014-11-20 12:01:52,088 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x1CC66280, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 T...e.x.e.......
8b 94 b7 4e 00 00 00 88 53 00 6d 00 61 00 72 00 ...N....S.m.a.r.
74 00 54 00 69 00 70 00 3f 00 2e 00 65 00 78 00 t.T.i.p.?...e.x.
65 00 00 00 00 00 00 00 86 94 b7 4e 00 00 00 88 e..........N....
18 bc 83 6a 44 59 81 6a fc b1 82 6a 8d 69 82 6a ...jDY.j...j.i.j
6e 98 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
81 94 b7 4e 00 00 00 88 2a 00 6d 00 77 00 69 00 ...N....*.m.w.i.
6e 00 73 00 65 00 61 00 72 00 63 00 68 00 2a 00 n.s.e.a.r.c.h.*.
00 00 00 00 00 00 00 00 bc 94 b7 4e 00 00 00 88 ...........N....
73 00 65 00 61 00 72 00 63 00 68 00 5f 00 3f 00 s.e.a.r.c.h._.?.
3f 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 ?...e.x.e.......
b7 94 b7 4e 00 00 00 88 57 00 54 00 6f 00 6f 00 ...N....W.T.o.o.
6c 00 2e 00 44 00 4c 00 4c 00 00 00 00 00 00 00 l...D.L.L.......
00 00 00 00 00 00 00 00 b2 94 b7 4e 00 00 00 88 ...........N....
57 00 54 00 6f 00 6f 00 6c 00 5f 00 44 00 41 00 W.T.o.o.l._.D.A.
2014-11-20 12:01:52,088 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x1CEB1078, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2a 00 2e 00 65 00 78 00 65 00 00 00 00 00 T.*...e.x.e.....
44 ef a2 4e 00 00 00 88 72 00 65 00 64 00 70 00 D..N....r.e.d.p.
6f 00 77 00 65 00 72 00 00 00 00 00 00 00 00 00 o.w.e.r.........
00 00 00 00 00 00 00 00 4f ef a2 4e 00 00 00 88 ........O..N....
4b 00 65 00 79 00 4c 00 6f 00 67 00 67 00 65 00 K.e.y.L.o.g.g.e.
72 00 20 00 3f 00 3f 00 2e 00 00 00 00 00 00 00 r...?.?.........
4a ef a2 4e 00 00 00 88 41 6c 70 68 61 30 2e 70 J..N....Alpha0.p
67 6d 2c 41 6c 70 68 61 31 2e 70 67 6d 00 00 00 gm,Alpha1.pgm...
00 00 00 00 00 00 00 00 75 ef a2 4e 00 00 00 88 ........u..N....
8d 35 3f 3f 3f 3f 40 00 6a 3f 3f 59 f3 3f 3f ff .5????@.j??Y.??.
57 fc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 W...............
70 ef a2 4e 00 00 00 88 66 63 33 44 53 65 78 56 p..N....fc3DSexV
69 6c 6c 61 2e 64 6c 6c 00 00 00 00 00 00 00 00 illa.dll........
00 00 00 00 00 00 00 00 7b ef a2 4e 00 00 00 88 ........{..N....
46 00 72 00 65 00 65 00 43 00 6f 00 64 00 65 00 F.r.e.e.C.o.d.e.
2014-11-20 12:02:35,387 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x2504FFDA, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 00 00 00 4d 5a 00 00 00 01 00 00 a0 28 T.....MZ.......(
4d 73 00 39 00 88 54 00 72 00 6f 00 6a 00 61 00 Ms.9..T.r.o.j.a.
6e 00 2e 00 44 00 72 00 6f 00 70 00 70 00 65 00 n...D.r.o.p.p.e.
72 00 2e 00 58 00 4d 00 4c 00 00 00 00 00 1e 39 r...X.M.L......9
00 00 00 01 00 00 59 17 4d 73 00 ae 00 88 54 00 ......Y.Ms....T.
72 00 6f 00 6a 00 61 00 6e 00 2e 00 44 00 72 00 r.o.j.a.n...D.r.
6f 00 70 00 70 00 65 00 72 00 2e 00 58 00 4d 00 o.p.p.e.r...X.M.
4c 00 00 00 00 00 80 51 0b 00 00 10 00 00 52 17 L......Q......R.
4d 73 00 39 00 80 fe 1c 83 05 69 00 ce 05 14 00 Ms.9......i.....
01 07 02 00 11 00 00 38 37 2c 36 35 2c 32 33 2e .......87,65,23.
65 78 65 00 38 37 2c 36 35 2c 32 33 00 3c 4d 6f exe.87,65,23.<Mo
64 75 6c 65 3e 00 4b 17 4d 73 00 af 00 88 54 00 dule>.K.Ms....T.
72 00 6f 00 6a 00 61 00 6e 00 2e 00 41 00 67 00 r.o.j.a.n...A.g.
65 00 6e 00 74 00 2e 00 4d 00 53 00 4c 00 00 00 e.n.t...M.S.L...
04 00 15 00 00 00 50 14 00 00 10 00 00 00 44 17 ......P.......D.
2014-11-20 12:02:35,387 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x2510AE7A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 73 69 64 65 6e 74 2e 70 64 62 00 00 ec ea T.sident.pdb....
4c 72 81 01 00 80 fb 06 72 76 65 72 00 43 6f 6d Lr......rver.Com
70 69 6c 61 74 69 6f 6e 52 65 6c 61 78 61 74 69 pilationRelaxati
6f 6e 73 00 00 00 e7 ea 4c 72 00 00 00 80 37 07 ons.....Lr....7.
61 64 5f 63 70 6c 2e 63 70 6c 00 43 50 6c 41 70 ad_cpl.cpl.CPlAp
70 6c 65 74 00 2e 65 78 65 00 65 00 44 00 e2 ea plet..exe.e.D...
4c 72 00 00 00 80 23 07 00 20 20 00 00 65 67 6c Lr....#......egl
61 63 2e 65 78 65 00 6e 52 65 6c 61 78 61 74 69 ac.exe.nRelaxati
6f 6e 73 00 0b 25 dd ea 4c 72 00 00 00 80 0a 07 ons..%..Lr......
65 72 76 65 72 2e 65 78 65 00 6d 73 63 6f 72 6c erver.exe.mscorl
69 62 00 67 61 6b 70 68 71 00 5c 00 00 00 d8 ea ib.gakphq.\.....
4c 72 00 96 00 80 c9 06 71 68 6b 2e 64 6c 6c 00 Lr......qhk.dll.
48 6f 6f 6b 4b 42 00 00 00 00 00 00 00 00 18 00 HookKB..........
00 00 81 01 00 00 d3 ea 4c 72 e0 01 00 88 00 77 ........Lr.....w
2e 65 78 65 00 77 00 4d 69 63 72 6f 73 6f 66 74 .exe.w.Microsoft
2014-11-20 12:02:35,388 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x2510AFBA, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 d7 0b 25 00 00 00 00 00 00 00 00 c4 ea T....%..........
4c 72 00 00 00 80 e2 06 65 72 74 79 00 31 32 33 Lr......erty.123
34 35 00 6a 65 73 75 73 00 65 6c 61 78 61 74 69 45.jesus.elaxati
6f 6e 73 00 00 25 3f e9 4c 72 00 00 00 80 39 00 ons..%?.Lr....9.
73 70 2d 61 74 74 30 31 2e 70 6f 70 33 2e 72 75 sp-att01.pop3.ru
2f 6f 72 6b 5f 72 65 74 2e 6a 70 67 00 00 3a e9 /ork_ret.jpg..:.
