kann nod 32 nicht laufen lassen - bricht immer wieder ab

#0
10.05.2007, 17:44
...neu hier

Beiträge: 5
#1 Hallo,
ich hoffe, mein posting ist in diesem Forum richtig.

Mein Problem:
Seit einigen Tagen passieren seltsame Dinge, wenn ich mich im Netz aufhalten. Der Aufbau einer Seite benötigt ungewöhnlich lange und gelingt mitunter gar nicht.

Heute war ich auf der Ebay-Seite und es wird mir keine Verschlüsselung angezeigt; ich bin immer eingeloggt, seit heute ist es allerdings auch nicht der Fall, so dass ich meine Daten neu eingeben muss. Am Wochenende hatte ich etwas gekauft und seitdem tauchte dieses seltsame Verhalten des PC auf.

Nun wollte ich einen erneuten Virencheck machen, aber er bricht nach ca. 10 Min immer wieder ab. Dies war allerdings auch bereits schon Sonntag der Fall. Leider kann ich nicht mehr sagen, an welcher Stelle genau der Abbruch passiert.

Ich kann mir das ganze nicht erklären und bitte Euch, mein HJT mal zu überprüfen, ob denn alles seine Richtigkeit hat.

Logfile of HijackThis v1.99.1
Scan saved at 17:29:23, on 10.05.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Eset\nod32kui.exe
C:\Programme\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\WF2K.EXE
C:\Programme\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\CASIO\Photo Loader\Plauto.exe
C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
C:\Dokumente und Einstellungen\***\Desktop\Downloads\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nod32kui] "C:\Programme\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\system32\WF2K.EXE Initial
O4 - HKLM\..\Run: [WinFast Schedule] C:\Programme\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Photo Loader resident.lnk = C:\Programme\CASIO\Photo Loader\Plauto.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod-Dienst (iPod Service) - Unknown owner - C:\Programme\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programme\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Programme\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programme\Spyware Doctor\swdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Programme\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe


Vielen Dank und Grüße an Euch
Georgina
Seitenanfang Seitenende
10.05.2007, 19:10
Moderator

Beiträge: 7805
#2 Schieb mal ein combofix Report nach: http://virus-protect.org/artikel/tools/combofix.html
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
10.05.2007, 20:25
...neu hier

Themenstarter

Beiträge: 5
#3 Hallo raman,

Danke für Deine Antwort und ich hoffe, es ist das, was Du haben wolltest....

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Header
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
find.bat Version 2007.05.01.01

Microsoft Windows XP [Version 5.1.2600]
Bootmodus: NORMAL

eScan Version: 9.1.9
Sprache: German

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infektionsmeldungen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Object "gain.gator Spyware/Adware" in Dateisystem gefunden! Folgende Maßnahme wurde durchgeführt: Keine Aktion vorgenommen.
Object "Possible Fujacks-type Worm" in Dateisystem gefunden! Folgende Maßnahme wurde durchgeführt: Keine Aktion vorgenommen.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (process.exe)! Action taken: Keine Aktion vorgenommen.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swreg.exe)! Action taken: Keine Aktion vorgenommen.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swsc.exe)! Action taken: Keine Aktion vorgenommen.


~~~~~~~~~~~
Dateien
~~~~~~~~~~~
~~~~ Infected files
~~~~~~~~~~~
Datei C:\AUTORUN.INF infiziert von "Fujack" Virus. Aktion vorgenommen: No Action Taken.
~~~~~~~~~~~
~~~~ Tagged files
~~~~~~~~~~~
Datei C:\System Volume Information\_restore{E98FF055-7076-41F4-93C1-6B88431474D6}\RP24\A0007448.exe//xpkey.exe markiert als not-a-virus:pSWTool.Win32.RAS.a. Keine Aktion vorgenommen.
~~~~~~~~~~~
~~~~ Offending files
~~~~~~~~~~~
Offending file found: C:\WINDOWS\system32\process.exe
Offending file found: C:\WINDOWS\system32\swreg.exe
Offending file found: C:\WINDOWS\system32\swsc.exe
~~~~~~~~~~~
Ordner
~~~~~~~~~~~
~~~~~~~~~~~
Registry
~~~~~~~~~~~
Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\p3p\history\gator.com !!!
Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C !!!


