Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Trojan.agent

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 28.05.2011, 07:36   #11
chibitwo
 
Trojan.agent - Standard

Trojan.agent



GMEr ist leider zwei Mal abgestürzt.

OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
Online Solutions. Complex Protection for Information Systems
Saved at 08:33:50 on 28.05.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Software Updater.job" - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"nvcpl.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\KATHAR~1\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{16148659-720A-457d-850B-2DBD87BB129D} "AudibleShlExt Class" - "Audible, Inc." - C:\Program Files\Audible\Bin\AudibleExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{16148659-720A-457d-850B-2DBD87BB129D} "AudibleShlExt Class" - "Audible, Inc." - C:\Program Files\Audible\Bin\AudibleExt.dll
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} "ShellViewRTF" - "XSS" - C:\Program Files\Sminst\ShellvRTF.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} "Java Plug-in 1.6.0_07" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\Katharina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\Katharina\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Exif Launcher S.lnk" - "FUJIFILM Corporation" - C:\Programme\FinePixViewerS\QuickDCF2.exe  (Shortcut exists | File exists)
"McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe  (Shortcut exists | File exists)
"Audible Download Manager.lnk" - "Audible, Inc." - C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"HPAdvisor" - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
"LightScribe Control Panel" - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"BrMfcWnd" - "Brother Industries, Ltd." - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"HP Health Check Scheduler" - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
"hpWirelessAssistant" - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
"IndexSearch" - "Nuance Communications, Inc." - "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"NvCplDaemon" - "NVIDIA Corporation" - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
"PaperPort PTD" - "Nuance Communications, Inc." - "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
"PPort11reminder" - "Nuance Communications, Inc." - "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
"QlbCtrl.exe" - " Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
"QPService" - "CyberLink Corp." - "C:\Program Files\HP\QuickPlay\QPService.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SSBkgdUpdate" - "Nuance Communications, Inc." - "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Java\jre6\bin\jusched.exe"
"UCam_Menu" - "CyberLink Corp." - "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
"UpdateLBPShortCut" - "CyberLink Corp." - "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
"UpdateP2GoShortCut" - "CyberLink Corp." - "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
"UpdatePDIRShortCut" - "CyberLink Corp." - "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
"UpdatePSTShortCut" - "CyberLink Corp." - "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Com4QLBEx" (Com4QLBEx) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Easybits Shared Services for Windows" (ezSharedSvc) - "EasyBits Sofware AS" - C:\Windows\System32\ezsvc7.dll
"GameConsoleService" (GameConsoleService) - "WildTangent, Inc." - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate1c9e06e4fafb5a1)" (gupdate1c9e06e4fafb5a1) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP Health Check Service" (HP Health Check Service) - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
"hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Recovery Service for Windows" (Recovery Service for Windows) - ? - C:\Program Files\SMINST\BLService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---
If You have questions or want to get some help, You can visit Online Solutions :: Index



MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Wistron
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: Compaq Presario CQ60 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 199):
0x8263D000 \SystemRoot\system32\ntkrnlpa.exe
0x8260A000 \SystemRoot\system32\hal.dll
0x80408000 \SystemRoot\system32\kdcom.dll
0x8040F000 \SystemRoot\system32\PSHED.dll
0x80420000 \SystemRoot\system32\BOOTVID.dll
0x80428000 \SystemRoot\system32\CLFS.SYS
0x80469000 \SystemRoot\system32\CI.dll
0x80549000 \SystemRoot\system32\drivers\Wdf01000.sys
0x805C5000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80602000 \SystemRoot\system32\drivers\acpi.sys
0x80648000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80651000 \SystemRoot\system32\drivers\msisadrv.sys
0x80659000 \SystemRoot\system32\drivers\pci.sys
0x80680000 \SystemRoot\system32\drivers\isapnp.sys
0x8068F000 \SystemRoot\system32\drivers\mpio.sys
0x806AB000 \SystemRoot\System32\drivers\partmgr.sys
0x806BA000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x806BD000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x806C7000 \SystemRoot\system32\drivers\volmgr.sys
0x806D6000 \SystemRoot\System32\drivers\volmgrx.sys
0x80720000 \SystemRoot\system32\drivers\intelide.sys
0x80727000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x80735000 \SystemRoot\system32\drivers\pciide.sys
0x8073C000 \SystemRoot\system32\drivers\aliide.sys
0x80743000 \SystemRoot\system32\drivers\amdide.sys
0x8074A000 \SystemRoot\system32\drivers\cmdide.sys
0x80752000 \SystemRoot\System32\drivers\mountmgr.sys
0x80762000 \SystemRoot\system32\drivers\msdsm.sys
0x8077C000 \SystemRoot\system32\drivers\nvraid.sys
0x80797000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x807B8000 \SystemRoot\system32\drivers\viaide.sys
0x8A40E000 \SystemRoot\system32\drivers\iastorv.sys
0x8A4AF000 \SystemRoot\system32\drivers\atapi.sys
0x8A4B7000 \SystemRoot\system32\drivers\ataport.SYS
0x8A4D5000 \SystemRoot\system32\drivers\lsi_scsi.sys
0x8A4EF000 \SystemRoot\system32\drivers\storport.sys
0x8A530000 \SystemRoot\system32\drivers\msahci.sys
0x8A53A000 \SystemRoot\system32\drivers\hpcisss.sys
0x8A545000 \SystemRoot\system32\drivers\adp94xx.sys
0x8A5AF000 \SystemRoot\system32\drivers\adpahci.sys
0x807C0000 \SystemRoot\system32\drivers\adpu160m.sys
0x805D2000 \SystemRoot\system32\drivers\SCSIPORT.SYS
0x8A60E000 \SystemRoot\system32\drivers\adpu320.sys
0x8A634000 \SystemRoot\system32\drivers\djsvs.sys
0x8A648000 \SystemRoot\system32\drivers\arc.sys
0x8A65E000 \SystemRoot\system32\drivers\arcsas.sys
0x8A674000 \SystemRoot\system32\drivers\elxstor.sys
0x8A708000 \SystemRoot\system32\drivers\i2omp.sys
0x8A712000 \SystemRoot\system32\drivers\iirsp.sys
0x8A722000 \SystemRoot\system32\drivers\iteatapi.sys
0x8A72E000 \SystemRoot\system32\drivers\iteraid.sys
0x8A73A000 \SystemRoot\system32\drivers\lsi_fc.sys
0x8A754000 \SystemRoot\system32\drivers\lsi_sas.sys
0x8A76C000 \SystemRoot\system32\drivers\megasas.sys
0x8A80C000 \SystemRoot\system32\drivers\megasr.sys
0x8A8C3000 \SystemRoot\system32\drivers\mraid35x.sys
0x8A8CE000 \SystemRoot\system32\drivers\nfrd960.sys
0x8A8DC000 \SystemRoot\system32\drivers\nvstor.sys
0x8AA02000 \SystemRoot\system32\drivers\ql2300.sys
0x8AB3A000 \SystemRoot\system32\drivers\ql40xx.sys
0x8AB8F000 \SystemRoot\system32\drivers\sisraid2.sys
0x8AB9C000 \SystemRoot\system32\drivers\sisraid4.sys
0x8ABB1000 \SystemRoot\system32\drivers\symc8xx.sys
0x8ABBD000 \SystemRoot\system32\drivers\sym_hi.sys
0x8ABC8000 \SystemRoot\system32\drivers\sym_u3.sys
0x8A8E9000 \SystemRoot\system32\drivers\uliahci.sys
0x8ABD3000 \SystemRoot\system32\drivers\ulsata.sys
0x8A925000 \SystemRoot\system32\drivers\ulsata2.sys
0x8A951000 \SystemRoot\system32\drivers\vsmraid.sys
0x8A972000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A9A4000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A776000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8AC0B000 \SystemRoot\system32\drivers\ndis.sys
0x8AD16000 \SystemRoot\system32\drivers\msrpc.sys
0x8AD41000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AE09000 \SystemRoot\System32\drivers\tcpip.sys
0x8AEF3000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B006000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B116000 \SystemRoot\system32\drivers\wd.sys
0x8B11E000 \SystemRoot\system32\drivers\volsnap.sys
0x8B157000 \SystemRoot\System32\Drivers\spldr.sys
0x8B15F000 \SystemRoot\system32\drivers\sbp2port.sys
0x8B174000 \SystemRoot\System32\Drivers\mup.sys
0x8B183000 \SystemRoot\System32\drivers\ecache.sys
0x8B1AA000 \SystemRoot\system32\drivers\disk.sys
0x8B1BB000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B1E4000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8B1EF000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8AF0E000 \SystemRoot\system32\DRIVERS\processr.sys
0x8AF1D000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8AF26000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8B1F8000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x8AF39000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8AF44000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8B1FD000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8AF74000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8B000000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8AF7F000 \SystemRoot\system32\DRIVERS\nvsmu.sys
0x8AF87000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8AF91000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8AFCF000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F007000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F094000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8F0AC000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8F0B2000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8F803000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x9015A000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x9015C000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F1AF000 \SystemRoot\System32\drivers\watchdog.sys
0x8F201000 \SystemRoot\system32\DRIVERS\athr.sys
0x8F2E5000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8F314000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8F31F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8F336000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8F341000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8F364000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8F373000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F387000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8F39C000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8F3AC000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8F3AE000 \SystemRoot\system32\DRIVERS\ks.sys
0x8F3D8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8F3E2000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8F1BB000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8F3EF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8AD7C000 \SystemRoot\system32\drivers\CHDRT32.sys
0x8ADB7000 \SystemRoot\system32\drivers\portcls.sys
0x8A9B4000 \SystemRoot\system32\drivers\drmk.sys
0x90408000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x90446000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x90549000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8F1F0000 \SystemRoot\system32\drivers\modem.sys
0x8AFDE000 \SystemRoot\system32\drivers\nvhda32v.sys
0x8AFEC000 \SystemRoot\system32\drivers\RTSTOR.SYS
0x8ADE4000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x90809000 \SystemRoot\system32\DRIVERS\OA004Vid.sys
0x9084B000 \SystemRoot\system32\DRIVERS\OA004Ufd.sys
0x9086F000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x90879000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x90886000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x9088F000 \SystemRoot\System32\Drivers\Null.SYS
0x90896000 \SystemRoot\System32\Drivers\Beep.SYS
0x908A6000 \SystemRoot\system32\drivers\HIDPARSE.SYS
0x908AD000 \SystemRoot\System32\drivers\vga.sys
0x908B9000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x908DA000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x908E3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x908F3000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x908FB000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90903000 \SystemRoot\system32\drivers\rdpencdd.sys
0x9090B000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90916000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90924000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x9092D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90943000 \SystemRoot\system32\DRIVERS\smb.sys
0x90957000 \SystemRoot\system32\drivers\afd.sys
0x9099F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x909D1000 \SystemRoot\system32\DRIVERS\pacer.sys
0x909E7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8A9D9000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x909F5000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x9240D000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92449000 \SystemRoot\system32\drivers\nsiproxy.sys
0x92453000 \SystemRoot\System32\Drivers\dfsc.sys
0x9246A000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x92490000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x92492000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9249F000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x924AA000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x9B430000 \SystemRoot\System32\win32k.sys
0x924B2000 \SystemRoot\System32\drivers\Dxapi.sys
0x924BC000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9B650000 \SystemRoot\System32\TSDDD.dll
0x9B670000 \SystemRoot\System32\cdd.dll
0x9B680000 \SystemRoot\System32\ATMFD.DLL
0x924CB000 \SystemRoot\system32\drivers\luafv.sys
0x924E6000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x924FB000 \SystemRoot\system32\drivers\spsys.sys
0x925AB000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x925BB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x925E5000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8B1C4000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xA0208000 \SystemRoot\system32\drivers\HTTP.sys
0xA0275000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA0292000 \SystemRoot\system32\DRIVERS\bowser.sys
0xA02AB000 \SystemRoot\System32\drivers\mpsdrv.sys
0xA02C0000 \SystemRoot\system32\drivers\mrxdav.sys
0xA02E1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA0300000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA0339000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xA0351000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA0379000 \SystemRoot\System32\DRIVERS\srv.sys
0xA03E0000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xA260B000 \SystemRoot\system32\drivers\peauth.sys
0xA26E9000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA26F3000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA26FF000 \SystemRoot\system32\DRIVERS\xaudio.sys
0xA2707000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77520000 \Windows\System32\ntdll.dll

