![]() |
|
Plagegeister aller Art und deren Bekämpfung: 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo, seit einer halben Stunde meldet mir der Antivir Guard kontinuierlich folgenden Malware-Fund: In der Datei 'C:\Windows\System32\hjgruixpeuxtce.dll' wurde ein Virus oder unerwünschtes Programm 'TR/Redol.B' [trojan] gefunden. Löschen oder ignorieren bringt nichts. Ich bekomme die Meldung meist dreimal hintereinander, etwa im 2-Minutentakt. Ich habe den "Trojan Remover" drüberlaufen lassen. Der fand und deaktivierte zwar eine auffällige Datei im oben genannten Verzeichnis (System32), brachte aber keine Verbesserung. Irgendwelche Tips? |
![]() | #2 |
![]() ![]() ![]() ![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo und
__________________![]() ComboFix kann ihn beseitigen, allerdings hatten wir heute 2 Fälle, in dem nach Einsatz von ComboFix die Rechner nicht mehr wollten. Die zweite Möglichkeit ist Gmer, RSIT und Avenger. Deine Entscheidung. ciao, andreas
__________________ |
![]() | #3 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo,
__________________danke für die schnelle Antwort. Könntest du deine Lösungsvorschläge etwas erklären (also mir sagen, was ich mit diesen Programmen anstellen soll.) Ich habe von dieser Trojanerproblematik nämlich reichlich wenig (also eigentlich gar keine Ahnung). Offensichtlich brauchst du meinen Bericht von HijackThis nicht mehr, das Problem scheint ja eindeutig zu sein, aber trotzdem habe ich ihn noch einmal rangehängt. Meinst du es wäre ratsam, wenn ich jetzt irgendwie versuche mit ComboFix den Trojaner zu killen, oder ist das gefährlich weil ich wirklich keine Ahnung habe von dem Thema? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:43:15, on 13.07.2009 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\rundll32.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\moi\AppData\Local\Google\Update\GoogleUpdate.exe C:\Windows\System32\rundll32.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN C:\Windows\system32\conime.exe C:\Windows\system32\Taskmgr.exe C:\Program Files\Opera\opera.exe C:\Users\moi\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl<mpl=googlemail R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O1 - Hosts: ::1 localhost O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot O4 - HKLM\..\RunOnce: [Trojan Remover] "C:\Program Files\Trojan Remover\RMVTRJAN.EXE" /restart O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\moi\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing O13 - Gopher Prefix: O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EBDEF30A-421D-4F42-8EAF-A478399D7306}: NameServer = 192.168.2.2 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-Dienst (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing) O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe -- End of file - 7798 bytes |
![]() | #4 |
![]() ![]() ![]() ![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Versuchen wir es erstmal mit Gmer (das auch gerne abstürzt). 1.) http://www.trojaner-board.de/74910-a...tion-tool.html 2.) http://www.trojaner-board.de/74908-a...t-scanner.html ciao, andreas
__________________ Kein Support per PN! Das ist hier ein Forum und keine Privatbetreuung! Für alle NeuenPrivatbetreuung nur gegen Bezahlung und ich koste sehr teuer. ![]() Anleitungen Virenscanner Kompromittierung unvermeidbar? |
![]() | #5 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo, danke für die Hilfe soweit. Unten befindet sich das ellenlange Ergebnisprotokoll von GMER. Wie geht es denn jetzt am besten weiter? Danke schon einmal im voraus an alle eifrigen Helfer GMER 1.0.15.14972 - http://www.gmer.net Rootkit scan 2009-07-14 21:22:01 Windows 6.0.6000 ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x8DCD8974] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x8DCE3388] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0x8DCE1166] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0x8DCE1380] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0x8DCE4B9E] SSDT 9B27BEA4 ZwCreateThread SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x8DCD8E54] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x8DCE3C84] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x8DCE3A00] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0x8DCE0F08] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x8DCE3E34] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x8DCD8CEC] SSDT 9B27BE90 ZwOpenProcess SSDT 9B27BE95 ZwOpenThread SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x8DCE4810] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x8DCE4246] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x8DCE4650] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0x8DCDB506] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x8DCD9042] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x8DCE3706] SSDT 9B27BE9F ZwTerminateProcess SSDT 9B27BE9A ZwWriteVirtualMemory SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateUserProcess [0x8DCE159E] INT 0x51 ? 