![]() |
|
Plagegeister aller Art und deren Bekämpfung: einige trojaner agenten, viele backdoors und einen spyagentWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() einige trojaner agenten, viele backdoors und einen spyagent Guten Abend Erstmal danke das ihr bereit seit den Leuten bei Ihrem Problemen mit dem PC zu helfen. Ich war heute auf Youtube und da stand ich muss meinen Flashplayer aktualiesieren sonst kann ich das video nicht sehn. Nun das habe ich gemacht. Ein paar minuten danach, schaltet sich der PC von selber aus, fährt wieder hoch,dann erscheint ein ganz schwarzer Bildschirm mit Sicherheitsmodus an der Ecke stehn. Dann blieb das einige Minuten, dann schaltete er sich wieder aus, und fuhr normal hoch. Es funktioniert alles tadellos, ausser das ich nicht auf die ´´Facebook´´ seite zugreifen kann, da kommt andauernd ´´Seiteladefehler`` Irgendwie muss der virus den zugriff blockiert haben. Ich kann auch keine Systemwiederherstellung machn, da kann ich nicht zwischen den Monaten hin und herschalten und dunkle Ziffern stehn da niergens, was mir auch komisch vor kommt. Nun ich habe Malewarbytes durchlaufen lassen hier meine LOGEDATEI : www.malwarebytes.org Datenbank Version: 7622 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 27.10.2011 16:50:58 mbam-log-2011-10-27 (16-50-58).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 215711 Laufzeit: 17 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 11 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 11 Infizierte Registrierungswerte: 18 Infizierte Dateiobjekte der Registrierung: 3 Infizierte Verzeichnisse: 2 Infizierte Dateien: 29 Infizierte Speicherprozesse: c:\WINDOWS\sysdriver32.exe (Trojan.Agent) -> 1504 -> Unloaded process successfully. c:\WINDOWS\systemup.exe (Trojan.Agent.Gen) -> 4072 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 3376 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 248 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 604 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 4024 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 2760 -> Unloaded process successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> 1416 -> Unloaded process successfully. c:\WINDOWS\update.tray-8-0\svchost.exe (Trojan.Agent) -> 1056 -> Unloaded process successfully. c:\WINDOWS\update.tray-9-0\svchost.exe (Trojan.Agent) -> 1064 -> Unloaded process successfully. c:\WINDOWS\update.1\svchost.exe (Trojan.Agent) -> 1424 -> Unloaded process successfully. Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srviecheck (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SRVSYSDRIVER32 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvbtcclient (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\DDSERVICE (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WXPDRIVERS (Trojan.Agent) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32.exe (Trojan.Agent) -> Value: sysdriver32.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\36507.exe (Trojan.Agent) -> Value: 36507.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32_.exe (Trojan.Agent) -> Value: sysdriver32_.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3608935.exe (Trojan.Agent) -> Value: 3608935.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\9525456.exe (Trojan.Agent) -> Value: 9525456.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\949696.exe (Trojan.Agent) -> Value: 949696.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\systemup (Trojan.Agent.Gen) -> Value: systemup -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2730915.exe (Trojan.Agent) -> Value: 2730915.exe -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\A99CA52351694BB7 (Trojan.SpyEyes) -> Value: A99CA52351694BB7 -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\7DDCBCE31E1A8F5E (Trojan.SpyEyes.Gen) -> Value: 7DDCBCE31E1A8F5E -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxpdrv (Backdoor.Agent) -> Value: wxpdrv -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tray_ico0 (Trojan.Agent) -> Value: tray_ico0 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tray_ico1 (Trojan.Agent) -> Value: tray_ico1 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\9134302.exe (Trojan.Downloader.Gen) -> Value: 9134302.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\l1rezerv.exe (Trojan.Agent) -> Value: l1rezerv.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddservice\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpDrivers\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: c:\nmr92.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully. c:\sisale.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully. Infizierte Dateien: c:\WINDOWS\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\dokumente und einstellungen\Tobias\lokale einstellungen\Temp\36507.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\sysdriver32_.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\3608935.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\dokumente und einstellungen\Tobias\lokale einstellungen\Temp\9525456.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\dokumente und einstellungen\Tobias\lokale einstellungen\Temp\949696.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\1846770.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\6286920.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\8530447.exe (Spyware.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\9134302.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.7.1\svchostdriver.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\systemup.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\1053121.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\1623703.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\2730915.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\5422740.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\6900644.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\120793483.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\203654774.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\507379148.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\l1rezerv.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.2\svchost.exe (Backdoor.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.5.0\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\services32.exe (Backdoor.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.tray-8-0\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.tray-9-0\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\update.1\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\nmr92.bin\config.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully. c:\sisale.bin\config.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully. Ich wäre euch sehr dankbar wenn mir irgendjemand sagt was ich jetzt machen soll. Die Viren hab ich schon gelöscht. Mit ganz lieben Grüßen Michaela ![]() ![]() |
Themen zu einige trojaner agenten, viele backdoors und einen spyagent |
backdoor.agent, bereit, bildschirm, blockiert, center, dateien, einstellungen, explorer, funktioniert, malewarbytes, microsoft, probleme, schwarzer bildschirm, security, seite, services, software, spyware.agent, svchost.exe, systemwiederherstellung, temp, trojan.agent, trojan.agent.ge, trojan.downloader.gen, trojan.spyeyes.gen, trojaner, version, video, viren, virus, youtube, zugriff, zugriff blockiert |