Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner im system32 (https://www.trojaner-board.de/85048-trojaner-system32.html)

Cyndy 18.04.2010 19:43

So da bin ich wieder.

Die Fenster öffnen sich nichtmehr.

Das Logfile von Gmer:

PHP-Code:

GMER 1.0.15.15281 hxxp://www.gmer.net
Rootkit scan 2010-04-18 20:41:15
Windows 6.1.7600 
Running
5fn885gb.exeDriverC:\Users\Tommy\AppData\Local\Temp\fwlcipod.sys


---- System GMER 1.0.15 ----

INT 0x1F        \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3EAF8
INT 0x37        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3E104
INT 0xC1        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3E3F4
INT 0xD1        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C26FB4
INT 0xDF        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3E1DC
INT 0xE1        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3E958
INT 0xE3        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3E6F8
INT 0xFD        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3EF2C
INT 0xFE        
\SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)                                                         82C3F1A8

Code            
\SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)                                                            ZwCreateProcessEx [0x8CAD950A]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)                                                            ZwCreateSection [0x8CAD932E]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)                                                            ZwLoadDriver [0x8CAD9468]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)                                                            NtCreateSection
Code            
\SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)                                                            ObMakeTemporaryObject

---- Kernel code sections GMER 1.0.15 ----

.
text           ntkrnlpa.exe!ZwSaveKeyEx 13AD                                                                                                                  82857579 1 Byte  [06]
.
text           ntkrnlpa.exe!KiDispatchInterrupt 5A2                                                                                                           8287BF52 19 Bytes  [E00FBAF0077309, ...] {LOOPNZ 0x11MOV EDX0x97307f0MOV CR4EAX; OR AL0x80MOV CR4EAXRET MOV ECXCR3}
PAGE            ntkrnlpa.exe!ZwLoadDriver                                                                                                                        829B5279 7 Bytes  JMP 8CAD946C \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObMakeTemporaryObject                                                                                                               82A1CF59 5 Bytes  JMP 8CAD54AA \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObInsertObject 27                                                                                                                 82A36C5F 5 Bytes  JMP 8CAD69E4 \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!NtCreateSection                                                                                                                     82A44CE3 7 Bytes  JMP 8CAD9332 \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                                                                   82AEEE52 7 Bytes  JMP 8CAD950E \SystemRoot\System32\Drivers\aswSP.SYS (avastself protection module/ALWIL Software)
?               
System32\drivers\stsa.sys                                                                                                                        Das System kann den angegebenen Pfad nicht finden. !
.
text           peauth.sys                                                                                                                                       9BC6CC9D 28 Bytes  [4F21205EB77B18, ...]
.
text           peauth.sys                                                                                                                                       9BC6CCC1 28 Bytes  [4F21205EB77B18, ...]

---- 
User code sections GMER 1.0.15 ----

.
text           C:\Program Files\Mozilla Firefox\firefox.exe[3900ntdll.dll!LdrLoadDll                                                                          771AF585 5 Bytes  JMP 000E13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- 
User IAT/EAT GMER 1.0.15 ----

IAT             C:\Windows\System32\rundll32.exe[1948] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                                            [751F5D3DC:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Windows\System32\rundll32.exe[1948] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                                             [751F5D3DC:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Windows\System32\rundll32.exe[1948] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                                           [751F5D3DC:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Windows\System32\rundll32.exe[1948] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]                                          [751F5D3DC:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Windows\System32\rundll32.exe[1948] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]                                           [751F5D3DC:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)

---- 
Devices GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                           SiWinAcc.sys (Windows Accelerator Driver/Silicon ImageInc.)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                          aswTdi.SYS (avastTDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                                           fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                                           rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                                           fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                                           rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                                           fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                                           rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000004e                                                                                                                halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                          aswTdi.SYS (avastTDI Filter Driver/ALWIL Software)
AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                         fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- 
Registry GMER 1.0.15 ----

Reg             HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\Tommy\setup\xb4s\photomail_install.exe     1
Reg             HKCU
\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\Tommy\setup\xb4s\3d_magic_install.exe      1
Reg             HKCU
\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\Tommy\setup\xb4s\PowerPointViewer.exe      1
Reg             HKCU
\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\Tommy\setup\xb4s\install_flash_player.exe  1

---- EOF GMER 1.0.15 ---- 


StLB 18.04.2010 20:12

Jepp, Log sieht ok aus.
Noch irgendwelche Symptome zu sehen?

Mache bitte abschließend noch einen Kontrollscan mit SUPERAntiSpyware und poste dann das Log hier.

StLB 19.04.2010 12:24

Grr...

Zitat:

D:TommyProgisProgrammeWinRARkeygen.exe (Trojan.Agent) -> No action taken.
Und sowas sticht einem erst am Ende der Bereinigung ins Auge :headbang:


Der Besitz von legaler Software ist Voraussetzung für einen Support hier im TrojanerBoard.

Cracks, Serials und Keygens sind illegal! Derlei Aktivitäten werden von uns nicht unterstützt.
Für Dich geht es hier weiter: Neuaufsetzen des Systems

Danach nie wieder illegale Software nutzen!


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:50 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131