Processes (total 82):
0 System Idle Process
4 System

 

Themen zu Trojan.agent
adobe, anti-malware, appdata, avira, datei, dateien, einloggen, explorer, firefox, firewall, frage, gelöscht, internet, malware, microsoft, problem, proxy, proxy server, rechner, scan, server, software, temp, trojan.agent, verbindung




Ähnliche Themen: Trojan.agent


  1. trojan.agent/Gen-frauder und trojan.agent/Gen-Reputation gefunden
    Log-Analyse und Auswertung - 02.11.2013 (10)
  2. WinXp Trojan.Agent/Gen-Reputation Stolen.Data Trojan.Agent/Gen-DunDun Win32/Spy.Banker.YPK trojan
    Log-Analyse und Auswertung - 29.10.2013 (7)
  3. Trojan.Ransom.ED, Trojan.Agent.ED, Trojan.FakeMS.PRGen und Bublik b. durch Email erhalten?
    Plagegeister aller Art und deren Bekämpfung - 02.04.2013 (29)
  4. Bublik b.; Trojan.Ransom.ED; Trojan.Agent.ED und Trojan.FakeMS.PRGen in Email?
    Mülltonne - 28.03.2013 (0)
  5. Vista: Trojan.Ransom.Gen; Trojan.0Access; Trojan.Agent; Firewall inaktiv
    Plagegeister aller Art und deren Bekämpfung - 28.03.2013 (3)
  6. Win.Trojan.Agent-228583, Win.Trojan.Expiro-1161 und Win.Trojan.Agent-232649
    Plagegeister aller Art und deren Bekämpfung - 13.03.2013 (8)
  7. Trojan.Fakesmoke, Trojan.Agent-128337, Trojan.Agent-128287 bei Desinfect 2012 (Clam AV)
    Log-Analyse und Auswertung - 06.02.2013 (17)
  8. Trojaner gefunden: Win 32:Patcher [Trj], Win.Trojan.Agent-36124, Win.Trojan.Agent-44393
    Log-Analyse und Auswertung - 02.02.2013 (7)
  9. TR/ATRAPS.Gen und TR/Kazy durch Antivir gemeldet; ferner Trojan.Agent.MRGGen, Trojan.0Access, Trojan.Dropper.BCMiner
    Plagegeister aller Art und deren Bekämpfung - 03.11.2012 (10)
  10. Trojan.Downloader, Trojan.Agent.VGENX, Trojan.Agent, PUP.Pantsoff.PasswordFinder, TR/spy.banker.gen5
    Log-Analyse und Auswertung - 27.10.2012 (1)
  11. Wohl mehrere Viren: Rootkit.0Access Trojan.Zaccess Trojan.RansomP.Gen Trojan.Agent bzw. TR/ATRAPS.Gen2
    Plagegeister aller Art und deren Bekämpfung - 25.09.2012 (13)
  12. Trojan.Apppatch,Trojan.Agent.BVXGen und Trojan.Midhos in C:\Users\inet-kid\AppData,TR/ATRAPS.Gen2
    Plagegeister aller Art und deren Bekämpfung - 13.09.2012 (35)
  13. Trojan.Agent, Backdoor.Agent, Trojan.Banker > 10 Trojaner auf einem PC
    Log-Analyse und Auswertung - 22.07.2012 (0)
  14. EXP/2008-5353.AO TR/Kazy.80527.3 Trojan.BT.Soft.Gen Trojan.Banker Trojan.Agent
    Plagegeister aller Art und deren Bekämpfung - 14.07.2012 (5)
  15. Trojan.Agent, Trojan.FakeAltert, Trojan.Hiloti.Gen gefunden und gelöscht,aber wirklich weg?
    Log-Analyse und Auswertung - 27.04.2011 (11)
  16. Trojan.BHO, Spyware.Passwords.XGen, Trojan.Dropper und Trojan.Agent mit Malware gefunden
    Plagegeister aller Art und deren Bekämpfung - 20.12.2010 (9)
  17. Diverse Trojaner vom Typ Trojan.Rodecap, Trojan.Dropper und Trojan.Agent! Brauche dringend Hilfe!
    Log-Analyse und Auswertung - 09.08.2010 (16)

Zum Thema Trojan.agent - GMEr ist leider zwei Mal abgestürzt. OSAM Logfile: Code: Alles auswählen Aufklappen ATTFilter Report of OSAM : Autorun Manager v5.0.11926.0 Online Solutions. Complex Protection for Information Systems Saved at 08:33:50 - Trojan.agent...
Archiv
Du betrachtest: Trojan.agent auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.