864A6F00 INT 0x62 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x82 ? 85614BF8 INT 0x92 ? 85614BF8 INT 0xB3 ? 864A6F00 ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_alloca_probe + 11C 81C5616C 4 Bytes JMP 4F4ED5F2 .text ntoskrnl.exe!_alloca_probe + 12C 81C5617C 4 Bytes [88, 33, CE, 8D] .text ntoskrnl.exe!_alloca_probe + 14C 81C5619C 8 Bytes [66, 11, CE, 8D, 80, 13, CE, ...] .text ntoskrnl.exe!_alloca_probe + 158 81C561A8 4 Bytes JMP 5011002E .text ntoskrnl.exe!_alloca_probe + 164 81C561B4 4 Bytes [A4, BE, 27, 9B] .text ... ? System32\Drivers\spxg.sys Das System kann den angegebenen Pfad nicht finden. ! .text USBPORT.SYS!DllUnload 8B6D7FEB 5 Bytes JMP 864A64E0 .text aqah8k2z.SYS 8C537000 22 Bytes [1A, B2, F9, 81, 04, B1, F9, ...] .text aqah8k2z.SYS 8C537017 145 Bytes [00, 99, 57, 49, 80, A4, 55, ...] .text aqah8k2z.SYS 8C5370A9 35 Bytes [67, C3, 81, 60, 5B, C3, 81, ...] .text aqah8k2z.SYS 8C5370CE 10 Bytes [00, 00, 00, 00, 00, 00, 66, ...] .text aqah8k2z.SYS 8C5370DA 12 Bytes [00, 00, 02, 00, 00, 00, 25, ...] .text ... ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 856132D8 IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice] [82B32C4C] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [82B32CA0] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [82B026D2] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [82B02040] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [82B027FC] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [82B020BE] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [82B0213C] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\ataport.SYS[ntoskrnl.exe!DbgBreakPoint] 856142D8 IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 864A65E0 IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [82B12048] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortNotification] 24488B66 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortUchar] E84D8966 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortUlong] 83E84D8B IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 896602C1 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 488BEA4D IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetScatterGatherList] [8DC80320] \SystemRoot\system32\DRIVERS\rdbss.sys (Redirected Drive Buffering SubSystem Driver/Microsoft Corporation) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortUchar] 57500845 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortStallExecution] F0458D57 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetParentBusType] 00006850 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortRequestCallback] 458DB002 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 35FF50E8 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetUnCachedExtension] [8C55CFBC] \SystemRoot\System32\Drivers\aqah8k2z.SYS (ATAPI IDE Miniport Driver/Microsoft Corporation) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortCompleteRequest] 57EC4D89 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 01F045C7 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] E8000000 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortMoveMemory] 0001E4E4 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortUshort] 4675C73B IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 55CFC8A1 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] [8D526A8C] \SystemRoot\system32\DRIVERS\AGRSM.sys (SoftModem Device Driver/Agere Systems) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortInitialize] 00009A88 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetDeviceBase] 48C08300 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortDeviceStateChange] 8D076A50 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[NTOSKRNL.exe!KeTickCount] 840FF87D IAT \SystemRoot\system32\DRIVERS\storport.sys[ntoskrnl.exe!DbgBreakPoint] 864522D8 IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [8DCD94B6] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [8DCD9590] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [8DCD9416] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8561B1F8 AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) Device \Driver\volmgr \Device\VolMgrControl 856161F8 Device \Driver\usbuhci \Device\USBPDO-0 864491F8 Device \Driver\usbuhci \Device\USBPDO-1 864491F8 Device \Driver\usbehci \Device\USBPDO-2 864461F8 Device \Driver\usbuhci \Device\USBPDO-3 864491F8 Device \Driver\usbuhci \Device\USBPDO-4 864491F8 Device \Driver\usbuhci \Device\USBPDO-5 864491F8 Device \Driver\usbehci \Device\USBPDO-6 864461F8 Device \Driver\volmgr \Device\HarddiskVolume1 856161F8 Device \Driver\volmgr \Device\HarddiskVolume2 856161F8 Device \Driver\cdrom \Device\CdRom0 864511F8 Device \Driver\volmgr \Device\HarddiskVolume3 856161F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8561A1F8 Device \Driver\atapi \Device\Ide\IdePort0 8561A1F8 Device \Driver\atapi \Device\Ide\IdePort1 8561A1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8561A1F8 Device \Driver\cdrom \Device\CdRom1 864511F8 Device \Driver\netbt \Device\NetBt_Wins_Export 8D3E71F8 Device \Driver\Smb \Device\NetbiosSmb 8D3E2500 Device \Driver\PCI_PNP6091 \Device\0000004c spxg.sys Device \Driver\sptd \Device\2125586111 spxg.sys Device \Driver\netbt \Device\NetBT_Tcpip_{EBDEF30A-421D-4F42-8EAF-A478399D7306} 8D3E71F8 Device \Driver\iScsiPrt \Device\RaidPort0 8646A1F8 Device \Driver\BTHUSB \Device\0000006a bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation) Device \Driver\usbuhci \Device\USBFDO-0 864491F8 Device \Driver\usbuhci \Device\USBFDO-1 864491F8 Device \Driver\usbehci \Device\USBFDO-2 864461F8 Device \Driver\usbuhci \Device\USBFDO-3 864491F8 Device \Driver\usbuhci \Device\USBFDO-4 864491F8 Device \Driver\usbuhci \Device\USBFDO-5 864491F8 Device \Driver\netbt \Device\NetBT_Tcpip_{D3419F58-E852-4EF7-91FF-8A0EE0D19495} 8D3E71F8 Device \Driver\usbehci \Device\USBFDO-6 864461F8 Device \Driver\aqah8k2z \Device\Scsi\aqah8k2z1 865A51F8 Device \Driver\aqah8k2z \Device\Scsi\aqah8k2z1Port3Path0Target0Lun0 865A51F8 Device \FileSystem\cdfs \Cdfs 9D9BC1F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0ca0 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0cab Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0ccf Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197efa9e13 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197efa9e13@0018aff3c74c 0xC3 0x1C 0x0B 0x4B ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xFC 0x9C 0x8C 0x92 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0xF8 0x7B 0xD6 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2F 0xAE 0x3B 0x31 ... Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0ca0 Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0cab Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0ccf Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00197efa9e13 Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00197efa9e13@0018aff3c74c 0xC3 0x1C 0x0B 0x4B ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xFC 0x9C 0x8C 0x92 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0xF8 0x7B 0xD6 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2F 0xAE 0x3B 0x31 ... ---- EOF - GMER 1.0.15 ---- |
![]() | #6 |
![]() ![]() ![]() ![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Lade dir den hier und scanne damit => Avira AntiRootkit Tool Die Logs von RSIT fehlen noch. Gmer zeigt an, dass du den Zonealarmtrojaner hast => http://www.trojaner-board.de/73296-z...ight=zonealarm ciao, andreas
__________________ --> 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet |
![]() | #7 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo, ich habe genau das selbe Problem. Bei mir wird TR/Redol.C gefunden. Das ganze im Abstand von 30min und die Dateien lassen sich ebenfalls nicht löschen / blockieren. (AntiVir) RootRepeal Scan: ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/07/16 08:15 Program Version: Version 1.3.2.0 Windows Version: Windows Vista SP1 ================================================== Drivers ------------------- Name: Ѓ浍楓㔨跛 Image Path: Ѓ浍楓㔨跛 Address: 0x91511000 Size: 163840 File Visible: No Signed: - Status: Hidden from the Windows API! Name: 1394BUS.SYS Image Path: C:\Windows\system32\DRIVERS\1394BUS.SYS Address: 0x8F059000 Size: 57344 File Visible: - Signed: - Status: - Name: acpi.sys Image Path: C:\Windows\system32\drivers\acpi.sys Address: 0x807B8000 Size: 286720 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x82A36000 Size: 3903488 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\Windows\system32\drivers\afd.sys Address: 0x8FD38000 Size: 294912 File Visible: - Signed: - Status: - Name: ajj2zjja.SYS Image Path: C:\Windows\System32\Drivers\ajj2zjja.SYS Address: 0x8F1BE000 Size: 225280 File Visible: - Signed: - Status: - Name: Apfiltr.sys Image Path: C:\Windows\system32\DRIVERS\Apfiltr.sys Address: 0x8F16E000 Size: 184320 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: C:\Windows\system32\drivers\atapi.sys Address: 0x8A86A000 Size: 32768 File Visible: - Signed: - Status: - Name: ataport.SYS Image Path: C:\Windows\system32\drivers\ataport.SYS Address: 0x8A872000 Size: 122880 File Visible: - Signed: - Status: - Name: atikmdag.sys Image Path: C:\Windows\system32\DRIVERS\atikmdag.sys Address: 0x8E401000 Size: 6180864 File Visible: - Signed: - Status: - Name: atksgt.sys Image Path: C:\Windows\system32\DRIVERS\atksgt.sys Address: 0xA000E000 Size: 271360 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\Windows\System32\ATMFD.DLL Address: 0x816B0000 Size: 311296 File Visible: - Signed: - Status: - Name: avgio.sys Image Path: D:\Programme\Avira\AntiVir Desktop\avgio.sys Address: 0x8FDF9000 Size: 6144 File Visible: - Signed: - Status: - Name: avgntflt.sys Image Path: C:\Windows\system32\DRIVERS\avgntflt.sys Address: 0x908BC000 Size: 81920 File Visible: - Signed: - Status: - Name: avipbb.sys Image Path: C:\Windows\system32\DRIVERS\avipbb.sys Address: 0x8F9D9000 Size: 114688 File Visible: - Signed: - Status: - Name: BATTC.SYS Image Path: C:\Windows\system32\DRIVERS\BATTC.SYS Address: 0x805F0000 Size: 40960 File Visible: - Signed: - Status: - Name: Beep.SYS Image Path: C:\Windows\System32\Drivers\Beep.SYS Address: 0x8F8F8000 Size: 28672 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\Windows\system32\BOOTVID.dll Address: 0x80486000 Size: 32768 File Visible: - Signed: - Status: - Name: bowser.sys Image Path: C:\Windows\system32\DRIVERS\bowser.sys Address: 0x9F291000 Size: 102400 File Visible: - Signed: - Status: - Name: cdd.dll Image Path: C:\Windows\System32\cdd.dll Address: 0x816A0000 Size: 57344 File Visible: - Signed: - Status: - Name: cdfs.sys Image Path: C:\Windows\system32\DRIVERS\cdfs.sys Address: 0xA0198000 Size: 90112 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\Windows\system32\DRIVERS\cdrom.sys Address: 0x8F1A6000 Size: 98304 File Visible: - Signed: - Status: - Name: CI.dll Image Path: C:\Windows\system32\CI.dll Address: 0x804CF000 Size: 917504 File Visible: - Signed: - Status: - Name: circlass.sys Image Path: C:\Windows\system32\DRIVERS\circlass.sys Address: 0x8ABE3000 Size: 57344 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\Windows\system32\drivers\CLASSPNP.SYS Address: 0x8AD9E000 Size: 135168 File Visible: - Signed: - Status: - Name: CLFS.SYS Image Path: C:\Windows\system32\CLFS.SYS Address: 0x8048E000 Size: 266240 File Visible: - Signed: - Status: - Name: CmBatt.sys Image Path: C:\Windows\system32\DRIVERS\CmBatt.sys Address: 0x8EB2A000 Size: 14208 File Visible: - Signed: - Status: - Name: compbatt.sys Image Path: C:\Windows\system32\DRIVERS\compbatt.sys Address: 0x805ED000 Size: 10496 File Visible: - Signed: - Status: - Name: crashdmp.sys Image Path: C:\Windows\System32\Drivers\crashdmp.sys Address: 0x90866000 Size: 53248 File Visible: - Signed: - Status: - Name: crcdisk.sys Image Path: C:\Windows\system32\drivers\crcdisk.sys Address: 0x8ADBF000 Size: 36864 File Visible: - Signed: - Status: - Name: dfsc.sys Image Path: C:\Windows\System32\Drivers\dfsc.sys Address: 0x8F9C2000 Size: 94208 File Visible: - Signed: - Status: - Name: disk.sys Image Path: C:\Windows\system32\drivers\disk.sys Address: 0x8AD8D000 Size: 69632 File Visible: - Signed: - Status: - Name: dne2000.sys Image Path: C:\Windows\system32\DRIVERS\dne2000.sys Address: 0x8EB2E000 Size: 121728 File Visible: - Signed: - Status: - Name: drmk.sys Image Path: C:\Windows\system32\drivers\drmk.sys Address: 0x8F82F000 Size: 151552 File Visible: - Signed: - Status: - Name: dump_dumpata.sys Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys Address: 0x90873000 Size: 45056 File Visible: No Signed: - Status: - Name: dump_msahci.sys Image Path: C:\Windows\System32\Drivers\dump_msahci.sys Address: 0x9087E000 Size: 40960 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\Windows\System32\drivers\Dxapi.sys Address: 0x90888000 Size: 40960 File Visible: - Signed: - Status: - Name: dxgkrnl.sys Image Path: C:\Windows\System32\drivers\dxgkrnl.sys Address: 0x8EA05000 Size: 651264 File Visible: - Signed: - Status: - Name: ecache.sys Image Path: C:\Windows\System32\drivers\ecache.sys Address: 0x8AD66000 Size: 159744 File Visible: - Signed: - Status: - Name: fastfat.SYS Image Path: C:\Windows\System32\Drivers\fastfat.SYS Address: 0xA0051000 Size: 163840 File Visible: - Signed: - Status: - Name: fileinfo.sys Image Path: C:\Windows\system32\drivers\fileinfo.sys Address: 0x8A8DA000 Size: 65536 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: C:\Windows\system32\drivers\fltmgr.sys Address: 0x8A8A8000 Size: 204800 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS Address: 0x8F8E8000 Size: 36864 File Visible: - Signed: - Status: - Name: fwpkclnt.sys Image Path: C:\Windows\System32\drivers\fwpkclnt.sys Address: 0x8FCF3000 Size: 110592 File Visible: - Signed: - Status: - Name: hal.dll Image Path: C:\Windows\system32\hal.dll Address: 0x82A03000 Size: 208896 File Visible: - Signed: - Status: - Name: HDAudBus.sys Image Path: C:\Windows\system32\DRIVERS\HDAudBus.sys Address: 0x8EAB1000 Size: 73728 File Visible: - Signed: - Status: - Name: HIDCLASS.SYS