4c 72 00 96 00 80 32 07 69 74 68 68 66 64 64 67 Lr....2.ithhfddg
66 64 2e 64 6c 6c 00 61 63 6b 49 00 74 61 6c 6c fd.dll.ackI.tall
2e 65 78 65 00 00 35 e9 4c 72 c9 00 00 80 0f 07 .exe..5.Lr......
00 6d 73 63 6f 72 6c 69 62 00 4d 69 63 72 6f 73 .mscorlib.Micros
6f 66 74 00 00 70 00 68 00 70 00 3f 00 00 30 e9 oft..p.h.p.?..0.
4c 72 81 01 00 80 19 07 53 32 63 73 49 78 4e 52 Lr......S2csIxNR
4f 55 42 33 70 54 6c 6b 39 00 64 2e 65 78 65 00 OUB3pTlk9.d.exe.
00 00 00 00 00 00 2b e9 4c 72 00 00 00 80 1e 07 ......+.Lr......
75 62 2e 65 78 65 00 53 74 75 62 00 6d 73 63 6f ub.exe.Stub.msco
2014-11-20 12:02:35,388 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x251DA874, Value:
58 00 54 00 52 00 45 00 4d 00 45 00 55 00 50 00 X.T.R.E.M.E.U.P.
44 00 41 00 54 00 45 00 00 00 00 5a 00 25 53 79 D.A.T.E....Z.%Sy
73 74 65 6d 52 6f 6f 74 25 25 5c 73 79 73 74 65 stemRoot%%\syste
6d 33 32 5c 62 74 77 5f 6f 6b 6f 2e 64 6c 6c 00 m32\btw_oko.dll.
00 37 00 37 00 37 00 37 00 00 00 00 07 02 4e 73 .7.7.7.7......Ns
00 00 00 88 54 64 26 00 06 00 00 00 00 00 eb 42 ....Td&........B
ff ff 00 00 10 00 00 00 01 00 00 00 10 37 9a 25 .............7.%
38 37 9a 25 40 37 9a 25 74 2e 63 70 05 00 00 00 87.%@7.%t.cp....
00 00 00 00 98 7e 1e 25 00 00 00 00 68 27 1a 01 .....~.%....h'..
ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 3c 02 4e 73 00 00 00 88 5f 78 5f 58 ....<.Ns...._x_X
5f 50 41 53 53 57 4f 52 44 4c 49 53 54 5f 58 5f _PASSWORDLIST_X_
78 5f 00 72 79 70 74 6f 72 5f 62 79 5f 6d 65 5c x_.ryptor_by_me\
52 65 6c 65 61 73 65 5c 53 74 75 62 2e 70 64 62 Release\Stub.pdb
00 4f 49 50 2e 61 62 63 00 4f 58 00 00 00 00 00 .OIP.abc.OX.....
00 00 00 00 00 00 00 00 00 00 00 00 31 02 4e 73 ............1.Ns
2014-11-20 12:02:36,776 - detector - WARNING - Process mbamservice.ex (pid: 2512) matched: Xtreme at address: 0x2583309A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 65 74 45 6e 76 69 72 6f 6e 6d 0f 53 29 fb T.etEnvironm.S).
8f 5d 02 1f 73 57 17 43 6f 6d 6d 61 6e 64 4c 11 .]..sW.CommandL.
07 db 3e 76 65 41 10 54 69 63 6b 14 75 36 4d 6f ..>veA.Tick.u6Mo
e6 ef 75 b7 64 63 65 48 21 6c 1f 65 63 6d 70 95 ..u.dceH!l.ecmp.
00 a0 b5 57 43 76 32 f6 dc ac dd 7a 4c 43 4d 9a ...WCv2....zLCM.
54 18 a3 4d 6e b7 db ed 62 72 9f 79 41 35 45 78 T..Mn...br.yA5Ex
26 54 68 12 61 64 d6 b9 9b db 19 43 06 33 45 76 &Th.ad.....C.3Ev
82 27 53 5c 7e 6c 6b bf 3e 50 6f 36 14 72 a3 56 .'S\~lk.>Po6.r.V
65 72 73 69 db ed b9 56 33 9a 38 bf 6f 63 c1 73 ersi...V3.8.oc.s
b7 ef 2f 60 88 31 4e 61 6d 8a 4c 1b 61 6c d7 7d ../`.1Nam.L.al.}
db 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 a6 a7 ................
81 75 00 00 00 89 6d 79 20 70 68 6f 74 6f 4c 6f .u....my.photoLo
2014-11-20 12:05:37,500 - detector - WARNING - Process WDRulesEngine. (pid: 3028) matched: Xtreme at address: 0x3B2C98A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 47 35 2e 23 23 40 29 16 60 58 58 58 58 T..G5.##@).`XXXX
e0 61 61 61 9a c6 f7 ff ff ff ff ff ff ff 00 8c .aaa............
76 c5 9c a4 87 53 3e f9 15 31 a4 e9 ea 38 83 92 v....S>..1...8..
26 35 6d 8b ed f7 13 c9 ae f0 53 3c b9 09 3f 3f &5m.......S<..??
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f ????????????????
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 38 00 00 00 ????????????8...
00 00 00 00 00 00 00 00 00 00 00 00 00 00 a6 fa ................
fc 4e 00 00 00 88 47 77 00 58 00 58 5a 00 32 7a .N....Gw.X.XZ.2z
00 00 35 00 56 59 52 49 35 45 37 44 77 59 31 4a ..5.VYRI5E7DwY1J
00 00 3e 00 41 00 40 00 ef 00 4c 0e 00 00 00 53 ..>.A.@...L....S
65 72 76 65 72 2e 70 61 63 6b 65 64 2e 70 61 63 erver.packed.pac
6b 65 64 2e 65 78 65 00 53 65 72 76 65 72 2e 70 ked.exe.Server.p
61 63 6b 65 64 2e 00 00 00 00 00 00 00 00 00 00 acked...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2014-11-20 12:05:44,359 - detector - WARNING - Process WDRulesEngine. (pid: 3028) matched: Xtreme at address: 0x6964FE48, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 4b 00 65 00 X.t.r.e.m.e.K.e.
79 00 6c 00 6f 00 67 00 67 00 65 00 72 00 00 00 y.l.o.g.g.e.r...
ca a8 86 4e 10 00 00 88 63 b3 5e 5c 27 d2 30 0f ...N....c.^\'.0.
27 d2 30 0f 27 d2 30 0f 00 00 00 00 07 00 00 00 '.0.'.0.........
00 00 00 00 00 00 00 00 d5 a8 86 4e 00 00 00 88 ...........N....
65 00 78 00 65 00 00 17 73 00 76 00 63 00 68 00 e.x.e...s.v.c.h.
6f 00 73 00 74 00 2e 00 65 00 78 00 65 00 00 00 o.s.t...e.x.e...
d0 a8 86 4e 00 00 00 88 48 b6 9f 1a 00 00 00 00 ...N....H.......
0a 00 00 00 10 00 00 00 20 00 00 00 27 00 00 00 ............'...
58 10 00 00 00 00 00 00 db a8 86 4e 00 00 00 88 X..........N....
50 41 44 44 49 4e 47 58 58 50 41 44 44 49 4e 47 PADDINGXXPADDING
00 00 00 00 07 00 00 00 00 00 30 00 00 00 00 00 ..........0.....
e6 a8 86 4e 00 b2 00 88 38 b4 9f 1a 47 00 53 00 ...N....8...G.S.
56 00 52 00 33 00 32 00 20 00 00 00 27 00 00 00 V.R.3.2.....'...
