Trojaner Difisim

#0
20.07.2007, 22:28
...neu hier

Beiträge: 8
#1 Hallo.
AOL PRIVACY CONTROL hat bei mir den Trojaner Difisim gemeldet.
Andere Onlinescanner aber nicht.
Was muss ich jetzt machen?
Danke im voraus
Gruß Oftwasneues
Seitenanfang Seitenende
21.07.2007, 08:26
Moderator

Beiträge: 7805
#2 Wo wird was genau gemeldet?
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
21.07.2007, 08:42
...neu hier

Themenstarter

Beiträge: 8
#3 Hallo!
Sofort, nachdem der PC gestartet wurde!
Seitenanfang Seitenende
21.07.2007, 10:05
Moderator

Beiträge: 7805
#4 Meein Fehler, ich meinte:

Wo= Ordner und Dateiname
Was= Genauer Viren/Trojanername

und poste bitte diese Informationen http://board.protecus.de/t23188.htm
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
21.07.2007, 10:32
...neu hier

Themenstarter

Beiträge: 8
#5 So habs mal versucht, hoffe das alles so richtig ist:

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\_000068_.tmp.dll
C:\WINDOWS\system32\_003257_.tmp.dll
C:\WINDOWS\system32\_003260_.tmp.dll
C:\WINDOWS\system32\_003444_.tmp.dll
C:\WINDOWS\system32\_003447_.tmp.dll
C:\WINDOWS\system32\_003449_.tmp.dll
C:\WINDOWS\system32\_003450_.tmp.dll
C:\WINDOWS\system32\_003451_.tmp.dll
C:\WINDOWS\system32\_003455_.tmp.dll


((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))


2007-07-21 10:39 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-20 22:31 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-07-20 14:47 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\ANWEND~1\ATI
2007-07-02 16:12 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 03:44 8,232,960 --a------ C:\WINDOWS\system32\atioglx2.dll
2007-06-27 03:30 972,072 --a------ C:\WINDOWS\system32\ativva6x.dat
2007-06-27 03:30 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat
2007-06-27 03:14 176,128 --a------ C:\WINDOWS\system32\atiok3x2.dll
2007-06-21 21:14 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-21 14:42 103,720 --a------ C:\WINDOWS\system32\AOLDial.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-20 22:11:56 -------- d-----w C:\Programme\QuickTime
2007-07-20 22:10:55 -------- d-----w C:\Programme\Norton Internet Security
2007-07-20 22:06:23 -------- d-----w C:\Programme\Gemeinsame Dateien\Symantec Shared
2007-07-20 22:06:02 -------- d-----w C:\Programme\Gemeinsame Dateien\Scanner
2007-07-20 22:03:09 -------- d-----w C:\Programme\AOL 9.0 VR
2007-07-20 12:43:53 -------- d-----w C:\Programme\ATI Technologies
2007-07-20 11:06:58 -------- d-----w C:\Programme\PokerStars
2007-07-16 19:46:57 -------- d-----w C:\Programme\Gemeinsame Dateien\aol
2007-07-11 06:39:19 78,360 ----a-w C:\WINDOWS\system32\perfc007.dat
2007-07-11 06:39:19 442,770 ----a-w C:\WINDOWS\system32\perfh007.dat
2007-07-09 19:01:12 -------- d-----w C:\Programme\PokerStars.NET
2007-06-29 19:05:00 520,192 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-06-13 16:11:15 33,592 ----a-w C:\WINDOWS\system32\drivers\atwpkt264.sys
2007-06-13 16:11:10 25,136 ----a-w C:\WINDOWS\system32\drivers\atwpkt2.sys
2007-06-08 19:18:50 2,368 ----a-w C:\WINDOWS\system32\STEC3.sys
2007-06-01 16:52:44 -------- d-----w C:\Programme\Google
2007-05-16 15:11:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-12 13:06:25 56,592 ----a-w C:\DOKUME~1\Standard\ANWEND~1\GDIPFONTCACHEV1.DAT
2007-04-25 14:22:27 144,896 ----a-w C:\WINDOWS\system32\schannel.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
2006-09-05 23:18 93400 -ra------ C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\1.0\NppBho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Programme\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOLDialer"="C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe" [2007-06-21 14:42]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" [2006-10-16 15:15]
"HostManager"="C:\Programme\Gemeinsame Dateien\AOL\1161021605\ee\AOLSoftware.exe" [2006-11-14 15:47]
"InCD"="C:\Programme\Ahead\InCD\InCD.exe" [2006-03-23 18:06]
"TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2006-12-06 11:53]
"Microsoft Works Update Detection"="C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 19:43]
"SSBkgdUpdate"="C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 11:22]
"PaperPort PTD"="C:\Programme\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 17:39]
"IndexSearch"="C:\Programme\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 18:01]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"ccApp"="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Programme\Norton Internet Security\osCheck.exe" [2006-09-05 19:22]
"Symantec PIF AlertEng"="C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
"StartCCC"="C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:57]
"NBJ"="C:\Programme\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 19:25]
"updateMgr"="C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages scecli