Image Path: C:\Windows\system32\DRIVERS\HIDCLASS.SYS Address: 0x8F8C0000 Size: 65536 File Visible: - Signed: - Status: - Name: hidir.sys Image Path: C:\Windows\system32\DRIVERS\hidir.sys Address: 0x8F8B5000 Size: 45056 File Visible: - Signed: - Status: - Name: HIDPARSE.SYS Image Path: C:\Windows\system32\DRIVERS\HIDPARSE.SYS Address: 0x8F8D0000 Size: 28672 File Visible: - Signed: - Status: - Name: hidusb.sys Image Path: C:\Windows\system32\DRIVERS\hidusb.sys Address: 0x8F9F5000 Size: 36864 File Visible: - Signed: - Status: - Name: hjgruibbfprnte.sys Image Path: C:\Windows\system32\drivers\hjgruibbfprnte.sys Address: 0x8F93C000 Size: 163840 File Visible: - Signed: - Status: Hidden from the Windows API! Name: HTTP.sys Image Path: C:\Windows\system32\drivers\HTTP.sys Address: 0x9F209000 Size: 438272 File Visible: - Signed: - Status: - Name: i8042prt.sys Image Path: C:\Windows\system32\DRIVERS\i8042prt.sys Address: 0x8F150000 Size: 77824 File Visible: - Signed: - Status: - Name: intelppm.sys Image Path: C:\Windows\system32\DRIVERS\intelppm.sys Address: 0x8EB1B000 Size: 61440 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\Windows\system32\DRIVERS\ipnat.sys Address: 0xA0172000 Size: 155648 File Visible: - Signed: - Status: - Name: itecir.sys Image Path: C:\Windows\system32\DRIVERS\itecir.sys Address: 0x8F0F8000 Size: 360448 File Visible: - Signed: - Status: - Name: k57nd60x.sys Image Path: C:\Windows\system32\DRIVERS\k57nd60x.sys Address: 0x8F014000 Size: 217088 File Visible: - Signed: - Status: - Name: kbdclass.sys Image Path: C:\Windows\system32\DRIVERS\kbdclass.sys Address: 0x8F163000 Size: 45056 File Visible: - Signed: - Status: - Name: kbdhid.sys Image Path: C:\Windows\system32\DRIVERS\kbdhid.sys Address: 0x8F8D7000 Size: 36864 File Visible: - Signed: - Status: - Name: kdcom.dll Image Path: C:\Windows\system32\kdcom.dll Address: 0x8040D000 Size: 32768 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\Windows\system32\DRIVERS\ks.sys Address: 0x8ABB9000 Size: 172032 File Visible: - Signed: - Status: - Name: ksecdd.sys Image Path: C:\Windows\System32\Drivers\ksecdd.sys Address: 0x8A8F3000 Size: 462848 File Visible: - Signed: - Status: - Name: lirsgt.sys Image Path: C:\Windows\system32\DRIVERS\lirsgt.sys Address: 0xA0079000 Size: 18048 File Visible: - Signed: - Status: - Name: lltdio.sys Image Path: C:\Windows\system32\DRIVERS\lltdio.sys Address: 0x908D0000 Size: 65536 File Visible: - Signed: - Status: - Name: luafv.sys Image Path: C:\Windows\system32\drivers\luafv.sys Address: 0x908A1000 Size: 110592 File Visible: - Signed: - Status: - Name: mcupdate_GenuineIntel.dll Image Path: C:\Windows\system32\mcupdate_GenuineIntel.dll Address: 0x80415000 Size: 393216 File Visible: - Signed: - Status: - Name: monitor.sys Image Path: C:\Windows\system32\DRIVERS\monitor.sys Address: 0x90892000 Size: 61440 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\Windows\system32\DRIVERS\mouclass.sys Address: 0x8F19B000 Size: 45056 File Visible: - Signed: - Status: - Name: mouhid.sys Image Path: C:\Windows\system32\DRIVERS\mouhid.sys Address: 0x8F8E0000 Size: 32768 File Visible: - Signed: - Status: - Name: mountmgr.sys Image Path: C:\Windows\System32\drivers\mountmgr.sys Address: 0x8A85A000 Size: 65536 File Visible: - Signed: - Status: - Name: mpsdrv.sys Image Path: C:\Windows\System32\drivers\mpsdrv.sys Address: 0x9F2AA000 Size: 86016 File Visible: - Signed: - Status: - Name: mrxdav.sys Image Path: C:\Windows\system32\drivers\mrxdav.sys Address: 0x9F2BF000 Size: 131072 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\Windows\system32\DRIVERS\mrxsmb.sys Address: 0x9F2DF000 Size: 126976 File Visible: - Signed: - Status: - Name: mrxsmb10.sys Image Path: C:\Windows\system32\DRIVERS\mrxsmb10.sys Address: 0x9F2FE000 Size: 233472 File Visible: - Signed: - Status: - Name: mrxsmb20.sys Image Path: C:\Windows\system32\DRIVERS\mrxsmb20.sys Address: 0x9F337000 Size: 98304 File Visible: - Signed: - Status: - Name: msahci.sys Image Path: C:\Windows\system32\drivers\msahci.sys Address: 0x8A890000 Size: 40960 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\Windows\System32\Drivers\Msfs.SYS Address: 0x8F964000 Size: 45056 File Visible: - Signed: - Status: - Name: msisadrv.sys Image Path: C:\Windows\system32\drivers\msisadrv.sys Address: 0x805AF000 Size: 32768 File Visible: - Signed: - Status: - Name: msiscsi.sys Image Path: C:\Windows\system32\DRIVERS\msiscsi.sys Address: 0x8EB4C000 Size: 188416 File Visible: - Signed: - Status: - Name: msrpc.sys Image Path: C:\Windows\system32\drivers\msrpc.sys Address: 0x8AB0C000 Size: 176128 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\Windows\system32\DRIVERS\mssmbios.sys Address: 0x8ABF1000 Size: 40960 File Visible: - Signed: - Status: - Name: mup.sys Image Path: C:\Windows\System32\Drivers\mup.sys Address: 0x8AD57000 Size: 61440 File Visible: - Signed: - Status: - Name: ndis.sys Image Path: C:\Windows\system32\drivers\ndis.sys Address: 0x8AA01000 Size: 1093632 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\Windows\system32\DRIVERS\ndistapi.sys Address: 0x8EBDD000 Size: 45056 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\Windows\system32\DRIVERS\ndisuio.sys Address: 0x9090A000 Size: 40960 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\Windows\system32\DRIVERS\ndiswan.sys Address: 0x8AB71000 Size: 143360 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\Windows\System32\Drivers\NDProxy.SYS Address: 0x8A9A6000 Size: 69632 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\Windows\system32\DRIVERS\netbios.sys Address: 0x8FDC8000 Size: 57344 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\Windows\System32\DRIVERS\netbt.sys Address: 0x8FD80000 Size: 204800 File Visible: - Signed: - Status: - Name: NETIO.SYS Image Path: C:\Windows\system32\drivers\NETIO.SYS Address: 0x8AB37000 Size: 237568 File Visible: - Signed: - Status: - Name: NETw5v32.sys Image Path: C:\Windows\system32\DRIVERS\NETw5v32.sys Address: 0x8EC01000 Size: 4272128 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\Windows\System32\Drivers\Npfs.SYS Address: 0x8F96F000 Size: 57344 File Visible: - Signed: - Status: - Name: nsiproxy.sys Image Path: C:\Windows\system32\drivers\nsiproxy.sys Address: 0x8FDEF000 Size: 40960 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: C:\Windows\System32\Drivers\Ntfs.sys Address: 0x8AC07000 Size: 1110016 File Visible: - Signed: - Status: - Name: ntkrnlpa.exe Image Path: C:\Windows\system32\ntkrnlpa.exe Address: 0x82A36000 Size: 3903488 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\Windows\System32\Drivers\Null.SYS Address: 0x8F8F1000 Size: 28672 File Visible: - Signed: - Status: - Name: nwifi.sys Image Path: C:\Windows\system32\DRIVERS\nwifi.sys Address: 0x908E0000 Size: 172032 File Visible: - Signed: - Status: - Name: OA001Ufd.sys Image Path: C:\Windows\system32\DRIVERS\OA001Ufd.sys Address: 0x90845000 Size: 133472 File Visible: - Signed: - Status: - Name: OA001Vid.sys Image Path: C:\Windows\system32\DRIVERS\OA001Vid.sys Address: 0x90800000 Size: 279488 File Visible: - Signed: - Status: - Name: ohci1394.sys Image Path: C:\Windows\system32\DRIVERS\ohci1394.sys Address: 0x8F049000 Size: 61952 File Visible: - Signed: - Status: - Name: pacer.sys Image Path: C:\Windows\system32\DRIVERS\pacer.sys Address: 0x8FDB2000 Size: 90112 File Visible: - Signed: - Status: - Name: partmgr.sys Image Path: C:\Windows\System32\drivers\partmgr.sys Address: 0x805DE000 Size: 61440 File Visible: - Signed: - Status: - Name: pci.sys Image Path: C:\Windows\system32\drivers\pci.sys Address: 0x805B7000 Size: 159744 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\Windows\system32\drivers\PCIIDEX.SYS Address: 0x8A89A000 Size: 57344 File Visible: - Signed: - Status: - Name: peauth.sys Image Path: C:\Windows\system32\drivers\peauth.sys Address: 0xA007E000 Size: 909312 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x82A36000 Size: 3903488 File Visible: - Signed: - Status: - Name: portcls.sys Image Path: C:\Windows\system32\drivers\portcls.sys Address: 0x8F802000 Size: 184320 File Visible: - Signed: - Status: - Name: PSHED.dll Image Path: C:\Windows\system32\PSHED.dll Address: 0x80475000 Size: 69632 File Visible: - Signed: - Status: - Name: PxHelp20.sys Image Path: C:\Windows\System32\Drivers\PxHelp20.sys Address: 0x8A8EA000 Size: 36288 File Visible: - Signed: - Status: - Name: rasacd.sys Image Path: C:\Windows\System32\DRIVERS\rasacd.sys Address: 0x8F97D000 Size: 36864 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\Windows\system32\DRIVERS\rasl2tp.sys Address: 0x8EBC6000 Size: 94208 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\Windows\system32\DRIVERS\raspppoe.sys Address: 0x8EBE8000 Size: 61440 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\Windows\system32\DRIVERS\raspptp.sys Address: 0x8E9E6000 Size: 81920 File Visible: - Signed: - Status: - Name: rassstp.sys Image Path: C:\Windows\system32\DRIVERS\rassstp.sys Address: 0x8AB94000 Size: 86016 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x82A36000 Size: 3903488 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\Windows\system32\DRIVERS\rdbss.sys Address: 0x8F986000 Size: 245760 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\Windows\System32\DRIVERS\RDPCDD.sys Address: 0x8F92C000 Size: 32768 File Visible: - Signed: - Status: - Name: rdpencdd.sys Image Path: C:\Windows\system32\drivers\rdpencdd.sys Address: 0x8F934000 Size: 32768 File Visible: - Signed: - Status: - Name: rimmptsk.sys Image Path: C:\Windows\system32\DRIVERS\rimmptsk.sys Address: 0x8F081000 