Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Eigenartiger Prozess im Taskmanager (https://www.trojaner-board.de/31676-eigenartiger-prozess-taskmanager.html)

Sin10 25.08.2006 14:55

Eigenartiger Prozess im Taskmanager
 
Liste der Anhänge anzeigen (Anzahl: 1)
moin all

bin letzens drauf gekommen das sich ein komischer task namens "system" im taskmanager rennen habe....

habe schon gesucht über google oder der gleichen, habe aber leider nichts was passt dazu gefunden...

habe nen screen gemacht, damit ihr seht wie dies aussieht,
was ich noch drauf gekommen bin ist, das das file mit keiner .exe oder sonstigen endung drin steht..

PS: ad-aware & bitdefender sagen nichts das dies ein virus, oder sonstiges ist

vielen dank fü die hilfe mal

MightyMarc 25.08.2006 15:03

Hi Sin10,

bitte mache mal folgendes:

1. Start > Ausführen > cmd

2. in der DOS-BOX nun folgendes:

tasklist /M > C:\task.txt

3. Inhalt der Datei C:\task.txt hier posten.

Gruß

Marc

Sin10 25.08.2006 15:19

Abbildname PID Module
========================= ===== =============================================
System Idle Process 0 Nicht verfgbar

System 4 Nicht verfgbar

smss.exe 700 ntdll.dll

csrss.exe 772 ntdll.dll, CSRSRV.dll, basesrv.dll,
winsrv.dll, USER32.dll, KERNEL32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll,
sxs.dll, WINSTA.dll

winlogon.exe 808 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, GDI32.dll,
USER32.dll, USERENV.dll, NDdeApi.dll,
CRYPT32.dll, MSASN1.dll, Secur32.dll,
WINSTA.dll, PROFMAP.dll, NETAPI32.dll,
REGAPI.dll, WS2_32.dll, WS2HELP.dll,
AUTHZ.dll, PSAPI.DLL, VERSION.dll,
SETUPAPI.dll, MSGINA.dll, SHELL32.dll,
SHLWAPI.dll, COMCTL32.dll, ODBC32.dll,
comdlg32.dll, comctl32.dll, odbcint.dll,
SHSVCS.dll, sfc.dll, sfc_os.dll,
WINTRUST.dll, ole32.dll, IMAGEHLP.dll,
Apphelp.dll, WINSCARD.DLL, WTSAPI32.dll,
sxs.dll, oleaut32.dll, uxtheme.dll,
WINMM.dll, Ati2evxx.dll, cscdll.dll,
WlNotify.dll, WINSPOOL.DRV, MPR.dll,
rsaenh.dll, SAMLIB.dll, msv1_0.dll,
wldap32.dll, cscui.dll, wdmaud.drv,
drprov.dll, ntlanman.dll, NETUI0.dll,
NETUI1.dll, NETRAP.dll, davclnt.dll,
MPRUI.dll, NETUI2.dll, netmsg.dll,
msacm32.drv, MSACM32.dll, midimap.dll,
COMRes.dll, CLBCATQ.DLL, NTMARTA.DLL,
wbemprox.dll, wbemcomn.dll, wbemsvc.dll,
fastprox.dll

services.exe 856 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, USER32.dll,
GDI32.dll, USERENV.dll, SCESRV.dll,
AUTHZ.dll, umpnpmgr.dll, WINSTA.dll,
NCObjAPI.DLL, secur32.dll, eventlog.dll,
WS2_32.dll, WS2HELP.dll, PSAPI.DLL,
Apphelp.dll, wtsapi32.dll, netapi32.dll

lsass.exe 868 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, LSASRV.dll, msvcrt.dll,
Secur32.dll, USER32.dll, GDI32.dll,
SAMSRV.dll, cryptdll.dll, DNSAPI.dll,
WS2_32.dll, WS2HELP.dll, MSASN1.dll,
NETAPI32.dll, SAMLIB.dll, MPR.dll,
NTDSAPI.dll, WLDAP32.dll, msprivs.dll,
kerberos.dll, msv1_0.dll, netlogon.dll,
w32time.dll, MSVCP60.dll, iphlpapi.dll,
USERENV.dll, schannel.dll, CRYPT32.dll,
wdigest.dll, rsaenh.dll, setupapi.dll,
scecli.dll, OLEAUT32.dll, OLE32.DLL,
shell32.dll, SHLWAPI.dll, comctl32.dll,
comctl32.dll, ipsecsvc.dll, oakley.DLL,
WINIPSEC.DLL, mswsock.dll, wshtcpip.dll,
pstorsvc.dll, psbase.dll, dssenh.dll,
VERSION.dll