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Diverses
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Prozesse und Module
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Scanfehler
~~~~~~~~~~~~~~~~~~~~~~
C:\Dokumente und Einstellungen\Rechner\Lokale Einstellungen\Temp\GLB17.tmp nicht gescannt. Wahrscheinlich durch Passwort geschützt...
C:\Dokumente und Einstellungen\Rechner\Lokale Einstellungen\Temp\GLB18.tmp nicht gescannt. Wahrscheinlich durch Passwort geschützt...
C:\Dokumente und Einstellungen\Rechner\Lokale Einstellungen\Temp\SIntf16.dll nicht gescannt. Wahrscheinlich durch Passwort geschützt...
C:\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig709\DEU\Data1.cab nicht gescannt. Wahrscheinlich durch Passwort geschützt...
C:\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig709\DEU_\Data1.cab nicht gescannt. Wahrscheinlich durch Passwort geschützt...
~~~~~~~~~~~~~~~~~~~~~~
Hosts-Datei
~~~~~~~~~~~~~~~~~~~~~~
DataBasePath: %SystemRoot%\System32\drivers\etc
Zeilen die nicht dem Standard entsprechen:
C:\WINDOWS\System32\drivers\etc\hosts :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Gescannte Dateien: 152425
Gefundene Viren: 6
Anzahl der desinfizierten Dateien: 0
Umbenannte Dateien: 0
Anzahl der gelöschten Dateien: 0
Anzahl Fehler: 46
Dauer des Scans bisher: 04:28:12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan-Optionen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Specherüberprüfung: Aktiviert
Registry Überprüfung: Aktiviert
System-Ordner Überprüfung: Aktiviert
Überprüfung der Systembereiche: Deaktiviert
Überprüfung der Dienste: Aktiviert
Überprüfung der Festplatten: Deaktiviert
Überprüfung aller Festplatten :Aktiviert

Batchstart: 20:21:58,25
Batchende: 20:22:03,12
Seitenanfang Seitenende
10.05.2007, 20:49
Moderator

Beiträge: 7805
#4 Noe, ich haette gerne ein Combofix Report, siehe obigen Link! ;)

Aber Escan scan war auch nicht falsch... ;)
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
10.05.2007, 21:38
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#5 @raman
Hé,das meine Viren lol
Offending file found: C:\WINDOWS\system32\process.exe
Offending file found: C:\WINDOWS\system32\swreg.exe
Offending file found: C:\WINDOWS\system32\swsc.exe
__________
MfG Argus
Seitenanfang Seitenende
10.05.2007, 21:39
...neu hier

Themenstarter

Beiträge: 5
#6 jetzt ist aber hoffentlich alles richtig... Keine Ahnung, wieso zuerst immer das Escan Log kam. Sorry.

"Rechner" - 2007-05-10 21:30:51 Service Pack 2
ComboFix 07-05.08.3.V - Running from: "C:\Programme\Mozilla Thunderbird\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\taskmgr.com
C:\setup.exe
C:\WINDOWS\regedit.com


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_IPRIP
-------\LEGACY_NM
-------\nm


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-10 ))))))))))))))))))))))))))))))))))


2007-05-10 20:21 <DIR> d-------- C:\bases_x
2007-05-06 13:13 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-05-06 13:13 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-05-06 10:58 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-05-06 10:58 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-05-06 10:58 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-05-06 10:58 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-05-06 10:58 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-05-06 10:58 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-05-06 10:58 <DIR> d-------- C:\Programme\Spyware Doctor
2007-05-06 10:51 <DIR> d-------- C:\CleanReg3
2007-05-05 06:38 <DIR> d-------- C:\DOKUME~1\ADMINI~1\ANWEND~1\AAV
2007-05-02 04:44 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-05-01 22:04 <DIR> d-------- C:\DOKUME~1\ADMINI~1\ANWEND~1\Talkback
2007-05-01 18:36 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-05-01 18:36 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-05-01 18:36 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-05-01 18:36 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-04-30 08:14 <DIR> d-------- C:\DOKUME~1\Rechner\ANWEND~1\IrfanView
2007-04-29 08:02 <DIR> d-------- C:\DOKUME~1\Rechner\ANWEND~1\AAV
2007-04-29 08:00 <DIR> d-------- C:\Programme\Gemeinsame Dateien\AAV
2007-04-29 08:00 <DIR> d-------- C:\Programme\BILDSteuer
2007-04-22 21:02 <DIR> d-------- C:\pc-bib
2007-04-22 06:11 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\ANWEND~1\WinZip
2007-04-22 06:08 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-04-22 06:08 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-04-22 06:08 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-10 19:30:12 -------- d-----w C:\Programme\Mozilla Thunderbird
2007-05-06 11:09:34 -------- d-----w C:\Programme\Hitman Pro
2007-05-06 09:03:01 -------- d-----w C:\Programme\SpywareBlaster
2007-05-02 13:50:34 67,952 ----a-w C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2007-05-02 02:54:04 -------- d-----w C:\Programme\ShiftN
2007-05-02 02:44:07 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2007-05-02 02:41:04 -------- d--h--w C:\Programme\InstallShield Installation Information
2007-05-02 02:40:19 -------- d-----w C:\Programme\Gemeinsame Dateien\Lexware
2007-05-01 16:25:58 -------- d-----w C:\DOKUME~1\Rechner\ANWEND~1\AdobeUM
2007-04-27 14:47:06 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-04-27 14:47:03 -------- d-----w C:\Programme\PTP2004
2007-04-08 15:30:29 -------- d-----w C:\Programme\Ahead
2007-04-08 15:30:28 -------- d-----w C:\Programme\Gemeinsame Dateien\Ahead
2007-04-08 15:30:23 -------- d-----w C:\Programme\CDBurnerXP Pro
2007-04-08 14:37:19 -------- d-----w C:\Programme\Elaborate Bytes