Size: 69632 File Visible: - Signed: - Status: - Name: rimsptsk.sys Image Path: C:\Windows\system32\DRIVERS\rimsptsk.sys Address: 0x8F092000 Size: 81920 File Visible: - Signed: - Status: - Name: rixdptsk.sys Image Path: C:\Windows\system32\DRIVERS\rixdptsk.sys Address: 0x8F0A6000 Size: 335872 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0xA01AE000 Size: 49152 File Visible: No Signed: - Status: - Name: rspndr.sys Image Path: C:\Windows\system32\DRIVERS\rspndr.sys Address: 0x90914000 Size: 77824 File Visible: - Signed: - Status: - Name: RtHDMIV.sys Image Path: C:\Windows\system32\drivers\RtHDMIV.sys Address: 0x8A9B7000 Size: 147264 File Visible: - Signed: - Status: - Name: SCSIPORT.SYS Image Path: C:\Windows\System32\Drivers\SCSIPORT.SYS Address: 0x80792000 Size: 155648 File Visible: - Signed: - Status: - Name: sdbus.sys Image Path: C:\Windows\system32\DRIVERS\sdbus.sys Address: 0x8F067000 Size: 106496 File Visible: - Signed: - Status: - Name: secdrv.SYS Image Path: C:\Windows\System32\Drivers\secdrv.SYS Address: 0xA015C000 Size: 40960 File Visible: - Signed: - Status: - Name: smb.sys Image Path: C:\Windows\system32\DRIVERS\smb.sys Address: 0x8FD24000 Size: 81920 File Visible: - Signed: - Status: - Name: spldr.sys Image Path: C:\Windows\System32\Drivers\spldr.sys Address: 0x8AD4F000 Size: 32768 File Visible: - Signed: - Status: - Name: spsys.sys Image Path: C:\Windows\system32\drivers\spsys.sys Address: 0x90927000 Size: 716800 File Visible: - Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: spup.sys Image Path: C:\Windows\System32\Drivers\spup.sys Address: 0x80689000 Size: 1048576 File Visible: No Signed: - Status: - Name: srv.sys Image Path: C:\Windows\System32\DRIVERS\srv.sys Address: 0x9F376000 Size: 311296 File Visible: - Signed: - Status: - Name: srv2.sys Image Path: C:\Windows\System32\DRIVERS\srv2.sys Address: 0x9F34F000 Size: 159744 File Visible: - Signed: - Status: - Name: srvnet.sys Image Path: C:\Windows\System32\DRIVERS\srvnet.sys Address: 0x9F274000 Size: 118784 File Visible: - Signed: - Status: - Name: ssmdrv.sys Image Path: C:\Windows\system32\DRIVERS\ssmdrv.sys Address: 0x8FDE9000 Size: 23040 File Visible: - Signed: - Status: - Name: storport.sys Image Path: C:\Windows\system32\DRIVERS\storport.sys Address: 0x8EB7A000 Size: 266240 File Visible: - Signed: - Status: - Name: stwrt.sys Image Path: C:\Windows\system32\DRIVERS\stwrt.sys Address: 0x8F854000 Size: 397312 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\Windows\system32\DRIVERS\swenum.sys Address: 0x8F1FE000 Size: 4992 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\Windows\System32\drivers\tcpip.sys Address: 0x8FC0C000 Size: 946176 File Visible: - Signed: - Status: - Name: tcpipreg.sys Image Path: C:\Windows\System32\drivers\tcpipreg.sys Address: 0xA0166000 Size: 49152 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\Windows\system32\DRIVERS\TDI.SYS Address: 0x8EBBB000 Size: 45056 File Visible: - Signed: - Status: - Name: tdx.sys Image Path: C:\Windows\system32\DRIVERS\tdx.sys Address: 0x8FD0E000 Size: 90112 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\Windows\system32\DRIVERS\termdd.sys Address: 0x8ABA9000 Size: 65536 File Visible: - Signed: - Status: - Name: TSDDD.dll Image Path: C:\Windows\System32\TSDDD.dll Address: 0x81680000 Size: 36864 File Visible: - Signed: - Status: - Name: tunmp.sys Image Path: C:\Windows\system32\DRIVERS\tunmp.sys Address: 0x8ADF5000 Size: 36864 File Visible: - Signed: - Status: - Name: tunnel.sys Image Path: C:\Windows\system32\DRIVERS\tunnel.sys Address: 0x8ADEA000 Size: 45056 File Visible: - Signed: - Status: - Name: umbus.sys Image Path: C:\Windows\system32\DRIVERS\umbus.sys Address: 0x8A964000 Size: 53248 File Visible: - Signed: - Status: - Name: usbccgp.sys Image Path: C:\Windows\system32\DRIVERS\usbccgp.sys Address: 0x8A9DB000 Size: 94208 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\Windows\system32\DRIVERS\USBD.SYS Address: 0x8FDFB000 Size: 8192 File Visible: - Signed: - Status: - Name: usbehci.sys Image Path: C:\Windows\system32\DRIVERS\usbehci.sys Address: 0x8EB0C000 Size: 61440 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\Windows\system32\DRIVERS\usbhub.sys Address: 0x8A971000 Size: 217088 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\Windows\system32\DRIVERS\USBPORT.SYS Address: 0x8EACE000 Size: 253952 File Visible: - Signed: - Status: - Name: usbprint.sys Image Path: C:\Windows\system32\DRIVERS\usbprint.sys Address: 0x8FC00000 Size: 40960 File Visible: - Signed: - Status: - Name: usbuhci.sys Image Path: C:\Windows\system32\DRIVERS\usbuhci.sys Address: 0x8EAC3000 Size: 45056 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\Windows\System32\drivers\vga.sys Address: 0x8F8FF000 Size: 49152 