ati2evxx.exe 1020 ntdll.dll, kernel32.dll, USER32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll,
ole32.dll, OLEAUT32.dll, MSVCRT.DLL,
Secur32.dll, Ati2edxx.dll, uxtheme.dll

svchost.exe 1052 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, rpcss.dll, msvcrt.dll,
WS2_32.dll, WS2HELP.dll, USER32.dll,
GDI32.dll, Secur32.dll, userenv.dll,
mswsock.dll, wshtcpip.dll, DNSAPI.dll,
iphlpapi.dll, winrnr.dll, WLDAP32.dll,
rasadhlp.dll, oleaut32.dll, OLE32.DLL,
CLBCATQ.DLL, COMRes.dll, VERSION.dll,
msi.dll, Apphelp.dll

svchost.exe 1284 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, user32.dll, GDI32.dll,
oleaut32.dll, MSVCRT.DLL, OLE32.DLL,
shsvcs.dll, SHLWAPI.dll, shell32.dll,
comctl32.dll, comctl32.dll, WINSTA.dll,
dhcpcsvc.dll, DNSAPI.dll, WS2_32.dll,
WS2HELP.dll, iphlpapi.dll, Secur32.dll,
UxTheme.dll, rsaenh.dll, wzcsvc.dll,
rtutils.dll, WMI.dll, CRYPT32.dll,
MSASN1.dll, WTSAPI32.dll, ESENT.dll,
WLDAP32.dll, NETAPI32.dll, rastls.dll,
ATL.DLL, CRYPTUI.dll, WINTRUST.dll,
IMAGEHLP.dll, WININET.dll, MPRAPI.dll,
ACTIVEDS.dll, adsldpc.dll, SAMLIB.dll,
SETUPAPI.dll, RASAPI32.dll, rasman.dll,
TAPI32.dll, WINMM.dll, SCHANNEL.dll,
USERENV.dll, WinSCard.dll, raschap.dll,
msv1_0.dll, CLBCATQ.DLL, COMRes.dll,
VERSION.dll, schedsvc.dll, NTDSAPI.dll,
mswsock.dll, wshtcpip.dll, MSIDLE.DLL,
NTMARTA.DLL, audiosrv.dll, wkssvc.dll,
cryptsvc.dll, certcli.dll, dmserver.dll,
es.dll, pchsvc.dll, hidserv.dll, HID.DLL,
srvsvc.dll, trkwks.dll, srsvc.dll,
POWRPROF.dll, sens.dll, seclogon.dll,
winspool.drv, wmisvc.dll, wbemcomn.dll,
VSSAPI.DLL, SXS.DLL, comsvcs.dll,
MTXCLU.DLL, WSOCK32.dll, colbact.DLL,
CLUSAPI.DLL, RESUTILS.DLL, browser.dll,
mtxoci.dll, wbemcore.dll, esscli.dll,
FastProx.dll, wmiutils.dll, repdrvfs.dll,
wmiprvsd.dll, NCObjAPI.DLL, wbemess.dll,
termsrv.dll, ICAAPI.dll, AUTHZ.dll,
mstlsapi.dll, REGAPI.dll, netman.dll,
NETSHELL.dll, credui.dll, upnp.dll,
SSDPAPI.dll, hnetcfg.dll, msi.dll,
rasadhlp.dll, RASDLG.dll, msxml3.dll,
sensapi.dll, ncprov.dll, wbemsvc.dll,
Apphelp.dll, catsrvut.dll, MfcSubs.dll,
MPR.dll, Cabinet.dll, urlmon.dll,
catsrv.dll, appmgmts.dll, netcfgx.dll

svchost.exe 1592 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, user32.dll, GDI32.dll,
MSVCRT.DLL, dnsrslvr.dll, DNSAPI.dll,
WS2_32.dll, WS2HELP.dll, iphlpapi.dll,
mswsock.dll, wshtcpip.dll

