|
Log-Analyse und Auswertung: unbekannter Virus. Bitte um Hilfe!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.06.2007, 23:43 | #1 |
| unbekannter Virus. Bitte um Hilfe! Hallo, ich habe folgendes Problem. Ich habe heute ein Programm gedownloadet , das sich als ein Addon für den Opera-browser ausgegeben hat. Sofort danach waren auf meinem Desktop Icons mit folgenden Namen "ErrorCleaner" , "PrivacyProtektor" und "Spyware&MalwareProtection". Im Infobereich der Taskleiste is jetzt außerdem ein Symbol mit einen "!" das mir sagt das ein Virus auf meinem Computer ist , allerdings hab ich das noch nie gesehen. Ich habe auch schon versucht mit NOD32 , ZoneAlarm und AntiVir PE Classic nach Viren zu suchen. AntiVir PE Classic hat auch was gefunden und ich habe es unter Karanthene stellen lassen , das hat aber nichts gebracht. REgelmäßig meldet Windows "Trojan Adware. W32.ExpDwnldr spyware detected." und bietet mir an eine mögliche Antispyware zu downloaden. Es werden jetzt auch dauernt Browserfenter geöffnet und es WAR mein Taksmanager blockiert. Mein Betriebssystem ist Windows XP Homeedition mit SP2 Ich habe jetzt eine Logfile mit HijackThis angefertigt. Logfile of HijackThis v1.99.1 Scan saved at 00:08:27, on 25.06.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\Programme\AntiVir PersonalEdition Classic\sched.exe C:\Programme\FRITZ!DSL\IGDCTRL.EXE C:\Programme\IVT Corporation\BlueSoleil\BTNtService.exe C:\Programme\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Programme\Eset\nod32kui.exe C:\Programme\QuickTime\qttask.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\Java\jre1.6.0_01\bin\jusched.exe C:\Programme\Opera\Opera.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\vsnp2std.exe C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\MSN Messenger\msnmsgr.exe C:\Programme\IVT Corporation\BlueSoleil\BlueSoleil.exe C:\Programme\Hama\Common\RaUI.exe C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe C:\Programme\iPod\bin\iPodService.exe C:\Dokumente und Einstellungen\pivke_2\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gomyron.com/NjU2NA==/2/3560/homepage/ R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programme\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSVPS System - {A1770FD6-A7CB-44DA-AD2C-692D2A2B521B} - C:\WINDOWS\vpsnetwork.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programme\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll O4 - HKLM\..\Run: [nod32kui] "C:\Programme\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [msnmsgr] "C:\Programme\MSN Messenger\msnmsgr.exe" /background O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BlueSoleil.lnk = C:\Programme\IVT Corporation\BlueSoleil\BlueSoleil.exe O4 - Global Startup: Hama Wireless LAN Utility.lnk = C:\Programme\Hama\Common\RaUI.exe O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Programme\RALINK\Common\RaUI.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing) O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O21 - SSODL: vpssup - {6EF6C931-5DA4-4E8A-94E7-F05AACC5235B} - C:\WINDOWS\vpssup.dll O21 - SSODL: expro - {B3FCE834-0A42-45E8-AF44-E94A678BA887} - C:\WINDOWS\expro.dll O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVM IGD CTRL Service - AVM Berlin - C:\Programme\FRITZ!DSL\IGDCTRL.EXE O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programme\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programme\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Ich hoffe ihr könnt mir helfen. |
25.06.2007, 07:28 | #2 |
/// AVZ-Toolkit Guru | unbekannter Virus. Bitte um Hilfe! Halli hallo.
__________________Du solltest keine 2 AV-Scanner auf deinem Rechner am Laufen haben! Die blockieren sich gegenseitig! Lösche bitte einen von beiden. Dann folge bitte dieser Anleitung: AntiRootkit Scanner Anleitung (führe die ersten vier Scanner aus und poste die logFiles) Gruß Undoreal
__________________ |
25.06.2007, 11:27 | #3 |
| unbekannter Virus. Bitte um Hilfe! OK ich habe jetzt alles so gemacht wie es da steht.