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\Windows\System32\drivers\VIDEOPRT.SYS Address: 0x8F90B000 Size: 135168 File Visible: - Signed: - Status: - Name: volmgr.sys Image Path: C:\Windows\system32\drivers\volmgr.sys Address: 0x8A801000 Size: 61440 File Visible: - Signed: - Status: - Name: volmgrx.sys Image Path: C:\Windows\System32\drivers\volmgrx.sys Address: 0x8A810000 Size: 303104 File Visible: - Signed: - Status: - Name: volsnap.sys Image Path: C:\Windows\system32\drivers\volsnap.sys Address: 0x8AD16000 Size: 233472 File Visible: - Signed: - Status: - Name: wanarp.sys Image Path: C:\Windows\system32\DRIVERS\wanarp.sys Address: 0x8FDD6000 Size: 77824 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\Windows\System32\drivers\watchdog.sys Address: 0x8EAA4000 Size: 53248 File Visible: - Signed: - Status: - Name: Wdf01000.sys Image Path: C:\Windows\system32\drivers\Wdf01000.sys Address: 0x80600000 Size: 507904 File Visible: - Signed: - Status: - Name: WDFLDR.SYS Image Path: C:\Windows\system32\drivers\WDFLDR.SYS Address: 0x8067C000 Size: 53248 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0x81460000 Size: 2105344 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\Windows\System32\win32k.sys Address: 0x81460000 Size: 2105344 File Visible: - Signed: - Status: - Name: wmiacpi.sys Image Path: C:\Windows\system32\DRIVERS\wmiacpi.sys Address: 0x8F1F5000 Size: 36864 File Visible: - Signed: - Status: - Name: WMILIB.SYS Image Path: C:\Windows\System32\Drivers\WMILIB.SYS Address: 0x80789000 Size: 36864 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x82A36000 Size: 3903488 File Visible: - Signed: - Status: - |
![]() | #8 | |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo Andreas ![]() Zitat:
![]() CMD.Exe.... komisch... irgendeins der Tausend Scanprogramme, die ich hab durchlaufen lassen, hat mich gebeten, ebendiese Datei zu löschen. Ich hatte sie aber nicht finden können. Na offensichtlich gabs sie doch. *shrug* Kann/Sollte ich die UAC jetzt eigentlich (oder später) wieder aktivieren? However: Hier ist das logfile von SysProt. Hätte ich nach Deaktivierung der UAC den Rechner neustarten müssen? Ich habs jetzt nicht gemacht, ich hoffe, dass das so trotzdem geht. http://www.materialordner.de/downloa...T5PjsQEwAsGYwDhttp://www.materialordner.de/downloa...T5PjsQEwAsGYwD |
![]() | #9 |
![]() ![]() ![]() ![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo Nora, 1.) Anleitung Avenger (by swandog46) Lade dir das Tool Hopsassa und speichere es auf dem Desktop:
Code:
ATTFilter Files to delete: C:\Windows\System32\hjgruixpeuxtce.dll ![]()
2.) Scanne und poste anschliessend das Log mit diesen Einstellungen: http://www.trojaner-board.de/54192-a...tellungen.html ciao, andreas
__________________ Kein Support per PN! Das ist hier ein Forum und keine Privatbetreuung! Für alle NeuenPrivatbetreuung nur gegen Bezahlung und ich koste sehr teuer. ![]() Anleitungen Virenscanner Kompromittierung unvermeidbar? |
![]() | #10 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo Andreas, verzeih die andauernde Absenz, bei mir ist zur Zeit Prüfungshalligalli. Hier ist nun das Logfile vom Avenger und ich beginne mich langsam zu fragen, ob das mysteriöse Rootkit überhaupt existiert... Code:
ATTFilter Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows Vista ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: file "C:\Windows\System32\hjgruixpeuxtce.dll" not found! Deletion of file "C:\Windows\System32\hjgruixpeuxtce.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate. Gruß, Nora |
![]() | #11 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo nochmal, ich glaube, ich habe uns unnötig weiterhin auf Trab gehalten. Ich bin gerade über das Log von einer Applikation gespolpert, die ich zu Beginn und ohne Anleitung hatte durchlaufen lassen und rate, was ich gefunden hab: http://www.materialordner.de/FqFxD9T...2TcfAf8fL.html Bedeutet es das, was ich denke, dass es bedeutet? |
![]() | #12 | |
![]() ![]() ![]() ![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldetZitat:
![]() Ich war schon völlig durch den Wind, weil keines der Programme etwas angezeigt hat. Poste bitte trotzdem noch ein Log von Avira und die RSIT-Logs, dann sollten wir durch sein. ciao, andreas
__________________ Kein Support per PN! Das ist hier ein Forum und keine Privatbetreuung! Für alle NeuenPrivatbetreuung nur gegen Bezahlung und ich koste sehr teuer. ![]() Anleitungen Virenscanner Kompromittierung unvermeidbar? |
![]() |
Themen zu 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet |
ander, antivir, antivir guard, c:\windows, datei, folge, folgende, folgenden, gefunde, gemeldet, guard, ignorieren, melde, meldet, meldung, programm, remover, stunde, system, system32, troja, trojan, unerwünschtes programm, verzeichnis, virus, windows |