00 00 00 00 00 00 00 00 e1 a8 86 4e 00 00 00 88 ...........N....
37 30 63 34 33 38 61 62 00 00 00 00 55 8b ec 51 70c438ab....U..Q
2014-11-20 12:05:50,171 - detector - WARNING - Process WDRulesEngine. (pid: 3028) matched: Xtreme at address: 0x6AFBDE04, Value:
58 74 72 65 6d 65 52 41 54 76 32 2e 39 5c 48 75 XtremeRATv2.9\Hu
6c 6b 6d 6f 64 49 6e 73 74 61 6c 6c 65 72 2e 65 lkmodInstaller.e
78 65 23 23 24 24 23 23 00 6f 66 74 00 3f 70 ef xe##$$##.oft.?p.
b9 68 0d f8 00 00 63 b5 b4 87 1a 95 7f 28 50 c7 .h....c......(P.
43 47 df 3a 20 12 2a fd d7 6d 6b 6d 7b 79 0a 74 CG.:..*..mkm{y.t
8d 80 4c b4 f7 25 af d4 d4 cf 49 5e 98 d2 0c ea ..L..%....I^....
37 bb 03 2b a6 2a fa ce d6 38 9d da 7d b1 d1 e5 7..+.*...8..}...
40 c7 b8 3c 10 75 2d ae 4e 7b 9f f8 4e 33 b5 6e @..<.u-.N{..N3.n
75 6f 8b 1c 11 ec 9c 77 67 1d 9c 91 04 11 e5 f9 uo.....wg.......
01 6e 5a 00 00 2e 46 03 00 f4 f0 a2 63 2a 48 cf .nZ...F.....c*H.
01 54 91 d5 74 2a 48 cf 01 d5 ab db 74 6d fb fa .T..t*H.....tm..
03 b3 88 ff 2b 9f f5 78 8e 35 de ea 0c 78 d2 f9 ....+..x.5...x..
b2 28 9e 55 3f 6a 9f f5 ab a0 24 97 31 b8 23 b1 .(.U?j....$.1.#.
7e 98 5c 08 09 85 f8 d7 b6 84 3c 2e 6f d7 a8 cc ~.\.......<.o...
7d 87 6b a5 b5 2e 24 01 d7 75 2c 70 bb 1d 32 e1 }.k...$..u,p..2.
39 f0 66 47 14 89 ad d9 8f b3 63 4d 00 00 68 00 9.fG......cM..h.
2014-11-20 13:01:53,936 - detector - INFO - Scanning finished
2014-11-20 13:01:53,936 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 13:01:53,936 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 13:01:53,936 - detector - INFO - Service stopped
2014-11-20 13:01:53,936 - detector - INFO - Analysis finished
2014-11-20 16:36:41,930 - detector - INFO - Starting with process ID 3960
2014-11-20 16:36:41,938 - detector - INFO - Selected Profile Name: Win7SP1x64
2014-11-20 16:36:41,940 - detector - INFO - Selected Driver: C:\Users\Lange\AppData\Local\Temp\_MEI58402\drivers\winpmem64.sys
2014-11-20 16:36:41,940 - detector.service - INFO - Launching service destroyer...
2014-11-20 16:36:41,943 - detector.service - DEBUG - Unable to OpenService: (1060, 'OpenService', 'Der angegebene Dienst ist kein installierter Dienst.')
2014-11-20 16:36:41,943 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 16:36:41,943 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 16:36:41,944 - detector.service - DEBUG - Unable to delete the service: (6, 'DeleteService', 'Das Handle ist ung\xfcltig.')
2014-11-20 16:36:42,026 - detector.service - INFO - Trying to start the winpmem service...
2014-11-20 16:36:42,089 - detector - INFO - Service started
2014-11-20 16:36:42,091 - detector - INFO - Selected Yara signature file at C:\Users\Lange\AppData\Local\Temp\_MEI58402\rules\signatures.yar
2014-11-20 16:36:42,092 - detector - INFO - Obtaining address space and generating config for volatility
2014-11-20 16:36:43,490 - detector - INFO - Address space: <volatility.plugins.addrspaces.amd64.AMD64PagedMemory object at 0x0B095610>, Base: <volatility.plugins.addrspaces.win32pmem.Win32FileAddressSpace object at 0x0A2C9F70>
2014-11-20 16:36:43,490 - detector - INFO - Profile: <volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0x041A8030>, DTB: 0x1a7000
2014-11-20 16:36:43,492 - detector - INFO - Starting yara scanner...
2014-11-20 16:58:02,941 - detector - INFO - Starting with process ID 6876
2014-11-20 16:58:02,941 - detector - INFO - Selected Profile Name: Win7SP1x64
2014-11-20 16:58:02,941 - detector - INFO - Selected Driver: C:\Users\Lange\AppData\Local\Temp\_MEI39322\drivers\winpmem64.sys
2014-11-20 16:58:02,941 - detector.service - INFO - Launching service destroyer...
2014-11-20 16:58:02,941 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 16:58:02,941 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 16:58:03,036 - detector.service - INFO - Trying to start the winpmem service...
2014-11-20 16:58:03,066 - detector - INFO - Service started
2014-11-20 16:58:03,066 - detector - INFO - Selected Yara signature file at C:\Users\Lange\AppData\Local\Temp\_MEI39322\rules\signatures.yar
2014-11-20 16:58:03,066 - detector - INFO - Obtaining address space and generating config for volatility
2014-11-20 16:58:04,181 - detector - INFO - Address space: <volatility.plugins.addrspaces.amd64.AMD64PagedMemory object at 0x0B1B6610>, Base: <volatility.plugins.addrspaces.win32pmem.Win32FileAddressSpace object at 0x0A3AAFF0>
2014-11-20 16:58:04,181 - detector - INFO - Profile: <volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0x0A3AAF70>, DTB: 0x1a7000
2014-11-20 16:58:04,181 - detector - INFO - Starting yara scanner...
2014-11-20 17:12:08,220 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x1D0160A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 65 74 45 6e 76 69 72 6f 6e 6d 0f 53 29 fb T.etEnvironm.S).
8f 5d 02 1f 73 57 17 43 6f 6d 6d 61 6e 64 4c 11 .]..sW.CommandL.
07 db 3e 76 65 41 10 54 69 63 6b 14 75 36 4d 6f ..>veA.Tick.u6Mo
e6 ef 75 b7 64 63 65 48 21 6c 1f 65 63 6d 70 95 ..u.dceH!l.ecmp.
00 a0 b5 57 43 76 32 f6 dc ac dd 7a 4c 43 4d 9a ...WCv2....zLCM.
54 18 a3 4d 6e b7 db ed 62 72 9f 79 41 35 45 78 T..Mn...br.yA5Ex
26 54 68 12 61 64 d6 b9 9b db 19 43 06 33 45 76 &Th.ad.....C.3Ev
82 27 53 5c 7e 6c 6b bf 3e 50 6f 36 14 72 a3 56 .'S\~lk.>Po6.r.V
65 72 73 69 db ed b9 56 33 9a 38 bf 6f 63 c1 73 ersi...V3.8.oc.s
b7 ef 2f 60 88 31 4e 61 6d 8a 4c 1b 61 6c d7 7d ../`.1Nam.L.al.}
db 00 00 00 00 00 33 36 30 c9 b1 b6 be 00 00 00 ......360.......