__________________Jedes Mal wenn ich die LogFile von RootKitRevealer speichern möchte kommt das ein Problem festgestellt wurde und das Programm jetzt geendet werden muss , die LogFile wird dabei nicht gespeichert. Blacklight konnte ich nicht downloaden , da der 2. Link nicht funktioniert und beim ersten Link keine Datei zu downloaden ist die "blbeta.exe" heißt. Nun zu den LogFiles GMER 1.0.12.12244 - http://www.gmer.net Rootkit scan 2007-06-25 11:48:45 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.12 ---- SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwClose SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwCreateProcess SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwCreateProcessEx SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwCreateSection SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwCreateSymbolicLinkObject SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwCreateThread SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwDuplicateObject SSDT sptd.sys ZwEnumerateKey SSDT sptd.sys ZwEnumerateValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey SSDT \SystemRoot\System32\vsdatant.sys ZwMapViewOfSection SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile SSDT sptd.sys ZwOpenKey SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwOpenProcess SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwOpenSection SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread SSDT sptd.sys ZwQueryKey SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwQuerySystemInformation SSDT sptd.sys ZwQueryValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwResumeThread SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwSetContextThread SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwSetInformationFile SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwSetInformationProcess SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwSetSecurityObject SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwSuspendThread SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwTerminateProcess SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ZwWriteVirtualMemory |
25.06.2007, 11:29 | #4 |
| unbekannter Virus. Bitte um Hilfe! SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[284] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[285] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[286] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[287] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[288] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[289] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[290] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[291] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[292] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[293] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[294] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[295] SSDT \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS SSDT[296] Code \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS FsRtlCheckLockForReadAccess Code \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS IoIsOperationSynchronous ---- Kernel code sections - GMER 1.0.12 ---- .text ntoskrnl.exe!KiDispatchInterrupt + 100 804DC962 7 Bytes JMP B9A25CD0 \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS .text ntoskrnl.exe!IoIsOperationSynchronous 804EAF7E 5 Bytes JMP B9A22C50 \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS .text ntoskrnl.exe!FsRtlCheckLockForReadAccess 804F3BF9 5 Bytes JMP B9A22760 \??\C:\WINDOWS\system32\ZoneLabs\avsys\KLIF.SYS ? C:\WINDOWS\system32\drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. ? srescan.sys Das System kann die angegebene Datei nicht finden. .text USBPORT.SYS!DllUnload F6BCD62C 5 Bytes JMP 865A23F0 ? System32\Drivers\awq34dgo.SYS Das System kann die angegebene Datei nicht finden. ? C:\WINDOWS\system32\DRIVERS\update.sys ? C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS Das System kann die angegebene Datei nicht finden. ? C:\WINDOWS\system32\313.tmp Das System kann die angegebene Datei nicht finden. ---- User code sections - GMER 1.0.12 ---- .text C:\Programme\MSN Messenger\msnmsgr.exe[2452] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Programme\MSN Messenger\msnmsgr.exe ---- Devices - GMER 1.0.12 ---- Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 8675E1E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 8675E1E8 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL |
25.06.2007, 11:31 | #5 |
| unbekannter Virus. Bitte um Hilfe! [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F43D58A0] vsdatant.sys Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 865A15D0 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 8656D1E8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F43D58A0] vsdatant.sys Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ |
25.06.2007, 11:32 | #6 |
| unbekannter Virus. Bitte um Hilfe! 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 867D31E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 865B4790 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 865B4790 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER |
25.06.2007, 11:34 | #7 |
| unbekannter Virus. Bitte um Hilfe! 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_PNP 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_CREATE 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_CLOSE 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_INTERNAL_DEVICE_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_POWER 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_SYSTEM_CONTROL 8675F1E8 Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 IRP_MJ_PNP 8675F1E8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 86014500 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 86014500 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 86014500 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 86014500 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 86014500 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP |
25.06.2007, 11:35 | #8 |