svchost.exe 1616 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, user32.dll, GDI32.dll,
oleaut32.dll, MSVCRT.DLL, OLE32.DLL,
lmhsvc.dll, iphlpapi.dll, WS2_32.dll,
WS2HELP.dll, webclnt.dll, WININET.dll,
SHLWAPI.dll, CRYPT32.dll, MSASN1.dll,
comctl32.dll, shell32.dll, comctl32.dll,
Secur32.dll, wsock32.dll, regsvc.dll,
mswsock.dll, DNSAPI.dll, rasadhlp.dll,
ssdpsrv.dll, wshtcpip.dll, uxtheme.dll

spoolsv.exe 1776 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, GDI32.dll,
USER32.dll, oleaut32.dll, OLE32.DLL,
SPOOLSS.DLL, WS2_32.dll, WS2HELP.dll,
DNSAPI.dll, rasadhlp.dll, localspl.dll,
VERSION.dll, Secur32.dll, sfc_os.dll,
WINTRUST.dll, CRYPT32.dll, MSASN1.dll,
IMAGEHLP.dll, USERENV.dll, winspool.drv,
netapi32.dll, cnbjmon.dll, mdimon.dll,
msi.dll, pjlmon.dll, tcpmon.dll, usbmon.dll,
mdippr.dll, mswsock.dll, winrnr.dll,
WLDAP32.dll, win32spl.dll, NETRAP.dll,
CLBCATQ.DLL, COMRes.dll, inetpp.dll,
icmp.dll, iphlpapi.DLL, SHLWAPI.dll,
comctl32.dll, comctl32.dll

spd.exe 1876 ntdll.dll, kernel32.dll, iphlpapi.dll,
msvcrt.dll, ADVAPI32.dll, RPCRT4.dll,
USER32.dll, GDI32.dll, WS2_32.dll,
WS2HELP.dll, ole32.dll, oleaut32.dll,
uxtheme.dll, CLBCATQ.DLL, COMRes.dll,
VERSION.dll, SETUPAPI.dll, MPRAPI.dll,
ACTIVEDS.dll, adsldpc.dll, NETAPI32.dll,
WLDAP32.dll, ATL.DLL, rtutils.dll,
SAMLIB.dll, mswsock.dll, wshtcpip.dll

GEARSEC.EXE 1948 ntdll.dll, kernel32.dll, USER32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll

mdm.exe 1996 ntdll.dll, kernel32.dll, ole32.dll,
GDI32.dll, USER32.dll, ADVAPI32.dll,
RPCRT4.dll, OLEAUT32.dll, MSVCRT.DLL,
VERSION.dll, SHLWAPI.dll, psapi.dll,
CLBCATQ.DLL, COMRes.dll, csm.dll,
MSVCR71.dll, msdbg2.dll

oodag.exe 260 ntdll.dll, kernel32.dll, WS2_32.dll,
msvcrt.dll, WS2HELP.dll, ADVAPI32.dll,
RPCRT4.dll, VERSION.dll, NETAPI32.dll,
USER32.dll, GDI32.dll, SHELL32.dll,
SHLWAPI.dll, ole32.dll, comctl32.dll,
comctl32.dll, OODAGRS.DLL, uxtheme.dll,
mswsock.dll, wshtcpip.dll, DNSAPI.dll,
winrnr.dll, WLDAP32.dll, rasadhlp.dll

StarWindService.exe 328 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, WS2_32.dll, msvcrt.dll,
WS2HELP.dll, USER32.dll, GDI32.dll,
mswsock.dll, DNSAPI.dll, winrnr.dll,
WLDAP32.dll, rasadhlp.dll, wshtcpip.dll

wdfmgr.exe 388 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, USER32.dll,
GDI32.dll, SETUPAPI.dll, Secur32.dll

vmware-authd.exe 548 ntdll.dll, kernel32.dll, MSVCR71.dll,
NETAPI32.dll, msvcrt.dll, ADVAPI32.dll,
RPCRT4.dll, WS2_32.dll, WS2HELP.dll,
USER32.dll, GDI32.dll, SETUPAPI.dll,
MPR.dll, userenv.dll, shfolder.dll,
SHLWAPI.dll, comctl32.dll, comctl32.dll,
SAMLIB.dll, rsaenh.dll, SHELL32.dll,
Secur32.dll, perfos.dll, perfproc.dll