00 00 33 36 30 73 64 2e 65 78 65 00 00 00 c8 f0 ..360sd.exe.....
d0 c7 c9 b1 b6 be 00 00 00 00 52 61 76 4d 6f 6e ..........RavMon
44 2e 65 78 65 00 64 79 05 00 49 2f 00 00 4d 71 D.exe.dy..I/..Mq
1a 02 00 00 00 89 4f 55 54 42 52 4f 57 53 45 31 ......OUTBROWSE1
2014-11-20 17:13:20,740 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x1AD28510, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 65 00 6d 73 63 6f 72 6c 69 62 00 00 00 00 T.e.mscorlib....
7c a0 ad 3c 00 00 00 88 08 26 b6 1a 00 00 00 00 |..<.....&......
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 71 a0 ad 3c 00 00 00 88 ........q..<....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CO..............
6a a0 ad 3c 00 00 00 88 10 27 b6 1a d5 81 48 5d j..<.....'....H]
d5 81 48 5d d5 81 48 5d 20 00 00 00 27 00 00 00 ..H]..H]....'...
00 00 00 00 00 00 00 00 6f a0 ad 3c 00 00 00 88 ........o..<....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CO..............
60 a0 ad 3c 00 00 00 88 68 27 b6 1a 81 ce 80 e4 `..<....h'......
81 ce 80 e4 81 ce 80 e4 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 65 a0 ad 3c 00 00 00 88 ........e..<....
d5 32 96 79 ac 17 3e b3 a4 ab 62 50 a3 c3 e0 3d .2.y..>...bP...=
2014-11-20 17:13:20,742 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x1AD44848, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 76 00 23 00 2e 00 23 00 20 00 2a 00 20 00 T.v.#...#...*...
49 00 6e 00 73 00 74 00 61 00 6c 00 6c 00 61 00 I.n.s.t.a.l.l.a.
74 00 69 00 6f 00 6e 00 2a 00 00 00 00 00 00 00 t.i.o.n.*.......
73 3a aa 3c 00 00 00 88 58 21 00 00 00 00 97 03 s:.<....X!......
58 21 97 03 57 0d 00 00 00 47 6f 6c 64 20 41 6e X!..W....Gold.An
74 69 76 69 72 75 73 00 47 6f 6c 64 20 41 6e 74 tivirus.Gold.Ant
69 76 69 72 75 73 2e 65 78 65 00 6d 73 63 6f 72 ivirus.exe.mscor
6c 69 62 00 72 75 73 00 78 3a aa 3c 00 00 00 88 lib.rus.x:.<....
a0 60 39 1a 00 00 00 00 00 00 00 00 00 00 00 00 .`9.............
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
58 62 39 1a 00 00 00 00 00 00 00 00 00 00 00 00 Xb9.............
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
41 3a aa 3c 00 00 00 88 40 6a 39 1a 00 00 00 00 A:.<....@j9.....
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 78 66 39 1a 00 00 00 00 ........xf9.....
2014-11-20 17:14:17,286 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x19A89D28, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 4b 00 65 00 X.t.r.e.m.e.K.e.
79 00 6c 00 6f 00 67 00 67 00 65 00 72 00 00 00 y.l.o.g.g.e.r...
db 62 af 3c 00 00 00 88 38 0b 72 1a 63 00 72 00 .b.<....8.r.c.r.
6f 00 3f 00 6f 00 66 00 20 00 00 00 27 00 00 00 o.?.o.f.....'...
6f 73 6f 66 00 00 00 00 dc 62 af 3c 03 00 00 88 osof.....b.<....
72 00 65 00 76 00 69 00 65 00 77 00 6e 00 73 00 r.e.v.i.e.w.n.s.
00 00 00 00 07 00 00 00 45 00 00 00 00 00 00 00 ........E.......
c1 62 af 3c 00 00 00 88 4a c7 bc f4 0e a6 d2 a7 .b.<....J.......
0e a6 d2 a7 0e a6 d2 a7 00 00 32 00 38 00 00 00 ..........2.8...
00 00 32 00 00 00 00 00 ca 62 af 3c 08 00 00 88 ..2......b.<....
50 00 45 00 53 00 48 00 69 00 45 00 4c 00 44 00 P.E.S.H.i.E.L.D.
00 00 00 00 07 00 00 00 00 00 00 00 00 00 00 00 ................
cf 62 af 3c 00 00 00 88 25 00 55 00 4e 00 4b 00 .b.<....%.U.N.K.
4e 00 4f 00 57 00 4e 00 25 00 00 00 07 00 00 00 N.O.W.N.%.......
07 00 00 00 00 00 00 00 b0 62 af 3c 07 00 00 88 .........b.<....
8b 6b 71 ec cf 0a 1f bf cf 0a 1f bf cf 0a 1f bf .kq.............
2014-11-20 17:14:36,539 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x1BDAE098, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 T...e.x.e.......
1d 2c f8 3c 00 00 00 88 53 00 6d 00 61 00 72 00 .,.<....S.m.a.r.
74 00 54 00 69 00 70 00 3f 00 2e 00 65 00 78 00 t.T.i.p.?...e.x.
65 00 00 00 00 00 00 00 16 2c f8 3c 00 00 00 88 e........,.<....
18 bc 83 6a 44 59 81 6a fc b1 82 6a 8d 69 82 6a ...jDY.j...j.i.j
6e 98 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
2b 2c f8 3c 00 00 00 88 2a 00 6d 00 77 00 69 00 +,.<....*.m.w.i.
6e 00 73 00 65 00 61 00 72 00 63 00 68 00 2a 00 n.s.e.a.r.c.h.*.
00 00 00 00 00 00 00 00 2c 2c f8 3c 00 00 00 88 ........,,.<....
73 00 65 00 61 00 72 00 63 00 68 00 5f 00 3f 00 s.e.a.r.c.h._.?.
3f 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 ?...e.x.e.......
21 2c f8 3c 00 00 00 88 57 00 54 00 6f 00 6f 00 !,.<....W.T.o.o.
6c 00 2e 00 44 00 4c 00 4c 00 00 00 00 00 00 00 l...D.L.L.......
00 00 00 00 00 00 00 00 3a 2c f8 3c 00 00 00 88 ........:,.<....
57 00 54 00 6f 00 6f 00 6c 00 5f 00 44 00 41 00 W.T.o.o.l._.D.A.
2014-11-20 17:14:36,542 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x1C000E90, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2a 00 2e 00 65 00 78 00 65 00 00 00 00 00 T.*...e.x.e.....
24 4a 77 3c 00 00 00 88 72 00 65 00 64 00 70 00 $Jw<....r.e.d.p.
6f 00 77 00 65 00 72 00 00 00 00 00 00 00 00 00 o.w.e.r.........
00 00 00 00 00 00 00 00 29 4a 77 3c 00 00 00 88 ........)Jw<....
4b 00 65 00 79 00 4c 00 6f 00 67 00 67 00 65 00 K.e.y.L.o.g.g.e.
72 00 20 00 3f 00 3f 00 2e 00 00 00 00 00 00 00 r...?.?.........
12 4a 77 3c 00 00 00 88 41 6c 70 68 61 30 2e 70 .Jw<....Alpha0.p
67 6d 2c 41 6c 70 68 61 31 2e 70 67 6d 00 00 00 gm,Alpha1.pgm...
00 00 00 00 00 00 00 00 17 4a 77 3c 00 00 00 88 .........Jw<....
8d 35 3f 3f 3f 3f 40 00 6a 3f 3f 59 f3 3f 3f ff .5????@.j??Y.??.
57 fc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 W...............
18 4a 77 3c 00 00 00 88 66 63 33 44 53 65 78 56 .Jw<....fc3DSexV
69 6c 6c 61 2e 64 6c 6c 00 00 00 00 00 00 00 00 illa.dll........