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
C:\Programme\Brother\ControlCenter2\brctrcen.exe /autorun

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
C:\Programme\Brother\Brmfl05a\BrStDvPt.exe

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-07-06 18:00:35 C:\WINDOWS\tasks\Norton Internet Security - Vollständige Systemprüfung ausführen - Standard.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-21 10:42:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-21 10:42:47
C:\ComboFix-quarantined-files.txt ... 2007-07-21 10:42

--- E O F ---

Code

2002-08-29 14:00      100352    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003447_.tmp.dll.vir
2002-08-29 14:00      126976    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003444_.tmp.dll.vir
2002-08-29 14:00      262656    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003450_.tmp.dll.vir
2002-08-29 14:00      29184    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003449_.tmp.dll.vir
2002-08-29 14:00      47104    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003257_.tmp.dll.vir
2002-08-29 14:00      557056    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003451_.tmp.dll.vir
2002-08-29 14:00      619008    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003455_.tmp.dll.vir
2002-08-29 14:00      802304    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_003260_.tmp.dll.vir
2004-08-04 00:57      988672    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\_000068_.tmp.dll.vir


Auflistung der Ordnerpfade
C:\QOOBOX
\---Quarantine
    +---C
    |   \---WINDOWS
    |       \---system32
    |               _000068_.tmp.dll.vir
    |               _003257_.tmp.dll.vir
    |               _003260_.tmp.dll.vir
    |               _003444_.tmp.dll.vir
    |               _003447_.tmp.dll.vir
    |               _003449_.tmp.dll.vir
    |               _003450_.tmp.dll.vir
    |               _003451_.tmp.dll.vir
    |               _003455_.tmp.dll.vir
    |              
    \---Registry_backups
Logfile of HijackThis v1.99.1
Scan saved at 10:50:37, on 21.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Gemeinsame Dateien\AOL\1161021605\ee\AOLSoftware.exe
C:\Programme\Ahead\InCD\InCD.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\SEC\Natural Color\NaturalColorLoad.exe
C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Programme\AOL 9.0 VR\waol.exe
C:\Programme\AOL 9.0 VR\shellmon.exe
C:\Programme\Gemeinsame Dateien\AOL\Topspeed\3.0\aoltpsd3.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Programme\Symantec\LiveUpdate\AUPDATE.EXE
C:\Dokumente und Einstellungen\Standard\Desktop\hijackthis_199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://update.microsoft.com/microsoftupdate
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Norton-Symbolleiste anzeigen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [AOLDialer] C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Programme\Gemeinsame Dateien\AOL\1161021605\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [InCD] C:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programme\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programme\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Programme\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NaturalColorLoad.lnk = ?
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/partner/de/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1161012778796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161012757109
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E599366-A7D3-476B-8B30-9E490330970E}: NameServer = 213.191.74.11 213.191.92.82
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Programme\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe

21.07.2007 12:20 2.206 wpa.dbl
20.07.2007 23:32 2.550 Uninstall.ico
20.07.2007 23:32 1.406 Help.ico
11.07.2007 16:59 139.776 swreg.exe
11.07.2007 08:39 427.592 perfh009.dat
11.07.2007 08:39 442.770 perfh007.dat
11.07.2007 08:39 66.376 perfc009.dat
11.07.2007 08:39 78.360 perfc007.dat
11.07.2007 08:39 989.700 PerfStringBackup.INI
29.06.2007 21:05 520.192 ati2sgag.exe
28.06.2007 09:57 16.256.984 MRT.exe
27.06.2007 03:44 8.232.960 atioglx2.dll
27.06.2007 03:30 3.107.788 ativva5x.dat
27.06.2007 03:30 972.072 ativva6x.dat
27.06.2007 03:14 176.128 atiok3x2.dll
21.06.2007 14:42 103.720 AOLDial.dll
08.06.2007 21:18 2.368 STEC3.sys
16.05.2007 17:11 683.520 inetcomm.dll
08.05.2007 10:59 3.583.488 mshtml.dll
07.05.2007 18:22 216.856 FNTCACHE.DAT
05.05.2007 16:24 4.254 jupdate-1.6.0_01-b06.log
25.04.2007 16:22 144.896 schannel.dll
25.04.2007 09:42 822.784 wininet.dll
25.04.2007 09:42 232.960 webcheck.dll
25.04.2007 09:42 1.152.000 urlmon.dll
25.04.2007 09:42 105.984 url.dll
25.04.2007 09:42 102.400 occache.dll
25.04.2007 09:42 670.720 mstime.dll
25.04.2007 09:42 193.024 msrating.dll
25.04.2007 09:42 477.696 mshtmled.dll
25.04.2007 09:41 52.224 msfeedsbs.dll
25.04.2007 09:41 459.264 msfeeds.dll
25.04.2007 09:41 27.648 jsproxy.dll
25.04.2007 09:41 1.824.768 inetcpl.cpl
25.04.2007 09:41 267.776 iertutil.dll
25.04.2007 09:41 6.058.496 ieframe.dll
25.04.2007 09:41 44.544 iernonce.dll
25.04.2007 09:41 384.512 iedkcs32.dll
25.04.2007 09:41 383.488 ieapfltr.dll
25.04.2007 09:41 124.928 advpack.dll
25.04.2007 09:41 153.088 ieakeng.dll
25.04.2007 09:41 132.608 extmgr.dll
25.04.2007 09:41 230.400 ieaksie.dll
24.04.2007 16:26 13.824 ieudinit.exe
24.04.2007 11:58 56.832 ie4uinit.exe
24.04.2007 11:32 1.485.696 LegitCheckControl.dll
24.04.2007 09:34 161.792 ieakui.dll
18.04.2007 18:13 2.854.400 msi.dll
17.04.2007 11:32 2.455.488 ieapfltr.dat
16.04.2007 22:47 33.624 wups.dll
16.04.2007 22:47 30.040 wuapi.dll.mui
16.04.2007 22:47 30.040 wuaucpl.cpl.mui
16.04.2007 22:45 1.710.936 wuaueng.dll
16.04.2007 22:45 549.720 wuapi.dll
16.04.2007 22:45 325.976 wucltui.dll
16.04.2007 22:45 216.408 wuaucpl.cpl
16.04.2007 22:45 203.096 wuweb.dll
16.04.2007 22:45 92.504 cdm.dll
16.04.2007 22:45 53.080 wuauclt.exe
16.04.2007 22:45 43.352 wups2.dll
16.04.2007 22:45 20.824 wuaueng.dll.mui
16.04.2007 22:44 34.136 wucltui.dll.mui
16.04.2007 22:44 271.224 mucltui.dll
16.04.2007 22:44 208.248 muweb.dll
16.04.2007 22:44 30.072 mucltui.dll.mui
16.04.2007 17:53 1.058.304 kernel32.dll
13.04.2007 13:17 48.776 S32EVNT1.DLL
13.04.2007 10:09 100 LuResult.txt
13.04.2007 03:21 271.360 mscoree.dll
Dieser Beitrag wurde am 21.07.2007 um 13:34 Uhr von OftWasNeues editiert.
Seitenanfang Seitenende
21.07.2007, 15:22
Moderator

