![]() |
termsrv(3).dll: Malwarebytes' Anti-Malware 1.51.1.1800 identifiziert Trojaner .... Infizierte Dateien: c:\WINDOWS\system32\termsrv(3).dll (Trojan.Downloader) -> No action taken. OTL läuft nicht auf diesen Rechner, jedoch auf einen anderen. GMER meldet während des Sans: i3cupqb.exe ... corrupt and unreadable. Please run the Chkdsk utility. i3cupqb.exe im Suchlauf auf Systempartition nicht gefunden i3cupqb.exe ist google nicht bekannt Hier die Logs: defogger_disable by jpshortstuff (23.02.10.1) Log created at 00:09 on 08/08/2011 (u) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... d347prt -> Disabled (Service running -> reboot required) SPTD -> Disabledd347bus -> Disabled (Service running -> reboot required) -=E.O.F=- GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2011-08-08 09:21:38 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3160215A rev.3.AAD Running: i3cupqpb.exe; Driver: C:\DOCUME~1\u\LOCALS~1\Temp\pxlcrfod.sys ---- System - GMER 1.0.15 ---- Code F8CC1C9C ZwRequestPort Code F8CC1D3C ZwRequestWaitReplyPort Code F8CC1BFC ZwTraceEvent Code F8CC1C9B NtRequestPort Code F8CC1D3B NtRequestWaitReplyPort Code F8CC1BFB NtTraceEvent ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!NtTraceEvent 80545BC0 5 Bytes JMP F8CC1C00 PAGE ntoskrnl.exe!NtRequestWaitReplyPort 8056DC86 5 Bytes JMP F8CC1D40 PAGE ntoskrnl.exe!NtRequestPort 8058E3D2 5 Bytes JMP F8CC1CA0 .text win32k.sys!EngAcquireSemaphore + 20F0 BF808339 5 Bytes JMP F8CC1480 .text win32k.sys!EngFreeUserMem + 5BD7 BF80EEC5 5 Bytes JMP F8CC13E0 .text win32k.sys!EngSetLastError + 79AA BF82430B 5 Bytes JMP F8CC15C0 .text win32k.sys!FONTOBJ_pxoGetXform + 84ED BF8519C5 5 Bytes JMP F8CC1A20 .text win32k.sys!XLATEOBJ_iXlate + 2EDD BF85DEB0 5 Bytes JMP F8CC1520 .text win32k.sys!EngCreatePalette + 8A BF85F854 5 Bytes JMP F8CC18E0 .text win32k.sys!EngCopyBits + 1409 BF89A1F5 5 Bytes JMP F8CC1700 .text win32k.sys!EngCopyBits + 4DEE BF89DBDA 5 Bytes JMP F8CC1660 .text win32k.sys!EngEraseSurface + A9E0 BF8C2150 5 Bytes JMP F8CC17A0 .text win32k.sys!EngDeleteSemaphore + 3B40 BF8EC2A9 5 Bytes JMP F8CC1980 .text win32k.sys!EngCreateClip + 19DF BF9133E5 5 Bytes JMP F8CC1AC0 .text win32k.sys!EngCreateClip + 1F6F BF913975 5 Bytes JMP F8CC1B60 .text win32k.sys!EngCreateClip + 25B5 BF913FBB 5 Bytes JMP F8CC1840 ---- User code sections - GMER 1.0.15 ---- .text F:\Programme 03\Dateienverwaltung\IMAGE-Tools\O&O DiskImage 5 Pro PRG\oodiag.exe[872] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 0059DA6B F:\Programme 03\Dateienverwaltung\IMAGE-Tools\O&O DiskImage 5 Pro PRG\oodiag.exe ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\system32\hal.dll[ntoskrnl.exe!IoReadPartitionTable] [F8709E1C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT \WINDOWS\system32\hal.dll[ntoskrnl.exe!IoWritePartitionTable] [F87097AE] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT ftdisk.sys[ntoskrnl.exe!IoReadPartitionTableEx] [F8709E3C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT dmio.sys[ntoskrnl.exe!IoWritePartitionTableEx] [F87097D2] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT dmio.sys[ntoskrnl.exe!IoReadPartitionTableEx] [F8709E3C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT PartMgr.sys[ntoskrnl.exe!IoReadPartitionTableEx] [F8709E3C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT disk.sys[ntoskrnl.exe!IoReadPartitionTable] [F8709E1C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT disk.sys[ntoskrnl.exe!IoReadPartitionTableEx] [F8709E3C] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) IAT disk.sys[ntoskrnl.exe!IoWritePartitionTableEx] [F87097D2] MDPMGRNT.sys (MacDrive partition driver/Mediafour Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) AttachedDevice \FileSystem\Ntfs \Ntfs oodisrh.sys (O&O DiskImage Snapshot/Restore Helper Driver (Win32)/O&O Software GmbH) Device \FileSystem\MRxDAV \Device\WebDavRedirector MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \Driver\rdpdr \Device\RdpDrPort MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \Driver\rdpdr \Device\RdpDr MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\MRxSmb \Device\LanmanRedirector MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer MDFSYSNT.sys (MacDrive file system driver/Mediafour Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD1 0x4F 0x45 0xD3 ... Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet016\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet021\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet022\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet023\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@ServiceBinary C:\WINDOWS\system32\drivers\VDRV9000.SYS Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@Group SCSI Miniport Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@ImagePath system32\DRIVERS\vdrv9000.sys Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@Start 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@Type 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000@Tag 34 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\Enum (not active ControlSet) Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\Enum@Count 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\Enum@NextInstance 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\Enum@INITSTARTFAILED 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\Enum@0 Root\SCSIADAPTER\0000 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\parameters\pnpinterface (not active ControlSet) Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\parameters\pnpinterface@1 1 Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\security (not active ControlSet) Reg HKLM\SYSTEM\ControlSet024\Services\vdrv9000\security@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL 4FD49D6FF81D135EB21215C5ED4A6DEEAED657A5DE588A25C9A1AB6D011A763BB1CB5BCD2BDD65C39E66121CD8CC7FC37DAB15AF826801DE75FBC65C488D208E36EB79EDEA87CDEF18E319 4091BD429B90CD1A5CE265D711EDD33FAE70C83AB2672EB0C8EB9FDDCD82845F35AF72D2B74157B6D49C135B761F0424D739A45EF9E7CE6CBBB3AE9C6A5304CB61A2C4C4817726F02AA23E 4C6F89AA39313CFC985F6D4D4C889FC0837915647D8EA8912001B4DC024EB834DB00C12E7275E3306AFD3FECA2D3DF677F4E656A436BD73CDEE78C61589A7AC736D06F32FEBC9E127BECC7 4CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D97226D213B555A6A0AC4980AC7933C1CD 94748BF0193B4BAE312D50697ACF33283995907088E4CC0C5C22C30C58338E8A46323715A8440CD0B1C3EC17A134B84050B9C44FE67AF92F0833FCB977500FBAF4F1F8265E96412BC950E4 67B3596E62704A9A8AEDDF5864898F64A5FDC6C965ADAB062A452F906C8CBF1A5BD201B70851C4BFBBF335A60FDCE315A198B67EF34F5E034D7C51D2A85E7E6094AFAB2A8C7B28D41DE25D 58F353639B2304069AB6918A0D5D3881955778017F5D16A212B0CD776E903681943B0FBEF9C5935EC4DE7A37B1CEBF0C9B53EA3EB321E06E6C1AFCBA959 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OOPM02.00.00.01PRO C01EF784985197BF2FE9927834CF903AB56B5DF2C55683AE73F4DFED3054DB8DE504291E35E4A3C7279B4A7BDDA4619A72A9295AA42653F67B7A941BF96C71F21AFEBC9E127BECC74CFEBC 9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D97226D213B555A6A0AC4980AC7933F72C947D7F 9C8CAA05111E1F37AC9E7926B96B959B01106D929C4A65530A6C6253C71011DFB493B7B97F42141EEC3675E82951395377D148E886E539C9124748CCC4382A06697890EB5B7AC07CDCFE2B 28AED5616892ED47C118F37EA15EA341C02B17CA93752BF9E8D5C93CB6F03285C24B93561FA3089AAF3FC7D19E3FAFE212F4DC85EEC6868E831BD9AC715773C19B754D7701B42A45455FDD 66CAB97D162511DB00427FC33D92C3F3CF1BEA45739C95E634D901C11E1DCC5103F3040518E4E389F77B7283C5F1608AF45FC01081AE876992B8F6A1D3D1D2E6022A8E1FF83FC2033BCD2B C73EFD762F01349D2127441D02ABF23A7C63062F815043760B9D247906AD2E66F8121BFD9BEACFFD2871CE9C7F2D20226EA15E932E725791E93F0B46F546D717E17C2FE02B402C0F3944C6 3D5A571CBBF236812619FBC467C3EA6B5E5910476132922581DDA28A334D5828AD2A0088C46C9C1D811499AB37817F45665B2A409EFD376B325642EB804 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION 050A172766C93CD51A1B73499839E8B3602B36EAC1B3373819F49FE0A14422125FBC3151CC07498D44EE3A025530D08300197F69016C441D2E27EC1C0D0A95E09D82D7050978A796AC6E4D EAB793E773BD3CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CC038D530 D6EB3452A6171C11EC38DE3DC493B4CA75EC26D2DB7F60928F63B77546440EF30497343BA9C8091C35C5CAE83E4F531B1A7225E91C838EB85F195000224AF00E8CAFC34D6BF2CB6F43726B A1482B222C0509C326D9C7D29A10F68CCC305FC573CC5688987D30BD7EBFEEC32E5B5AA68F2093FBBB176601556653872C18A1D3EFFE78DB2BD6C2376201DD11F9D5E3E84DF8878A933ACA 73FC471A9FA3EC82E4C383185D484FC092A7FCF3532478A4F4DC436EF0CA8D3609983F49F56E9F4748A3DE4772E5A117314F537ACF81684CDCAED268F3B1BFBDA2A2FBF6F078080A51B6B9 30BEAEEF02764FC3CF8C19305EB3A2A2A69DCCE2C9A40ACF47BB6362B95519DD0DB001BE95C80FB163D6253D329310CFEEBA54EE967AB2B3F74306CD952FDB3D3074EF753895EDA8BB4017 5F7518419D1CDBB4BBB591F241D639E8CCB53E826A7B00C1E0A54A3AD4729A914EA56272EF1DD68E888C5A16B7C795C84883E4041DE90971B1EBDC3B063 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODI05.00.00.01PRO AEFB99EB8688374AACF4BEF56AF43B13303EA62A4B8EA20CE8245C2A00955C4C5BC200A44D4D5E2F4A5174CBF64F3319EAF8DFE3A1E2E3CBF2B6F15C8170A745EE5485F5DA81ED35E77289 0652472DFBDD97BD3890C00C4114DD43EE2E67D393A2A4F2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E 7D6A3B98088EDD5E5BE2F6E6679DB7CE019D40AA5CC038D530D6EB3452828A876751751F709A631F29052EC0C8FBA5B3A5893D9F010A4B77D5411CD69EA6595125FE8EFBCB93CC8BEBA335 D4B6D6610E30527E993BB818B23EB254D0E44E241C88C630B1B4148EAC5DC6699EBF164000EF9A64291F2CCF78245589A6A9C520E2BBCE09DAFDC1D1A0C541FC2CE45A0565E4FC48E9799F E78AE32B55A52500996819A11A1470E8D7491BC4F40A1B670263C7F3D37C0A6D696C9319289E86936D32B32F3780C5F673CD8D67ACCAC8A621E102E105830819EFE57969C665EFB88D87CD C689C32D000B97FE27CF854A225D0AB28AAEA69AC52F031148475376CE8176E1210D8949BA9AD481E161D5708AC74CAC95F892DE3CEB958A4716442456E2D01B5814FEB20231F8625BB6D8 7E34035C75105DF4676A7D30495DF49978F6602BD969C1D4F354F2389C3B7932AC95C930C8E9AA833761D3AA6461F4B864793B5E343910C10A54160EE38 ---- EOF - GMER 1.0.15 ---- vielen Dank |
Du solltest diese Kiste doch neu aufsetzen... :balla: http://www.trojaner-board.de/101434-...tml#post686750 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 06:42 Uhr. |
Copyright ©2000-2025, Trojaner-Board