vmount2.exe 568 ntdll.dll, kernel32.dll, MSVCR71.dll,
SETUPAPI.dll, msvcrt.dll, ADVAPI32.dll,
RPCRT4.dll, GDI32.dll, USER32.dll,
WS2_32.dll, WS2HELP.dll, vmxScsiLib.dll,
WINMM.dll, ole32.dll, SHELL32.dll,
SHLWAPI.dll, OLEAUT32.dll, MSVCP71.dll,
comctl32.dll, comctl32.dll, uxtheme.dll,
CLBCATQ.DLL, COMRes.dll, VERSION.dll,
msi.dll, shfolder.dll

vmnat.exe 616 ntdll.dll, kernel32.dll, USER32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll,
WS2_32.dll, msvcrt.dll, WS2HELP.dll,
mswsock.dll, wshtcpip.dll, iphlpapi.dll

winvnc4.exe 676 ntdll.dll, kernel32.dll, USER32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll,
SHELL32.dll, msvcrt.dll, SHLWAPI.dll,
WS2_32.dll, WS2HELP.dll, VERSION.dll,
ole32.dll, comctl32.dll, oleaut32.dll,
wtsapi32.dll, WINSTA.dll, security.dll,
SECUR32.dll, aclui.dll, mswsock.dll,
wshtcpip.dll, uxtheme.dll, DNSAPI.dll,
winrnr.dll, WLDAP32.dll, rasadhlp.dll,
Apphelp.dll, rsaenh.dll

xcommsvr.exe 716 ntdll.dll, kernel32.dll, VERSION.dll,
USER32.dll, GDI32.dll, ADVAPI32.dll,
RPCRT4.dll

vmnetdhcp.exe 736 ntdll.dll, kernel32.dll, MSVCR71.dll,
USER32.dll, GDI32.dll, ADVAPI32.dll,
RPCRT4.dll, WS2_32.dll, msvcrt.dll,
WS2HELP.dll

ati2evxx.exe 1476 ntdll.dll, kernel32.dll, USER32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll,
ole32.dll, OLEAUT32.dll, MSVCRT.DLL,
sockspy.dll, Secur32.dll, uxtheme.dll,
Ati2edxx.dll, CLBCATQ.DLL, COMRes.dll,
VERSION.dll

edit:// alles passt da nicht rein, müsste 3 posts machen das ich alle unter bekomme...

MightyMarc 25.08.2006 15:38

Imho alles ok. System PID 4 ist ein Windowssystemprozess. AFAIK handelt der Prozess zwischen Gerätetreibern und Kernel.

Sin10 25.08.2006 15:48

Zitat:

Zitat von MightyMarc
Imho alles ok. System PID 4 ist ein Windowssystemprozess. AFAIK handelt der Prozess zwischen Gerätetreibern und Kernel.


danke für deine hilfe, hatte schon angst das es irgendein trojaner oder sonstiges ist...

bernd456 31.08.2006 15:23

Hallo Marc
ich erhalte im DOS-Fenster folgende Fehlermeldung

[edit]
bitte eröffne, wie jeder andere hier auch, für dein problem einen eigenen beitrag
nur so wird sichergestellt, das jedem user übersichtlich und individuell geholfen werden kann

danke
GUA
[/edit]

Plazer 15.01.2007 21:16

Hallo
Habe das selbe auf mein pc hier ist meine Task.txt :

[edit]
bitte eröffne, wie jeder andere hier auch, für dein problem einen eigenen beitrag
nur so wird sichergestellt, das jedem user übersichtlich und individuell geholfen werden kann

danke
GUA
[/edit]

MightyMarc 16.01.2007 01:20

Zitat:

Zitat von Plazer (Beitrag 249176)
Habe das selbe auf mein pc...

Wäre auch schlimm, wenn Du diesen Prozess nicht laufen hättest.

Zitat:

hoffe jemand kann mir helfen
Hast Du ein konkretes Problem oder einen Verdacht?


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:41 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129