00 00 00 00 00 00 00 00 1d 4a 77 3c 00 00 00 88 .........Jw<....
46 00 72 00 65 00 65 00 43 00 6f 00 64 00 65 00 F.r.e.e.C.o.d.e.
2014-11-20 17:15:34,407 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x24D5CC84, Value:
58 74 72 65 6d 65 52 41 54 76 32 2e 39 5c 48 75 XtremeRATv2.9\Hu
6c 6b 6d 6f 64 49 6e 73 74 61 6c 6c 65 72 2e 65 lkmodInstaller.e
78 65 23 23 24 24 23 23 00 00 00 00 94 3e 96 06 xe##$$##.....>..
00 00 00 80 7d 03 66 00 38 00 36 00 36 00 32 00 ....}.f.8.6.6.2.
38 00 38 00 35 00 35 00 36 00 37 00 62 00 66 00 8.8.5.5.6.7.b.f.
30 00 36 00 61 00 33 00 66 00 39 00 31 00 64 00 0.6.a.3.f.9.1.d.
30 00 65 00 31 00 36 00 66 00 62 00 31 00 30 00 0.e.1.6.f.b.1.0.
32 00 32 00 00 00 32 00 34 00 58 00 6e 00 62 00 2.2...2.4.X.n.b.
70 00 00 00 a3 3e 96 06 00 49 00 88 31 2e 30 2e p....>...I..1.0.
30 2e 30 00 00 29 01 00 24 35 34 65 39 31 36 61 0.0..)..$54e916a
37 2d 36 62 37 63 2d 34 39 61 39 2d 61 65 39 65 7-6b7c-49a9-ae9e
2d 35 33 63 38 62 35 38 38 38 39 64 62 00 00 17 -53c8b58889db...
01 00 12 43 6f 70 79 72 69 67 68 74 20 c2 a9 20 ...Copyright....
20 32 30 31 34 00 58 00 45 00 00 00 ae 3e 96 06 .2014.X.E....>..
00 00 00 80 93 03 31 00 37 00 62 00 61 00 38 00 ......1.7.b.a.8.
62 00 65 00 32 00 36 00 35 00 66 00 36 00 35 00 b.e.2.6.5.f.6.5.
2014-11-20 17:15:34,407 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x24F48C3A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 73 69 64 65 6e 74 2e 70 64 62 00 00 d9 ee T.sident.pdb....
99 06 00 00 00 80 d4 0f 72 76 65 72 00 43 6f 6d ........rver.Com
70 69 6c 61 74 69 6f 6e 52 65 6c 61 78 61 74 69 pilationRelaxati
6f 6e 73 00 00 00 c2 ee 99 06 00 00 00 80 10 10 ons.............
61 64 5f 63 70 6c 2e 63 70 6c 00 43 50 6c 41 70 ad_cpl.cpl.CPlAp
70 6c 65 74 00 2e 65 78 65 00 65 00 44 00 c7 ee plet..exe.e.D...
99 06 00 00 00 80 fc 0f 00 20 20 00 00 65 67 6c .............egl
61 63 2e 65 78 65 00 6e 52 65 6c 61 78 61 74 69 ac.exe.nRelaxati
6f 6e 73 00 00 00 c8 ee 99 06 00 00 00 80 e3 0f ons.............
65 72 76 65 72 2e 65 78 65 00 6d 73 63 6f 72 6c erver.exe.mscorl
69 62 00 67 61 6b 70 68 71 00 5c 00 00 00 cd ee ib.gakphq.\.....
99 06 00 00 00 80 a2 0f 71 68 6b 2e 64 6c 6c 00 ........qhk.dll.
48 6f 6f 6b 4b 42 00 00 00 00 00 00 00 00 00 00 HookKB..........
00 00 00 00 00 00 f6 ee 99 06 00 00 00 80 bb 0f ................
65 72 76 65 72 2e 65 78 65 00 6d 73 63 6f 72 6c erver.exe.mscorl
2014-11-20 17:15:34,407 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x24F48D7A, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 00 00 00 00 00 00 00 00 00 00 00 e1 ee T...............
99 06 00 00 00 80 c5 0f 65 72 74 79 00 31 32 33 ........erty.123
34 35 00 6a 65 73 75 73 00 65 6c 61 78 61 74 69 45.jesus.elaxati
6f 6e 73 00 00 00 ea ee 99 06 00 00 00 80 12 09 ons.............
73 70 2d 61 74 74 30 31 2e 70 6f 70 33 2e 72 75 sp-att01.pop3.ru
2f 6f 72 6b 5f 72 65 74 2e 6a 70 67 00 00 ef ee /ork_ret.jpg....
99 06 00 00 00 80 0b 10 69 74 68 68 66 64 64 67 ........ithhfddg
66 64 2e 64 6c 6c 00 61 63 6b 49 00 74 61 6c 6c fd.dll.ackI.tall
2e 65 78 65 00 00 90 ee 99 06 00 00 00 80 e8 0f .exe............
00 6d 73 63 6f 72 6c 69 62 00 4d 69 63 72 6f 73 .mscorlib.Micros
6f 66 74 00 00 70 00 68 00 70 00 3f 00 00 95 ee oft..p.h.p.?....
99 06 00 00 00 80 f2 0f 53 32 63 73 49 78 4e 52 ........S2csIxNR
4f 55 42 33 70 54 6c 6b 39 00 64 2e 65 78 65 00 OUB3pTlk9.d.exe.
00 00 00 00 00 00 9e ee 99 06 00 00 00 80 82 1b ................
75 62 2e 65 78 65 00 53 74 75 62 00 6d 73 63 6f ub.exe.Stub.msco
2014-11-20 17:15:34,408 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x24FBB052, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 47 35 2e 23 23 40 29 16 60 58 58 58 58 T..G5.##@).`XXXX
e0 61 61 61 9a c6 f7 ff ff ff ff ff ff ff 00 8c .aaa............
76 c5 9c a4 87 53 3e f9 15 31 a4 e9 ea 38 83 92 v....S>..1...8..
26 35 6d 8b ed f7 13 c9 ae f0 53 3c b9 09 3f 3f &5m.......S<..??
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f ????????????????
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 38 00 00 00 ????????????8...
00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 ca ................
ac 06 00 00 00 88 47 77 00 58 00 58 5a 00 32 7a ......Gw.X.XZ.2z
00 00 35 00 56 59 52 49 35 45 37 44 77 59 31 4a ..5.VYRI5E7DwY1J
00 00 3e 00 41 00 40 00 ef 00 4c 0e 00 00 00 53 ..>.A.@...L....S
65 72 76 65 72 2e 70 61 63 6b 65 64 2e 70 61 63 erver.packed.pac
6b 65 64 2e 65 78 65 00 53 65 72 76 65 72 2e 70 ked.exe.Server.p
61 63 6b 65 64 2e 00 00 00 00 00 00 00 00 00 00 acked...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2014-11-20 17:15:34,410 - detector - WARNING - Process mbamservice.ex (pid: 2776) matched: Xtreme at address: 0x24F95E2C, Value:
58 00 54 00 52 00 45 00 4d 00 45 00 55 00 50 00 X.T.R.E.M.E.U.P.
44 00 41 00 54 00 45 00 00 00 00 5a 00 25 53 79 D.A.T.E....Z.%Sy
73 74 65 6d 52 6f 6f 74 25 25 5c 73 79 73 74 65 stemRoot%%\syste
6d 33 32 5c 62 74 77 5f 6f 6b 6f 2e 64 6c 6c 00 m32\btw_oko.dll.
