![]() |
|
Log-Analyse und Auswertung: virus C:\SYS...\_RESTORE{08021......6CEEA}\RP811\A0237606.EXE (Nicht bereinigt & Übermittelt)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 | |
| ![]() virus C:\SYS...\_RESTORE{08021......6CEEA}\RP811\A0237606.EXE (Nicht bereinigt & Übermittelt) Hallo, ich habe bei mir ein Problem mit solchen Dateien wie im Titel genannt. Diese wurde jetzt vom f-secure-online-scanner gefunden und konnte nicht bereinigt werden. Die Dateien tauchen immer wieder auf, manchmal sind es mehrere, sie unterscheiden sich immer wieder etwas in der Ziffernzusammenstellung, sollen sie dann gelöscht werden, meldet z.B. Antivir die Datei sei nicht vorhanden. Es funktioniert alles, aber es beunruhigt mich halt doch. Ich habe mal einen Scan mit GMER laufen lassen, vieleicht hilft das jemanden weiter? Ich kenn mich selbst mit solchen Problemen nicht wirklich gut aus. Das System ist Windows XP. Also nochmal die Meldung von f.secure: Zitat:
GMER Logfile: Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-07-06 15:19:56 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0 SAMSUNG_ rev.1AJ1 Running: ri6r23i1.exe; Driver: C:\DOKUME~1\Metz\LOKALE~1\Temp\pgliqpoc.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeKey [0xB269E004] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeMultipleKeys [0xB269E0D4] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB269DD76] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB269DE1E] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB269DEBA] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB269DF56] ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB62B9380, 0x566465, 0xE8000020] ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs avgidsfilterx.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. ) AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications@ Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@GathererPlugin Search.Gatherer Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@ApplicationPath C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Search\Data\Applications\Windows\ Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@DefaultProjectPath C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Search\Data\Applications\Windows\Projects Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@DefaultCatalogConfigUrl Software\Microsoft\Windows Search Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@GatherLogsPath C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Search\Data\Applications\Windows\GatherLogs Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@DisplayName Windows Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@DataTimeout 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@ConnectTimeout 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@RetryLimit 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@UseClustering 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@FilterSecurity 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@AccessControl 0x99 0xCA 0xBA 0xDE ... Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@CrawlScopeVersion 119 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@DeletedCountSync 90 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@SingleInstancing 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@UseIncrementalCrawlDirIter 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows@UseHostHitTiming 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\0@ProgId Search.JetPropStore Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\1@ProgId Search.TripoliIndexer Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\2 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\2@ProgId Search.MapPI Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex@WorkingDirectory C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex@LazyLoad 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex@CrawlInterval 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex@AccessControl 0x99 0xCA 0xBA 0xDE ... Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins@NewPluginIdentifier 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0@ProgId Search.MapPI Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0@CreationFlags 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0@PluginIdentifier 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0@Disabled 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins@NewPluginIdentifier 2 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0@ProgId Search.JetPropStore Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0@CreationFlags 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0@PluginIdentifier 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0@Disabled 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1@ProgId Search.TripoliIndexer Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1@CreationFlags 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1@PluginIdentifier 1 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1@Disabled 0 Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\ProtocolManagers Reg HKLM\SOFTWARE\Classes\Applications\Quote.exe\shell\open Reg HKLM\SOFTWARE\Classes\Applications\Quote.exe\shell\open\command Reg HKLM\SOFTWARE\Classes\Applications\Quote.exe\shell\open\command@ C:\PROGRA~1\AMIBRO~1\AmiQuote\Quote.exe "%1" Reg HKLM\SOFTWARE\Classes\Applications\Quote.exe\shell\print Reg HKLM\SOFTWARE\Classes\Applications\Quote.exe\shell\printto ---- Files - GMER 1.0.15 ---- File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\ComDb.Dat 22672 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\domain.txt 44 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository 0 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS 0 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\INDEX.BTR 1744896 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\INDEX.MAP 908 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\MAPPING1.MAP 11468 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\MAPPING2.MAP 11468 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\OBJECTS.DATA 21635072 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\Repository\FS\OBJECTS.MAP 10592 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_MACHINE_SAM 28672 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_MACHINE_SECURITY 49152 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_MACHINE_SOFTWARE 33808384 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_MACHINE_SYSTEM 4632576 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_.DEFAULT 4894720 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_NTUSER_S-1-5-18 4894720 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_NTUSER_S-1-5-19 237568 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_NTUSER_S-1-5-20 380928 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_NTUSER_S-1-5-21-329068152-2077806209-725345543-1003 6553600 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_NTUSER_S-1-5-21-329068152-2077806209-725345543-1004 10248192 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{08021CEB-3068-4061-8826-55638B66CEEA}\Fifoed(2)\snapsho\_REGISTRY_USER_USRCLASS_S-1-5-21-329068152-2077806209-725345543-1004 1220608 bytes ---- EOF - GMER 1.0.15 ----[/QUOTE] Geändert von rk17 (06.07.2012 um 14:43 Uhr) Grund: System |
Themen zu virus C:\SYS...\_RESTORE{08021......6CEEA}\RP811\A0237606.EXE (Nicht bereinigt & Übermittelt) |
antivir, code, dateien, driver, driver./avg, einstellungen, funktioniert, gelöscht, gmer, harddisk, log, malware, microsoft, monitor, port, problem, probleme, registry, service pack 3, software, system, system volume information, system32, temp, udp, virus |