2007-04-08 12:02:36 -------- d-----w C:\DOKUME~1\Rechner\ANWEND~1\Ahead
2007-04-05 02:54:43 -------- d-----w C:\Programme\HotPotatoes6
2007-04-03 17:53:43 -------- d-----w C:\Programme\xp-AntiSpy
2007-03-31 06:17:39 -------- d-----w C:\Programme\mg11
2007-03-31 06:17:38 -------- d-----w C:\Programme\Gemeinsame Dateien\GIS
2007-03-31 06:17:37 -------- d-----w C:\Programme\Gemeinsame Dateien\mapserv
2007-03-31 05:23:33 -------- d-----w C:\Programme\Webroot
2007-03-31 05:23:33 -------- d-----w C:\DOKUME~1\Rechner\ANWEND~1\Webroot
2007-03-30 10:06:58 -------- d-----w C:\Programme\Common Files
2007-03-28 09:50:26 82,380 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-03-25 04:24:26 84,286 ----a-w C:\WINDOWS\system32\perfc007.dat
2007-03-25 04:24:26 435,486 ----a-w C:\WINDOWS\system32\perfh007.dat
2007-03-17 13:44:25 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:30 579,072 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:30 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:30 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:32:24 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:18:44 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{53707962-6F74-2D53-2644-206D7942484F}"="C:\PROGRA~1\SPYBOT~1\SDHelper.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Programme\Java\jre1.5.0_10\bin\ssv.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nod32kui"="\"C:\\Programme\\Eset\\nod32kui.exe\" /WAITSERVICE"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"SunJavaUpdateSched"="\"C:\\Programme\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"WinFoxV2"="C:\\WINDOWS\\system32\\WF2K.EXE Initial"
"WinFast Schedule"="C:\\Programme\\WinFast\\WFTVFM\\WFWIZ.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"TkBellExe"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=dword:00000000
"SynchronousUserGroupPolicy"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\knc-tonctrl
C:\Programme\Anubis\Typhoon\TonCtrl.EXE /A

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tkbellexe
"C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updatemgr
"C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FAH@C:+Dokumente und Einstellungen+Rechner+Desktop+FAH504-Console.exe"=dword:00000002
"WMPNetworkSvc"=dword:00000003

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HTTPFilter HTTPFilter\0\0
DcomLaunch DcomLaunch\0TermService\0\0
WudfServiceGroup WUDFSvc\0\0

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#7700#MY36H120GKD6.job
C:\WINDOWS\tasks\HP Usg Daily.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-10 21:33:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [1220]

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-10 21:34:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-10 21:34
Seitenanfang Seitenende
10.05.2007, 21:48
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#7 @Georgina
Ich seh im log von ComboFix,Hitmanpro, bei uns in Holland wird dieser scanner stark abgeraten
Schon mal benutzt?
__________
MfG Argus
Seitenanfang Seitenende
10.05.2007, 22:11
Moderator

Beiträge: 7805
#8 Da muessen wir noch 2 Dinge nachschieben. Im Windowsordner befindet sich eine Datei namens catchme. Starte diese und druecke scan danach solltest u auf dem Desktop eine Datei mit Catchme.log finden. Den Inhalt bitte Posten. Mache zusaetzlich bitte noch ein Gmerscan und das Log hier ebenfalls hineinkopieren: http://virus-protect.org/artikel/tools/gmer.html
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
11.05.2007, 05:04
...neu hier

Themenstarter

Beiträge: 5
#9 hallo,

hitmanpro nutze ich regelmäßig; aber auch hier brach er letztens (ohne Meldung) ab.
Wieso ist das Programm nicht empfehlenswert?

Hier nun das "Catchme"-Log:

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-11 04:40:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

und nun das Log von Gmer (Das ist ja wahnsinnig lang und hoffentlich auch das, was Ihr haben wolltet ;-) )

GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-11 04:58:35
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwCreateKey
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwCreateProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwCreateProcessEx
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwDeleteKey
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwDeleteValueKey
SSDT \??\C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwSetValueKey
SSDT \??\C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.12 ----

? C:\WINDOWS\System32\DRIVERS\update.sys

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89BC48FC
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 898152BC
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 898AA5C8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 897ADC2C
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 898AA5C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_NAMED_PIPE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_READ 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_WRITE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FLUSH_BUFFERS 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DIRECTORY_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FILE_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SHUTDOWN 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_LOCK_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLEANUP 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_MAILSLOT 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CHANGE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_NAMED_PIPE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_READ 