00 37 00 37 00 37 00 37 00 00 00 00 e5 97 ac 06 .7.7.7.7........
00 00 00 88 31 39 35 2e 32 35 2e 31 39 30 2e 31 ....195.25.190.1
38 30 2f 70 63 6c 74 67 2f 66 72 2f 31 2e 65 78 80/pcltg/fr/1.ex
65 00 74 2e 70 68 70 00 5c 49 64 48 54 54 50 2e e.t.php.\IdHTTP.
70 61 73 00 00 10 00 00 00 00 6a 00 ff 15 98 f8 pas.......j.....
09 10 cc cc 00 38 35 36 62 65 31 36 33 38 30 66 .....856be16380f
30 30 34 00 f0 97 ac 06 00 00 00 80 a9 03 63 64 004...........cd
6a 69 77 6d 63 73 8b c0 55 8b ec 81 c4 04 f0 ff jiwmcs..U.......
ff 50 81 c4 00 72 6b 00 6e 6f 66 64 6f 67 7a 00 .P...rk.nofdogz.
72 74 4b 65 79 4c 6f 67 48 6f 6f 6b 69 6e 67 00 rtKeyLogHooking.
53 74 6f 70 4b 65 79 4c 6f 67 48 6f 6f 6b 69 6e StopKeyLogHookin
67 00 32 00 9c fe 1b 9d 6d 0e 79 00 cf 97 ac 06 g.2.....m.y.....
2014-11-20 17:49:31,029 - detector - INFO - Starting with process ID 4984
2014-11-20 17:49:31,029 - detector - INFO - Selected Profile Name: Win7SP1x64
2014-11-20 17:49:31,029 - detector - INFO - Selected Driver: C:\Users\Lange\AppData\Local\Temp\_MEI86042\drivers\winpmem64.sys
2014-11-20 17:49:31,029 - detector.service - INFO - Launching service destroyer...
2014-11-20 17:49:31,029 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 17:49:31,029 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 17:49:31,341 - detector.service - INFO - Trying to start the winpmem service...
2014-11-20 17:49:31,388 - detector - INFO - Service started
2014-11-20 17:49:31,388 - detector - INFO - Selected Yara signature file at C:\Users\Lange\AppData\Local\Temp\_MEI86042\rules\signatures.yar
2014-11-20 17:49:31,388 - detector - INFO - Obtaining address space and generating config for volatility
2014-11-20 17:49:32,792 - detector - INFO - Address space: <volatility.plugins.addrspaces.amd64.AMD64PagedMemory object at 0x0AEBC5D0>, Base: <volatility.plugins.addrspaces.win32pmem.Win32FileAddressSpace object at 0x0A0EBD10>
2014-11-20 17:49:32,792 - detector - INFO - Profile: <volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0x0A0F1190>, DTB: 0x1a7000
2014-11-20 17:49:32,792 - detector - INFO - Starting yara scanner...
2014-11-20 18:04:48,691 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x1ADFE678, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 23 00 00 00 00 00 00 00 00 00 00 00 00 00 T.#.............
17 df 11 59 00 00 00 88 88 06 da 1a 00 00 00 00 ...Y............
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 1c df 11 59 00 00 00 88 ...........Y....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 07 00 00 00 00 00 00 00 00 00 00 00 CO..............
19 df 11 59 00 00 00 88 90 07 da 1a 00 00 00 00 ...Y............
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 26 df 11 59 00 00 00 88 ........&..Y....
50 45 00 00 4c 01 03 00 00 00 3f 3f 3f 3f 50 45 PE..L.....????PE
43 4f 00 00 07 00 00 00 00 00 00 00 00 00 00 00 CO..............
23 df 11 59 00 00 00 88 e8 07 da 1a 00 00 00 00 #..Y............
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 28 df 11 59 00 00 00 88 ........(..Y....
d5 32 96 79 ac 17 3e b3 a4 ab 62 50 a3 c3 e0 3d .2.y..>...bP...=
2014-11-20 18:04:48,693 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x1AED30D0, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 76 00 23 00 2e 00 23 00 20 00 2a 00 20 00 T.v.#...#...*...
49 00 6e 00 73 00 74 00 61 00 6c 00 6c 00 61 00 I.n.s.t.a.l.l.a.
74 00 69 00 6f 00 6e 00 2a 00 00 00 00 00 00 00 t.i.o.n.*.......
06 2a f2 59 00 00 00 88 58 21 00 00 00 00 97 03 .*.Y....X!......
58 21 97 03 57 0d 00 00 00 47 6f 6c 64 20 41 6e X!..W....Gold.An
74 69 76 69 72 75 73 00 47 6f 6c 64 20 41 6e 74 tivirus.Gold.Ant
69 76 69 72 75 73 2e 65 78 65 00 6d 73 63 6f 72 ivirus.exe.mscor
6c 69 62 00 72 75 73 00 0f 2a f2 59 00 00 00 88 lib.rus..*.Y....
80 f3 04 1a 00 00 00 00 00 00 00 00 00 00 00 00 ................
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
68 c4 04 1a 00 00 00 00 00 00 00 00 00 00 00 00 h...............
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
10 2a f2 59 00 00 00 88 c8 44 03 1a 00 00 00 00 .*.Y.....D......
00 00 00 00 00 00 00 00 20 00 00 00 27 00 00 00 ............'...
00 00 00 00 00 00 00 00 d8 fe 04 1a 00 00 00 00 ................
2014-11-20 18:04:51,424 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x19951DC8, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 4b 00 65 00 X.t.r.e.m.e.K.e.
79 00 6c 00 6f 00 67 00 67 00 65 00 72 00 00 00 y.l.o.g.g.e.r...
51 e5 93 59 00 00 00 88 a0 e7 58 1a 44 00 2e 00 Q..Y......X.D...
45 00 58 00 45 00 00 00 20 00 00 00 27 00 00 00 E.X.E.......'...
65 00 78 00 00 00 00 00 2e e5 93 59 07 00 00 88 e.x........Y....
a8 e8 58 1a 45 f8 33 c5 89 45 e4 53 56 57 50 8d ..X.E.3..E.SVWP.
20 00 00 00 27 00 00 00 00 00 00 00 00 00 00 00 ....'...........
2b e5 93 59 00 00 00 88 37 30 63 34 33 38 61 62 +..Y....70c438ab
00 00 00 00 55 8b ec 51 c6 45 ff 02 8a 45 ff 59 ....U..Q.E...E.Y
00 00 25 00 00 00 00 00 20 e5 93 59 07 00 00 88 ..%........Y....
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 32 00 38 00 00 00 00 00 5a 00 42 00 00 00 ..2.8.....Z.B...
3d e5 93 59 00 00 00 88 d3 9d 61 26 97 fc 0f 75 =..Y......a&...u
97 fc 0f 75 97 fc 0f 75 00 00 00 00 07 00 00 00 ...u...u........
00 00 00 00 00 00 00 00 3a e5 93 59 00 00 00 88 ........:..Y....
d8 00 7e 19 30 00 30 00 30 00 33 00 30 00 30 00 ..~.0.0.0.3.0.0.
2014-11-20 18:04:55,693 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x1BED62D0, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 T...e.x.e.......
1a 86 8e 5a 00 00 00 88 53 00 6d 00 61 00 72 00 ...Z....S.m.a.r.
74 00 54 00 69 00 70 00 3f 00 2e 00 65 00 78 00 t.T.i.p.?...e.x.
65 00 00 00 00 00 00 00 27 86 8e 5a 00 00 00 88 e.......'..Z....
18 bc 83 6a 44 59 81 6a fc b1 82 6a 8d 69 82 6a ...jDY.j...j.i.j
6e 98 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
2c 86 8e 5a 00 00 00 88 2a 00 6d 00 77 00 69 00 ,..Z....*.m.w.i.
6e 00 73 00 65 00 61 00 72 00 63 00 68 00 2a 00 n.s.e.a.r.c.h.*.
00 00 00 00 00 00 00 00 29 86 8e 5a 00 00 00 88 ........)..Z....
73 00 65 00 61 00 72 00 63 00 68 00 5f 00 3f 00 s.e.a.r.c.h._.?.
3f 00 2e 00 65 00 78 00 65 00 00 00 00 00 00 00 ?...e.x.e.......
36 86 8e 5a 00 00 00 88 57 00 54 00 6f 00 6f 00 6..Z....W.T.o.o.
6c 00 2e 00 44 00 4c 00 4c 00 00 00 00 00 00 00 l...D.L.L.......
00 00 00 00 00 00 00 00 33 86 8e 5a 00 00 00 88 ........3..Z....
57 00 54 00 6f 00 6f 00 6c 00 5f 00 44 00 41 00 W.T.o.o.l._.D.A.
2014-11-20 18:04:55,693 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x1C1110C8, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 2a 00 2e 00 65 00 78 00 65 00 00 00 00 00 T.*...e.x.e.....
59 09 71 5a 00 00 00 88 72 00 65 00 64 00 70 00 Y.qZ....r.e.d.p.
6f 00 77 00 65 00 72 00 00 00 00 00 00 00 00 00 o.w.e.r.........
00 00 00 00 00 00 00 00 66 09 71 5a 00 00 00 88 ........f.qZ....
4b 00 65 00 79 00 4c 00 6f 00 67 00 67 00 65 00 K.e.y.L.o.g.g.e.
72 00 20 00 3f 00 3f 00 2e 00 00 00 00 00 00 00 r...?.?.........
63 09 71 5a 00 00 00 88 41 6c 70 68 61 30 2e 70 c.qZ....Alpha0.p
67 6d 2c 41 6c 70 68 61 31 2e 70 67 6d 00 00 00 gm,Alpha1.pgm...
00 00 00 00 00 00 00 00 68 09 71 5a 00 00 00 88 ........h.qZ....
8d 35 3f 3f 3f 3f 40 00 6a 3f 3f 59 f3 3f 3f ff .5????@.j??Y.??.
57 fc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 W...............
75 09 71 5a 00 00 00 88 66 63 33 44 53 65 78 56 u.qZ....fc3DSexV
69 6c 6c 61 2e 64 6c 6c 00 00 00 00 00 00 00 00 illa.dll........
00 00 00 00 00 00 00 00 72 09 71 5a 00 00 00 88 ........r.qZ....
46 00 72 00 65 00 65 00 43 00 6f 00 64 00 65 00 F.r.e.e.C.o.d.e.
2014-11-20 18:05:18,529 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x1EE71DFC, Value:
58 74 72 65 6d 65 52 41 54 76 32 2e 39 5c 48 75 XtremeRATv2.9\Hu
6c 6b 6d 6f 64 49 6e 73 74 61 6c 6c 65 72 2e 65 lkmodInstaller.e
78 65 23 23 24 24 23 23 00 00 00 00 a1 6d 9d 5c xe##$$##.....m.\
00 00 00 80 7c 12 77 2e 77 69 73 64 6f 6d 34 38 ....|.w.wisdom48
39 39 2e 6e 65 74 3a 32 30 31 33 00 3d 00 46 00 99.net:2013.=.F.
4f 00 55 00 4e 00 44 00 2e 00 30 00 30 00 37 00 O.U.N.D...0.0.7.
2e 00 65 00 78 00 65 00 3f 51 51 6c 6f 67 0f 0e ..e.x.e.?QQlog..
31 0f 5c 2b 00 c0 03 00 00 90 00 15 00 53 48 44 1.\+.........SHD
6f 00 00 00 b4 6d 9d 5c 00 00 00 88 46 44 53 77 o....m.\....FDSw
68 72 33 33 37 36 37 39 35 72 33 34 6a 6b 6f 68 hr3376795r34jkoh
35 6f 69 33 68 35 33 34 69 2e 63 70 6c 00 43 50 5oi3h534i.cpl.CP
6c 41 70 70 6c 65 74 00 6c 41 70 70 6c 65 74 00 lApplet.lApplet.
00 c0 14 00 0c 00 00 00 bd 31 00 00 00 00 74 00 .........1....t.
4e 00 61 00 00 2a 86 48 86 00 00 00 bf 6d 9d 5c N.a..*.H.....m.\
00 00 00 88 43 72 79 70 74 65 64 00 43 72 79 70 ....Crypted.Cryp
74 65 64 2e 65 78 65 00 6d 73 63 6f 72 6c 69 62 ted.exe.mscorlib
2014-11-20 18:05:47,605 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x2590DBE2, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 65 74 45 6e 76 69 72 6f 6e 6d 0f 53 29 fb T.etEnvironm.S).
8f 5d 02 1f 73 57 17 43 6f 6d 6d 61 6e 64 4c 11 .]..sW.CommandL.
07 db 3e 76 65 41 10 54 69 63 6b 14 75 36 4d 6f ..>veA.Tick.u6Mo
e6 ef 75 b7 64 63 65 48 21 6c 1f 65 63 6d 70 95 ..u.dceH!l.ecmp.
00 a0 b5 57 43 76 32 f6 dc ac dd 7a 4c 43 4d 9a ...WCv2....zLCM.
54 18 a3 4d 6e b7 db ed 62 72 9f 79 41 35 45 78 T..Mn...br.yA5Ex
26 54 68 12 61 64 d6 b9 9b db 19 43 06 33 45 76 &Th.ad.....C.3Ev
82 27 53 5c 7e 6c 6b bf 3e 50 6f 36 14 72 a3 56 .'S\~lk.>Po6.r.V
65 72 73 69 db ed b9 56 33 9a 38 bf 6f 63 c1 73 ersi...V3.8.oc.s
b7 ef 2f 60 88 31 4e 61 6d 8a 4c 1b 61 6c d7 7d ../`.1Nam.L.al.}
db 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 33 ...............3
f4 62 00 00 00 89 6d 79 20 70 68 6f 74 6f 4c 6f .b....my.photoLo
2014-11-20 18:05:53,723 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x25121C14, Value:
58 00 54 00 52 00 45 00 4d 00 45 00 55 00 50 00 X.T.R.E.M.E.U.P.
44 00 41 00 54 00 45 00 00 00 00 5a 00 25 53 79 D.A.T.E....Z.%Sy
73 74 65 6d 52 6f 6f 74 25 25 5c 73 79 73 74 65 stemRoot%%\syste
6d 33 32 5c 62 74 77 5f 6f 6b 6f 2e 64 6c 6c 00 m32\btw_oko.dll.
00 37 00 37 00 37 00 37 00 00 00 00 08 f9 6f 62 .7.7.7.7......ob
00 00 00 80 ef 2a 6f 64 75 6c 65 3e 00 43 53 47 .....*odule>.CSG
4f 20 69 74 65 6d 20 67 65 6e 65 72 61 74 6f 72 O.item.generator
20 32 30 31 34 2e 65 78 65 00 50 72 6f 67 72 61 .2014.exe.Progra
6d 00 4a 74 53 67 71 63 45 6b 6e 72 65 6d 52 68 m.JtSgqcEknremRh
45 58 63 00 54 67 4f 4b 71 44 66 46 78 53 52 50 EXc.TgOKqDfFxSRP
00 00 00 00 13 f9 6f 62 00 00 00 88 5f 78 5f 58 ......ob...._x_X
5f 50 41 53 53 57 4f 52 44 4c 49 53 54 5f 58 5f _PASSWORDLIST_X_
78 5f 00 72 79 70 74 6f 72 5f 62 79 5f 6d 65 5c x_.ryptor_by_me\
52 65 6c 65 61 73 65 5c 53 74 75 62 2e 70 64 62 Release\Stub.pdb
00 4f 49 50 2e 61 62 63 00 4f 58 00 00 da 04 00 .OIP.abc.OX.....
04 00 00 00 90 ad 00 00 00 25 13 25 26 f9 6f 62 .........%.%&.ob
2014-11-20 18:05:55,160 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x251F7DC2, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 73 69 64 65 6e 74 2e 70 64 62 00 00 58 55 T.sident.pdb..XU
6e 62 00 00 00 80 29 10 72 76 65 72 00 43 6f 6d nb....).rver.Com
70 69 6c 61 74 69 6f 6e 52 65 6c 61 78 61 74 69 pilationRelaxati
6f 6e 73 00 00 00 25 55 6e 62 00 00 00 80 65 10 ons...%Unb....e.
61 64 5f 63 70 6c 2e 63 70 6c 00 43 50 6c 41 70 ad_cpl.cpl.CPlAp
70 6c 65 74 00 2e 65 78 65 00 65 00 44 00 22 55 plet..exe.e.D."U
6e 62 00 00 00 80 51 10 00 20 20 00 00 65 67 6c nb....Q......egl
61 63 2e 65 78 65 00 6e 52 65 6c 61 78 61 74 69 ac.exe.nRelaxati
6f 6e 73 00 00 00 2f 55 6e 62 00 00 00 80 38 10 ons.../Unb....8.
65 72 76 65 72 2e 65 78 65 00 6d 73 63 6f 72 6c erver.exe.mscorl
69 62 00 67 61 6b 70 68 71 00 5c 00 00 00 34 55 ib.gakphq.\...4U
6e 62 00 00 00 80 f7 0f 71 68 6b 2e 64 6c 6c 00 nb......qhk.dll.
48 6f 6f 6b 4b 42 00 00 00 00 00 00 00 00 00 00 HookKB..........
00 00 00 00 00 00 31 55 6e 62 00 00 00 80 10 10 ......1Unb......
65 72 76 65 72 2e 65 78 65 00 6d 73 63 6f 72 6c erver.exe.mscorl
2014-11-20 18:05:55,160 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x251F7F02, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 T..............U
6e 62 00 00 00 80 1a 10 65 72 74 79 00 31 32 33 nb......erty.123
34 35 00 6a 65 73 75 73 00 65 6c 61 78 61 74 69 45.jesus.elaxati
6f 6e 73 00 00 00 0d 55 6e 62 00 00 00 80 67 09 ons....Unb....g.
73 70 2d 61 74 74 30 31 2e 70 6f 70 33 2e 72 75 sp-att01.pop3.ru
2f 6f 72 6b 5f 72 65 74 2e 6a 70 67 00 00 0a 55 /ork_ret.jpg...U
6e 62 00 00 00 80 60 10 69 74 68 68 66 64 64 67 nb....`.ithhfddg
66 64 2e 64 6c 6c 00 61 63 6b 49 00 74 61 6c 6c fd.dll.ackI.tall
2e 65 78 65 00 00 17 55 6e 62 00 00 00 80 3d 10 .exe...Unb....=.
00 6d 73 63 6f 72 6c 69 62 00 4d 69 63 72 6f 73 .mscorlib.Micros
6f 66 74 00 00 70 00 68 00 70 00 3f 00 00 1c 55 oft..p.h.p.?...U
6e 62 00 00 00 80 47 10 53 32 63 73 49 78 4e 52 nb....G.S2csIxNR
4f 55 42 33 70 54 6c 6b 39 00 64 2e 65 78 65 00 OUB3pTlk9.d.exe.
00 00 00 00 00 00 19 55 6e 62 00 00 00 80 d7 1b .......Unb......
75 62 2e 65 78 65 00 53 74 75 62 00 6d 73 63 6f ub.exe.Stub.msco
2014-11-20 18:05:55,160 - detector - WARNING - Process mbamservice.ex (pid: 3124) matched: Xtreme at address: 0x25252CE2, Value:
58 00 74 00 72 00 65 00 6d 00 65 00 52 00 41 00 X.t.r.e.m.e.R.A.
54 00 00 47 35 2e 23 23 40 29 16 60 58 58 58 58 T..G5.##@).`XXXX
e0 61 61 61 9a c6 f7 ff ff ff ff ff ff ff 00 8c .aaa............
76 c5 9c a4 87 53 3e f9 15 31 a4 e9 ea 38 83 92 v....S>..1...8..
26 35 6d 8b ed f7 13 c9 ae f0 53 3c b9 09 3f 3f &5m.......S<..??
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f ????????????????
3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 3f 38 00 00 00 ????????????8...
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 3e ...............>
57 0d fa ae ad 08 98 f8 7b 23 c0 02 18 25 0e 00 W.......{#...%..
2014-11-20 18:57:38,144 - detector - INFO - Scanning finished
2014-11-20 18:57:38,144 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-20 18:57:38,145 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-20 18:57:38,147 - detector - INFO - Service stopped
2014-11-20 18:57:38,147 - detector - INFO - Analysis finished
2014-11-21 10:13:35,200 - detector - INFO - Starting with process ID 8916
2014-11-21 10:13:35,200 - detector - INFO - Selected Profile Name: Win7SP1x64
2014-11-21 10:13:35,200 - detector - INFO - Selected Driver: C:\Users\Lange\AppData\Local\Temp\_MEI93562\drivers\winpmem64.sys
2014-11-21 10:13:35,200 - detector.service - INFO - Launching service destroyer...
2014-11-21 10:13:35,200 - detector.service - DEBUG - Unable to OpenService: (1060, 'OpenService', 'Der angegebene Dienst ist kein installierter Dienst.')
2014-11-21 10:13:35,200 - detector.service - INFO - Trying to stop the winpmem service...
2014-11-21 10:13:35,200 - detector.service - INFO - Trying to delete the winpmem service...
2014-11-21 10:13:35,200 - detector.service - DEBUG - Unable to delete the service: (6, 'DeleteService', 'Das Handle ist ung\xfcltig.')
2014-11-21 10:13:35,246 - detector.service - INFO - Trying to start the winpmem service...
2014-11-21 10:13:35,293 - detector - INFO - Service started
2014-11-21 10:13:35,293 - detector - INFO - Selected Yara signature file at C:\Users\Lange\AppData\Local\Temp\_MEI93562\rules\signatures.yar
2014-11-21 10:13:35,293 - detector - INFO - Obtaining address space and generating config for volatility
2014-11-21 10:13:36,713 - detector - INFO - Address space: <volatility.plugins.addrspaces.amd64.AMD64PagedMemory object at 0x0B9AB610>, Base: <volatility.plugins.addrspaces.win32pmem.Win32FileAddressSpace object at 0x049EFAF0>
2014-11-21 10:13:36,713 - detector - INFO - Profile: <volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0x049EFBF0>, DTB: 0x1a7000
2014-11-21 10:13:36,713 - detector - INFO - Starting yara scanner... MBAM hat keine Einträge in den Scanlogs |