| unbekannter Virus. Bitte um Hilfe! 86014500 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 86014500 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F43D58A0] vsdatant.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_CREATE [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_CREATE_NAMED_PIPE [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_CLOSE [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_READ [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_WRITE [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_QUERY_INFORMATION [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SET_INFORMATION [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_QUERY_EA [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SET_EA [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_FLUSH_BUFFERS [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_QUERY_VOLUME_INFORMATION [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SET_VOLUME_INFORMATION [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_DIRECTORY_CONTROL [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_FILE_SYSTEM_CONTROL [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_DEVICE_CONTROL [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_INTERNAL_DEVICE_CONTROL [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SHUTDOWN [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_LOCK_CONTROL [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_CLEANUP [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_CREATE_MAILSLOT [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_QUERY_SECURITY [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SET_SECURITY [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_POWER [F7768E7A] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SYSTEM_CONTROL [F778C2C8] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_DEVICE_CHANGE [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_QUERY_QUOTA [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_SET_QUOTA [F778FB0E] sptd.sys Device \Driver\PCI_NTPNP1650 \Device\0000005e IRP_MJ_PNP [F778D238] sptd.sys Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 865A15D0 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE |
25.06.2007, 11:39 | #9 |
| unbekannter Virus. Bitte um Hilfe! 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 85E881E8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F43D58A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F43D58A0] vsdatant.sys Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 865A15D0 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY |
25.06.2007, 11:42 | #10 |
| unbekannter Virus. Bitte um Hilfe! 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 85E881E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 85E881E8 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 865A15D0 Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 865A15D0 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 8656D1E8 Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP 8656D1E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 867D31E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 867D31E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_CREATE 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_CLOSE 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_POWER 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1Port6Path0Target0Lun0 IRP_MJ_PNP 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_CREATE 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_CLOSE 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_DEVICE_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_POWER 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_SYSTEM_CONTROL 8653F1E8 Device \Driver\awq34dgo \Device\Scsi\awq34dgo1 IRP_MJ_PNP 8653F1E8 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 86057790 Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 86057790 |
25.06.2007, 11:44 | #11 |
| unbekannter Virus. Bitte um Hilfe! ---- Registry - GMER 1.0.12 ---- Reg \Registry\USER\S-1-5-21-448539723-616249376-682003330-1008\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0x1A 0x57 0x06 0x3B ... Reg \Registry\USER\S-1-5-21-448539723-616249376-682003330-1008\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0xCF 0x05 0x77 0xD1 ... ---- Files - GMER 1.0.12 ---- ADS C:\Dokumente und Einstellungen\pivke_2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\der_pivke@hotmail.de\SharingMetadata\robbykey@hotmail.de\DFSR\Staging\CS{9438BD5E-748A-526F-698D-2D0B7D0C1D87}\01\10-{9438BD5E-748A-526F-698D-2D0B7D0C1D87}-v1-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Dokumente und Einstellungen\pivke_2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\der_pivke@hotmail.de\SharingMetadata\robbykey@hotmail.de\DFSR\Staging\CS{9438BD5E-748A-526F-698D-2D0B7D0C1D87}\11\11-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v11-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Dokumente und Einstellungen\pivke_2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\der_pivke@hotmail.de\SharingMetadata\robbykey@hotmail.de\DFSR\Staging\CS{9438BD5E-748A-526F-698D-2D0B7D0C1D87}\13\13-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v13-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Dokumente und Einstellungen\pivke_2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\der_pivke@hotmail.de\SharingMetadata\robbykey@hotmail.de\DFSR\Staging\CS{9438BD5E-748A-526F-698D-2D0B7D0C1D87}\13\13-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v13-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Dokumente und Einstellungen\pivke_2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\der_pivke@hotmail.de\SharingMetadata\robbykey@hotmail.de\DFSR\Staging\CS{9438BD5E-748A-526F-698D-2D0B7D0C1D87}\15\15-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v15-{EF357B45-C6AB-421F-82A6-83BF8A9F6207}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ---- EOF - GMER 1.0.12 ---- und die von Sophos Sophos Anti-Rootkit Version 1.3 (data 1.06) (c) 2006 Sophos Plc Started logging on 25.06.2007 at 11:13:28 Stopped logging on 25.06.2007 at 11:16:00 |
25.06.2007, 12:11 | #12 |
/// AVZ-Toolkit Guru | unbekannter Virus. Bitte um Hilfe! Das sieht ja schonmal granicht so schlecht aus. Wenn die logs so lang sind kannst du sie gerne anhängen.. Blacklight auch noch, dann machen wir weiter.. Gruß Undoreal
__________________ - Sämtliche Hilfestellungen im Forum werden ohne Gewährleistung oder Haftung gegeben - |
25.06.2007, 12:56 | #13 |
| unbekannter Virus. Bitte um Hilfe! OK ich habe jetzt BlackLight gedownloadet und das System gecheckt. Hier die LogFile: 06/25/07 13:44:27 [Info]: BlackLight Engine 1.0.64 initialized 06/25/07 13:44:27 [Info]: OS: 5.1 build 2600 (Service Pack 2) 06/25/07 13:44:27 [Note]: 7019 4 06/25/07 13:44:27 [Note]: 7005 0 06/25/07 13:44:33 [Note]: 7006 0 06/25/07 13:44:33 [Note]: 7011 1748 06/25/07 13:44:33 [Note]: 7026 0 06/25/07 13:44:34 [Note]: 7026 0 06/25/07 13:44:35 [Note]: FSRAW library version 1.7.1022 06/25/07 13:48:56 [Note]: 7007 0 |
25.06.2007, 14:10 | #15 |
| unbekannter Virus. Bitte um Hilfe! Ok dann mach ich das mal... |
Themen zu unbekannter Virus. Bitte um Hilfe! |
antivir, avira, bho, bitte um hilfe, computer, desktop, dsl, einstellungen, helfen, hijack, hijackthis, internet, internet explorer, logfile, monitor, object, programm, rundll, shortcut, software, spyware, trojan, urlsearchhook, viren, virus, vista, windows, windows xp, wireless lan |