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_WRITE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_EA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FLUSH_BUFFERS 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_VOLUME_INFORMATION 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DIRECTORY_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FILE_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SHUTDOWN 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_LOCK_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLEANUP 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_MAILSLOT 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_SECURITY 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CHANGE 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_QUOTA 897F4AF8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 897F4AF8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_PNP 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_CREATE 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_CREATE_NAMED_PIPE 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_CLOSE 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_READ 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_WRITE 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_QUERY_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SET_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_QUERY_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SET_EA 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_FLUSH_BUFFERS 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_QUERY_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SET_VOLUME_INFORMATION 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_DIRECTORY_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_FILE_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_INTERNAL_DEVICE_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SHUTDOWN 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_LOCK_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_CLEANUP 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_CREATE_MAILSLOT 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_QUERY_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SET_SECURITY 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_POWER 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SYSTEM_CONTROL 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_DEVICE_CHANGE 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_QUERY_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_SET_QUOTA 898AA5C8
Device \Driver\Cdrom \Device\CdRom5 IRP_MJ_PNP 898AA5C8
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 897173B4
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 897BFCA4
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 897BFCA4
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 8987BBB4
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 898D01D4
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_CREATE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_CREATE_NAMED_PIPE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_CLOSE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_READ 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_WRITE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_QUERY_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SET_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_QUERY_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SET_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_FLUSH_BUFFERS 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_DIRECTORY_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SHUTDOWN 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_LOCK_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_CLEANUP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_CREATE_MAILSLOT 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_QUERY_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SET_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_POWER 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_DEVICE_CHANGE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_QUERY_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_SET_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target3Lun0 IRP_MJ_PNP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_CREATE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_CREATE_NAMED_PIPE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_CLOSE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_READ 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_WRITE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_QUERY_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SET_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_QUERY_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SET_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_FLUSH_BUFFERS 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_QUERY_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SET_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_DIRECTORY_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_FILE_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_INTERNAL_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SHUTDOWN 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_LOCK_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_CLEANUP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_CREATE_MAILSLOT 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_QUERY_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SET_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_POWER 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_DEVICE_CHANGE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_QUERY_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_SET_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1 IRP_MJ_PNP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_CREATE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_CREATE_NAMED_PIPE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_CLOSE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_READ 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_WRITE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_QUERY_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SET_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_QUERY_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SET_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_FLUSH_BUFFERS 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_DIRECTORY_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SHUTDOWN 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_LOCK_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_CLEANUP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_CREATE_MAILSLOT 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_QUERY_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SET_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_POWER 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_DEVICE_CHANGE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_QUERY_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_SET_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target2Lun0 IRP_MJ_PNP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_CREATE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_CLOSE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_READ 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_WRITE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SET_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SET_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SHUTDOWN 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_CLEANUP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SET_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_POWER 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_SET_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target0Lun0 IRP_MJ_PNP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_CREATE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_CREATE_NAMED_PIPE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_CLOSE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_READ 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_WRITE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_QUERY_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SET_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_QUERY_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SET_EA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_FLUSH_BUFFERS 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_DIRECTORY_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SHUTDOWN 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_LOCK_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_CLEANUP 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_CREATE_MAILSLOT 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_QUERY_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SET_SECURITY 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_POWER 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SYSTEM_CONTROL 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_DEVICE_CHANGE 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_QUERY_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_SET_QUOTA 896C7008
Device \Driver\d344prt \Device\Scsi\d344prt1Port2Path0Target1Lun0 IRP_MJ_PNP 896C7008
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 898152BC
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 89B93144
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 89B93144
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 89B93144
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 89B93144
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 89B93144
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 897B544C

---- Modules - GMER 1.0.12 ----

Module _________ F7477000-F748F000 (98304 bytes)

---- EOF - GMER 1.0.12 ----

Vielen Dank nochmals und einen schönen Tag
Georgina
Seitenanfang Seitenende
11.05.2007, 12:47
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#10 @Georgina

HitmanPro
NOD32 ist eine Probe-version von 30Tage
SpySweeper ist eine Probe-version von 7Tage
Spywware Doctor scant nur

Folgende Programme kann man sich sowieso frei runterladen
Ad-Aware SE
Spybot S&D
CWSchredder
SpywareBlaster

Mann hat selbsts entwickelte tools hinzu gefuegt die auch Windows items entfernen koennen

Die automatische up-date's sind natuerlich schoen aber wenn ich z.b Spybot benutze schau ich sowieso ob es updates gibt

Die meisten AntiSpyware Foren(in Holland) unterstuetzen HitmanPro nicht
Und raten HP zu entfernen

Kann es sein,das HP schon laenger als 30tage auf dein Rechner steht?
__________
MfG Argus
Seitenanfang Seitenende
11.05.2007, 16:43
...neu hier

Themenstarter

Beiträge: 5
#11 Danke für Deine Hinweise. Hitmanpro habe ich bereits wesentlich länger als 30 Tage, hatte aber sonst nie Schwierigkeiten damit. Werden denn meine Probleme verschwinden, wenn ich das Programm entferne?
Seitenanfang Seitenende
11.05.2007, 16:53
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#12 Auf jeden fall funktioniert NOD32 nicht mehr also du Surfst ungeschuetzt
Ich geh davon das du mit eScan MWAV meinst?
__________
MfG Argus
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: