![]() |
|
Plagegeister aller Art und deren Bekämpfung: 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #5 |
![]() | ![]() 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet Hallo, danke für die Hilfe soweit. Unten befindet sich das ellenlange Ergebnisprotokoll von GMER. Wie geht es denn jetzt am besten weiter? Danke schon einmal im voraus an alle eifrigen Helfer GMER 1.0.15.14972 - http://www.gmer.net Rootkit scan 2009-07-14 21:22:01 Windows 6.0.6000 ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x8DCD8974] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x8DCE3388] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0x8DCE1166] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0x8DCE1380] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0x8DCE4B9E] SSDT 9B27BEA4 ZwCreateThread SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x8DCD8E54] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x8DCE3C84] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x8DCE3A00] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0x8DCE0F08] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x8DCE3E34] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x8DCD8CEC] SSDT 9B27BE90 ZwOpenProcess SSDT 9B27BE95 ZwOpenThread SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x8DCE4810] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x8DCE4246] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x8DCE4650] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0x8DCDB506] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x8DCD9042] SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x8DCE3706] SSDT 9B27BE9F ZwTerminateProcess SSDT 9B27BE9A ZwWriteVirtualMemory SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateUserProcess [0x8DCE159E] INT 0x51 ? 864A6F00 INT 0x62 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x72 ? 864A6F00 INT 0x82 ? 85614BF8 INT 0x92 ? 85614BF8 INT 0xB3 ? 864A6F00 ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_alloca_probe + 11C 81C5616C 4 Bytes JMP 4F4ED5F2 .text ntoskrnl.exe!_alloca_probe + 12C 81C5617C 4 Bytes [88, 33, CE, 8D] .text ntoskrnl.exe!_alloca_probe + 14C 81C5619C 8 Bytes [66, 11, CE, 8D, 80, 13, CE, ...] .text ntoskrnl.exe!_alloca_probe + 158 81C561A8 4 Bytes JMP 5011002E .text ntoskrnl.exe!_alloca_probe + 164 81C561B4 4 Bytes [A4, BE, 27, 9B] .text ... ? System32\Drivers\spxg.sys Das System kann den angegebenen Pfad nicht finden. ! .text USBPORT.SYS!DllUnload 8B6D7FEB 5 Bytes JMP 864A64E0 .text aqah8k2z.SYS 8C537000 22 Bytes [1A, B2, F9, 81, 04, B1, F9, ...] .text aqah8k2z.SYS 8C537017 145 Bytes [00, 99, 57, 49, 80, A4, 55, ...] .text aqah8k2z.SYS 8C5370A9 35 Bytes [67, C3, 81, 60, 5B, C3, 81, ...] .text aqah8k2z.SYS 8C5370CE 10 Bytes [00, 00, 00, 00, 00, 00, 66, ...] .text aqah8k2z.SYS 8C5370DA 12 Bytes [00, 00, 02, 00, 00, 00, 25, ...] .text ... ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 856132D8 IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice] [82B32C4C] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [82B32CA0] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [82B026D2] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [82B02040] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [82B027FC] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [82B020BE] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [82B0213C] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\system32\drivers\ataport.SYS[ntoskrnl.exe!DbgBreakPoint] 856142D8 IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 864A65E0 IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [82B12048] \SystemRoot\System32\Drivers\spxg.sys IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortNotification] 24488B66 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortUchar] E84D8966 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortUlong] 83E84D8B IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 896602C1 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 488BEA4D IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetScatterGatherList] [8DC80320] \SystemRoot\system32\DRIVERS\rdbss.sys (Redirected Drive Buffering SubSystem Driver/Microsoft Corporation) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortUchar] 57500845 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortStallExecution] F0458D57 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetParentBusType] 00006850 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortRequestCallback] 458DB002 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 35FF50E8 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetUnCachedExtension] [8C55CFBC] \SystemRoot\System32\Drivers\aqah8k2z.SYS (ATAPI IDE Miniport Driver/Microsoft Corporation) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortCompleteRequest] 57EC4D89 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 01F045C7 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] E8000000 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortMoveMemory] 0001E4E4 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortUshort] 4675C73B IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 55CFC8A1 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] [8D526A8C] \SystemRoot\system32\DRIVERS\AGRSM.sys (SoftModem Device Driver/Agere Systems) IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortInitialize] 00009A88 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortGetDeviceBase] 48C08300 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[ataport.SYS!AtaPortDeviceStateChange] 8D076A50 IAT \SystemRoot\System32\Drivers\aqah8k2z.SYS[NTOSKRNL.exe!KeTickCount] 840FF87D IAT \SystemRoot\system32\DRIVERS\storport.sys[ntoskrnl.exe!DbgBreakPoint] 864522D8 IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [8DCD94B6] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [8DCD9590] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [8DCD9416] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8561B1F8 AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) Device \Driver\volmgr \Device\VolMgrControl 856161F8 Device \Driver\usbuhci \Device\USBPDO-0 864491F8 Device \Driver\usbuhci \Device\USBPDO-1 864491F8 Device \Driver\usbehci \Device\USBPDO-2 864461F8 Device \Driver\usbuhci \Device\USBPDO-3 864491F8 Device \Driver\usbuhci \Device\USBPDO-4 864491F8 Device \Driver\usbuhci \Device\USBPDO-5 864491F8 Device \Driver\usbehci \Device\USBPDO-6 864461F8 Device \Driver\volmgr \Device\HarddiskVolume1 856161F8 Device \Driver\volmgr \Device\HarddiskVolume2 856161F8 Device \Driver\cdrom \Device\CdRom0 864511F8 Device \Driver\volmgr \Device\HarddiskVolume3 856161F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8561A1F8 Device \Driver\atapi \Device\Ide\IdePort0 8561A1F8 Device \Driver\atapi \Device\Ide\IdePort1 8561A1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8561A1F8 Device \Driver\cdrom \Device\CdRom1 864511F8 Device \Driver\netbt \Device\NetBt_Wins_Export 8D3E71F8 Device \Driver\Smb \Device\NetbiosSmb 8D3E2500 Device \Driver\PCI_PNP6091 \Device\0000004c spxg.sys Device \Driver\sptd \Device\2125586111 spxg.sys Device \Driver\netbt \Device\NetBT_Tcpip_{EBDEF30A-421D-4F42-8EAF-A478399D7306} 8D3E71F8 Device \Driver\iScsiPrt \Device\RaidPort0 8646A1F8 Device \Driver\BTHUSB \Device\0000006a bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation) Device \Driver\usbuhci \Device\USBFDO-0 864491F8 Device \Driver\usbuhci \Device\USBFDO-1 864491F8 Device \Driver\usbehci \Device\USBFDO-2 864461F8 Device \Driver\usbuhci \Device\USBFDO-3 864491F8 Device \Driver\usbuhci \Device\USBFDO-4 864491F8 Device \Driver\usbuhci \Device\USBFDO-5 864491F8 Device \Driver\netbt \Device\NetBT_Tcpip_{D3419F58-E852-4EF7-91FF-8A0EE0D19495} 8D3E71F8 Device \Driver\usbehci \Device\USBFDO-6 864461F8 Device \Driver\aqah8k2z \Device\Scsi\aqah8k2z1 865A51F8 Device \Driver\aqah8k2z \Device\Scsi\aqah8k2z1Port3Path0Target0Lun0 865A51F8 Device \FileSystem\cdfs \Cdfs 9D9BC1F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0ca0 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0cab Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002783d0ccf Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197efa9e13 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197efa9e13@0018aff3c74c 0xC3 0x1C 0x0B 0x4B ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xFC 0x9C 0x8C 0x92 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0xF8 0x7B 0xD6 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2F 0xAE 0x3B 0x31 ... Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0ca0 Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0cab Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0002783d0ccf Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00197efa9e13 Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\00197efa9e13@0018aff3c74c 0xC3 0x1C 0x0B 0x4B ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xFC 0x9C 0x8C 0x92 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0xF8 0x7B 0xD6 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2F 0xAE 0x3B 0x31 ... ---- EOF - GMER 1.0.15 ---- |
Themen zu 'TR/Redol.B' - hjgruixpeuxtce.dll wird ständig vom Antivir Guard gemeldet |
ander, antivir, antivir guard, c:\windows, datei, folge, folgende, folgenden, gefunde, gemeldet, guard, ignorieren, melde, meldet, meldung, programm, remover, stunde, system, system32, troja, trojan, unerwünschtes programm, verzeichnis, virus, windows |