Beiträge: 7805
#6 Was befindet sich in diesem Ordner:
C:\WINDOWS\system32\Kaspersky Lab


Mache bitte auch einen Kontrollscan mit Drweb und Ewido micro:

http://freedrweb.com/?lng=de (nimm aber diesen Download: ftp://ftp.drweb.com/pub/drweb/cureit/cureit-beta.exe )

http://downloads.ewido.net/ewido_micro.exe
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
21.07.2007, 20:14
...neu hier

Themenstarter

Beiträge: 8
#7 In dem Ordner war was von dem Onlinescan. Als ich den Kaspersky Online Scanner deinstalliert habe, war auch der Ordner verschwunden.
Die beiden Scans waren auch ergebnislos!
Seitenanfang Seitenende
21.07.2007, 20:48
Moderator

Beiträge: 7805
#8 Das sieht laut log, bis auf ein /zwei kleinen Harmlosen DAteien sauber aus. Du koenntest aber noch einen scan mit Gmer machen. Vieleicht versteckt sich noch irgendwo ein Rootkit.


http://www.virus-protect.org/artikel/tools/gmer.html
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
21.07.2007, 21:58
...neu hier

Themenstarter

Beiträge: 8
#9 Habe den Scan gemacht, aber hab keine Ahnung davon:

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-21 21:54:30
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT 893E8C10 ZwAlertResumeThread
SSDT 893EA100 ZwAlertThread
SSDT 8950EAA8 ZwAllocateVirtualMemory
SSDT 895B7958 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey
SSDT 893E7968 ZwCreateMutant
SSDT 895992F8 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey
SSDT 89411FD0 ZwFreeVirtualMemory
SSDT 893E8A60 ZwImpersonateAnonymousToken
SSDT 893E8B38 ZwImpersonateThread
SSDT 893AD2D0 ZwMapViewOfSection
SSDT 893E10B8 ZwOpenEvent
SSDT 894A7C20 ZwOpenProcessToken
SSDT 893F3980 ZwOpenThreadToken
SSDT 8939D508 ZwResumeThread
SSDT 893F38A8 ZwSetContextThread
SSDT 893F62C0 ZwSetInformationProcess
SSDT 893F26A0 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey
SSDT 893DDC30 ZwSuspendProcess
SSDT 893EA838 ZwSuspendThread
SSDT 8926A4A8 ZwTerminateProcess
SSDT 893EA9B0 ZwTerminateThread
SSDT 894A3610 ZwUnmapViewOfSection
SSDT 894DE2B8 ZwWriteVirtualMemory

---- Kernel IAT/EAT - GMER 1.0.13 ----

IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F789C4FE] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F789C52C] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRequest] [F789C54E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F789C20E] PDDSLHND.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F789C256] PDDSLHND.sys

---- User IAT/EAT - GMER 1.0.13 ----

IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\psapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLacsd.exe[2328] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll
IAT C:\Programme\AOL 9.0 VR\waol.exe[2720] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll

---- Devices - GMER 1.0.13 ----

Device \Ntfs IRP_MJ_CREATE [F7B77C01] Ntfs.sys
Device \Ntfs IRP_MJ_CLOSE [F7B770EA] Ntfs.sys
Device \Ntfs IRP_MJ_READ [F7B54F3B] Ntfs.sys
Device \Ntfs IRP_MJ_WRITE [F7B53B57] Ntfs.sys
Device \Ntfs IRP_MJ_QUERY_INFORMATION [F7B782B9] Ntfs.sys
Device \Ntfs IRP_MJ_SET_INFORMATION [F7B55618] Ntfs.sys
Device \Ntfs IRP_MJ_QUERY_EA [F7B782B9] Ntfs.sys
Device \Ntfs IRP_MJ_SET_EA [F7B782B9] Ntfs.sys
Device \Ntfs IRP_MJ_FLUSH_BUFFERS [F7B91EC8] Ntfs.sys
Device \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F7B78404] Ntfs.sys
Device \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F7B78404] Ntfs.sys
Device \Ntfs IRP_MJ_DIRECTORY_CONTROL [F7B79FBD] Ntfs.sys
Device \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F7B7C758] Ntfs.sys
Device \Ntfs IRP_MJ_DEVICE_CONTROL [F7B78404] Ntfs.sys
Device \Ntfs IRP_MJ_SHUTDOWN [F7B665AF] Ntfs.sys
Device \Ntfs IRP_MJ_LOCK_CONTROL [F7BCBAA3] Ntfs.sys
Device \Ntfs IRP_MJ_CLEANUP [F7B77AB8] Ntfs.sys
Device \Ntfs IRP_MJ_QUERY_SECURITY [F7B78404] Ntfs.sys
Device \Ntfs IRP_MJ_SET_SECURITY [F7B78404] Ntfs.sys
Device \Ntfs IRP_MJ_QUERY_QUOTA [F7B782B9] Ntfs.sys
Device \Ntfs IRP_MJ_SET_QUOTA [F7B782B9] Ntfs.sys
Device \Ntfs IRP_MJ_PNP [F7B947F0] Ntfs.sys
Device \Ntfs FastIoCheckIfPossible [F7B8BEDA] Ntfs.sys
Device \Ntfs FastIoRead [F7B72B57] Ntfs.sys
Device \Ntfs FastIoWrite [F7B91448] Ntfs.sys
Device \Ntfs FastIoQueryBasicInfo [F7B7848E] Ntfs.sys
Device \Ntfs FastIoQueryStandardInfo [F7B76F7E] Ntfs.sys
Device \Ntfs FastIoLock [F7B920F2] Ntfs.sys
Device \Ntfs FastIoUnlockSingle [F7B921F8] Ntfs.sys
Device \Ntfs FastIoUnlockAll [F7BCB6AE] Ntfs.sys
Device \Ntfs FastIoUnlockAllByKey [F7BCB7F3] Ntfs.sys
Device \Ntfs AcquireFileForNtCreateSection [F7B7283A] Ntfs.sys
Device \Ntfs ReleaseFileForNtCreateSection [F7B72881] Ntfs.sys
Device \Ntfs FastIoQueryNetworkOpenInfo [F7BB9E1D] Ntfs.sys
Device \Ntfs AcquireForModWrite [F7B7EA10] Ntfs.sys
Device \Ntfs MdlRead [F7BB9F31] Ntfs.sys
Device \Ntfs PrepareMdlWrite [F7BBA2AB] Ntfs.sys
Device \Ntfs FastIoQueryOpen [F7B76DB8] Ntfs.sys
Device \Ntfs AcquireForCcFlush [F7B726E2] Ntfs.sys
Device \Ntfs ReleaseForCcFlush [F7B72708] Ntfs.sys

AttachedDevice \Ntfs IRP_MJ_CREATE [F74AF1DE] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F74AF1DE] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_CLOSE [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_READ [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_WRITE [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_QUERY_INFORMATION [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SET_INFORMATION [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_QUERY_EA [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SET_EA [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_FLUSH_BUFFERS [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_DIRECTORY_CONTROL [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F74AF454] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_DEVICE_CONTROL [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SHUTDOWN [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_LOCK_CONTROL [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_CLEANUP [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_CREATE_MAILSLOT [F74AF1DE] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_QUERY_SECURITY [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SET_SECURITY [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_POWER [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SYSTEM_CONTROL [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_DEVICE_CHANGE [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_QUERY_QUOTA [F74A2F4C] fltmgr.sys
AttachedDevice \Ntfs IRP_MJ_SET_QUOTA [F74A2F4C] fltmgr.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_READ [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_POWER [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_READ [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_READ [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_POWER [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_READ [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_POWER [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA [B12CC180] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA [B12CC180] SYMTDI.SYS

Device \Device\LanmanRedirector IRP_MJ_CREATE [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CLOSE [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_READ [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_WRITE [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_INFORMATION [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_EA [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_EA [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION [B114B189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION [B114B189] mrxsmb.sys
Device \Device\LanmanRedirec
Seitenanfang Seitenende
22.07.2007, 07:53
Moderator

Beiträge: 7805
#10 Das sieht "normal" aus.
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: