|
Log-Analyse und Auswertung: Trojaner an BoardWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.12.2011, 10:49 | #1 |
| Trojaner an Board Guten Morgen zusammen!ich erhalte eine Meldung ihr System ist ausgelastet.dann öffnet sich ein Fenster und nichts geht mehr.Ich soll irgendeine Summe zahlen.Mein Virenscanner Antivir wurde gestoppt.ich habe Windows 2000 Professional.Würde mich über Hilfe freuen.gruss seifi Hier noch ein AnhangOTL Logfile: Code:
ATTFilter OTL logfile created on: 27.12.2011 10:17:38 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation Internet Explorer (Version = 6.0.2800.1106) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 895,23 Mb Total Physical Memory | 783,85 Mb Available Physical Memory | 87,56% Memory free 2,14 Gb Paging File | 2,07 Gb Available in Paging File | 96,66% Paging File free Paging file location(s): C:\pagefile.sys 1344 2688 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Programme Drive C: | 74,52 Gb Total Space | 65,17 Gb Free Space | 87,45% Space Free | Partition Type: NTFS Computer Name: AP-SEIFERT | User Name: Seifert | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.12.27 10:15:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner\OTL.exe PRC - [2003.06.19 11:05:04 | 000,245,008 | ---- | M] (Microsoft Corporation) -- C:\WINNT\explorer.exe PRC - [2003.06.19 11:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\wbem\WinMgmt.exe ========== Modules (No Company Name) ========== MOD - [2008.05.02 05:15:37 | 000,010,240 | ---- | M] () -- C:\Programme\Unlocker\UnlockerCOM.dll MOD - [2007.11.09 04:52:00 | 000,466,944 | ---- | M] () -- C:\WINNT\system32\nvshell.dll ========== Win32 Services (SafeList) ========== SRV - [2011.06.29 12:29:16 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.28 09:25:34 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008.02.04 13:37:12 | 000,413,746 | ---- | M] (SafeNet) [Auto | Stopped] -- C:\Programme\Juniper\NetScreen-Remote\IreIKE.exe -- (IreIKE) SRV - [2008.02.04 13:37:12 | 000,073,782 | ---- | M] (SafeNet) [Auto | Stopped] -- C:\Programme\Juniper\NetScreen-Remote\IPSecMon.exe -- (IPSECMON) SRV - [2005.06.03 07:37:10 | 000,123,152 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINNT\system32\mstask.exe -- (Schedule) SRV - [2005.03.15 12:14:42 | 000,041,984 | ---- | M] (Advanced Micro Devices) [Auto | Stopped] -- C:\Programme\AMD\Cool'n'Quiet\GemServ.exe -- (GemServ) AMD PowerNow! (tm) SRV - [2003.07.28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2003.06.19 11:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\wbem\WinMgmt.exe -- (WinMgmt) SRV - [2003.06.19 11:05:04 | 000,147,728 | ---- | M] (VERITAS Software Corp.) [On_Demand | Stopped] -- C:\WINNT\System32\dmadmin.exe -- (dmadmin) SRV - [2003.06.19 11:05:04 | 000,096,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\FAXSVC.EXE -- (Fax) SRV - [2003.06.19 11:05:04 | 000,068,368 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINNT\system32\regsvc.exe -- (RemoteRegistry) SRV - [2003.06.19 11:05:04 | 000,022,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\utilman.exe -- (UtilMan) ========== Driver Services (SafeList) ========== DRV - [2011.06.29 12:29:17 | 000,135,896 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\avipbb.sys -- (avipbb) DRV - [2011.06.29 12:29:17 | 000,078,216 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINNT\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2010.07.07 10:16:20 | 000,058,000 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\System32\drivers\cdr4_2K.sys -- (Cdr4_2K) DRV - [2010.07.07 10:16:20 | 000,023,420 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\System32\drivers\cdralw2k.sys -- (Cdralw2k) DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.02.13 10:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008.02.04 13:29:14 | 000,138,296 | ---- | M] (SafeNet) [Kernel | System | Running] -- C:\WINNT\system32\drivers\IpSecDrv.sys -- (IPSECDRV) DRV - [2008.01.17 10:35:44 | 000,536,634 | ---- | M] (SafeNet) [Kernel | Auto | Stopped] -- C:\WINNT\system32\drivers\Crypto.sys -- (Crypto) DRV - [2008.01.02 15:48:32 | 000,029,184 | ---- | M] (Deterministic Networks Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\vapnt.sys -- (DniVap) SafeNet WAN Miniport (VA) DRV - [2007.09.07 08:40:46 | 000,128,144 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\dne2000.sys -- (DNE) DRV - [2007.03.06 11:27:32 | 000,019,968 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2007.03.06 11:27:24 | 000,055,168 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2007.02.16 07:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\nvsmu.sys -- (nvsmu) DRV - [2006.11.03 08:32:30 | 004,394,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2004.07.09 01:58:10 | 000,015,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\mpe.sys -- (MPE) DRV - [2003.10.29 10:54:24 | 000,011,456 | R--- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\gemwdm.sys -- (gemwdm) AMD PowerNow! (tm) DRV - [2003.06.19 11:05:04 | 000,369,104 | ---- | M] (VERITAS Software Corp.) [Kernel | Disabled | Stopped] -- C:\WINNT\system32\drivers\dmboot.sys -- (dmboot) DRV - [2003.06.19 11:05:04 | 000,137,936 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmio.sys -- (dmio) DRV - [2003.06.19 11:05:04 | 000,060,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\parallel.sys -- (Parallel) DRV - [2003.06.19 11:05:04 | 000,049,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\usbhub20.sys -- (usbhub20) DRV - [2003.06.19 11:05:04 | 000,027,440 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINNT\System32\drivers\efs.sys -- (EFS) DRV - [2003.06.19 11:05:04 | 000,024,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\openhci.sys -- (openhci) DRV - [2003.06.19 11:05:04 | 000,009,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\gameenum.sys -- (gameenum) DRV - [2003.06.19 11:05:04 | 000,007,728 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\diskperf.sys -- (Diskperf) DRV - [2003.06.19 11:05:04 | 000,007,312 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmload.sys -- (dmload) DRV - [2003.01.06 15:27:46 | 000,040,448 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\WINNT\system32\drivers\DgivEcp.sys -- (DgivEcp) DRV - [2002.07.24 13:00:00 | 000,021,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\rca.sys -- (RCA) Microsoft Streaming Network-RCA (Raw Channel Access) DRV - [2002.07.24 13:00:00 | 000,009,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\netdtect.sys -- (NetDetect) DRV - [1999.10.19 14:27:30 | 000,029,968 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\avmwan.sys -- (AVMWAN) DRV - [1999.09.24 19:17:30 | 000,387,440 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\fpcibase.sys -- (fpcibase) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.autohaus.de/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.autohaus.de/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.11.10 12:50:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.06.16 14:41:01 | 000,000,000 | ---D | M] [2009.10.21 12:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Mozilla\Extensions [2009.10.21 12:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Mozilla\Firefox\Profiles\parh2s40.default\extensions [2011.11.10 12:50:38 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2011.11.10 12:50:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2011.10.06 11:57:48 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.10.06 11:57:48 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2011.10.06 11:57:48 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2011.10.06 11:57:48 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.06 11:57:48 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.06 11:57:48 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2002.07.24 13:00:00 | 000,000,820 | ---- | M]) - C:\WINNT\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1031,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx (Microsoft Corporation) O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Alcmtr] C:\WINNT\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [FreePDFAssistent] C:\Programme\FreePDF\FreePDFA.exe (shbox) O4 - HKLM..\Run: [NvCplDaemon] C:\WINNT\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINNT\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINNT\System32\nwiz.exe () O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [UnlockerAssistant] C:\Programme\Unlocker\UnlockerAssistant.exe () O4 - HKCU..\Run: [{0B803606-B754-11DE-823B-806D6172696F}] C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe (Mozilla Foundation) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\NetScreen-Remote.lnk = C:\Programme\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet) O4 - Startup: C:\Dokumente und Einstellungen\Seifert\Startmenü\Programme\Autostart\Telefon- und Branchenbuch Sommer 2009 - Schnellstarter.lnk = C:\Programme\klickTel\Telefon- und Branchenbuch Sommer 2009\KSTART32.EXE (telegate MEDIA AG) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0 O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM () O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINNT\system32\RNR20.DLL (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\msafd.dll (Microsoft Corporation) O15 - HKCU\..Trusted Domains: leaseplango-partner.de ([autohaus] http in Vertrauenswürdige Sites) O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255365661000 (WUWebControl Class) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {B9BE4AC6-505E-480F-BAC1-35512FBA992F} hxxp://80.139.191.100/eDVR.cab (EFOcx Control) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D1F21B75-F3D2-4A44-9278-BFB70DC7B9F9}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream - No CLSID value found O18 - Protocol\Filter\application/x-complus - No CLSID value found O18 - Protocol\Filter\application/x-msdownload - No CLSID value found O18 - Protocol\Filter\Class Install Handler - No CLSID value found O18 - Protocol\Filter\deflate - No CLSID value found O18 - Protocol\Filter\gzip - No CLSID value found O18 - Protocol\Filter\lzdhtml - No CLSID value found O18 - Protocol\Filter\text/webviewhtml - No CLSID value found O18 - Protocol\Filter\text/xml - No CLSID value found O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\USERINIT.EXE (Microsoft Corporation) O20 - Winlogon\Notify\wzcnotif: DllName - (wzcdlg.dll) - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.10.12 16:58:15 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.12.27 10:14:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Neuer Ordner [2011.12.27 09:53:27 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\otl [2011.12.27 09:50:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\defogger [2011.12.17 11:27:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Lagerliste Handweiser [2011.12.12 16:43:08 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Seifert\Desktop\Kontaktdaten Mastrangelo [2009.10.13 10:14:17 | 000,018,944 | ---- | C] ( ) -- C:\WINNT\System32\implode.dll [4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ] [1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.27 10:08:21 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_448.dat [2011.12.27 10:07:59 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2ac.dat [2011.12.27 09:56:18 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Seifert\defogger_reenable [2011.12.23 18:12:49 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2b0.dat [2011.12.23 17:58:37 | 000,000,226 | -HS- | M] () -- C:\boot.ini [2011.12.23 17:04:02 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2a8.dat [2011.12.23 11:32:01 | 000,000,940 | ---- | M] () -- C:\WINNT\FBAReg.ini [2011.12.22 15:12:21 | 000,000,316 | ---- | M] () -- C:\WINNT\ktel.ini [2011.12.20 13:41:20 | 000,002,706 | ---- | M] () -- C:\WINNT\SSDS32.INI [2011.12.20 13:38:07 | 000,000,024 | ---- | M] () -- C:\WINNT\ssnew01.ini [2011.12.19 09:25:23 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_2c0.dat [4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ] [1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.27 10:08:21 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_448.dat [2011.12.27 10:07:59 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2ac.dat [2011.12.27 09:56:18 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Seifert\defogger_reenable [2011.12.23 18:12:49 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2b0.dat [2011.12.23 17:04:02 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2a8.dat [2011.12.19 09:25:23 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2c0.dat [2011.11.05 09:10:14 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2c4.dat [2011.08.19 08:08:43 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_2b8.dat [2011.07.18 13:49:37 | 000,143,360 | ---- | C] () -- C:\WINNT\System32\nsldap32v50.dll [2011.02.07 13:06:12 | 000,000,024 | ---- | C] () -- C:\WINNT\ssnew01.ini [2010.09.02 13:54:58 | 000,102,400 | ---- | C] () -- C:\WINNT\DLL2KUSB.DLL [2010.09.02 13:54:58 | 000,098,304 | ---- | C] () -- C:\WINNT\DLL32.DLL [2010.09.02 13:54:58 | 000,048,176 | ---- | C] () -- C:\WINNT\Imp16d20.dll [2010.09.02 13:54:58 | 000,045,056 | ---- | C] () -- C:\WINNT\System32\USBPRN.DLL [2010.09.02 13:54:58 | 000,045,056 | ---- | C] () -- C:\WINNT\System32\SCANX.DLL [2010.09.02 13:54:57 | 000,135,104 | ---- | C] () -- C:\WINNT\Tab16d20.dll [2010.09.02 13:54:57 | 000,028,672 | ---- | C] () -- C:\WINNT\SSTHUNK.DLL [2010.09.02 13:54:57 | 000,024,576 | ---- | C] () -- C:\WINNT\NTFAX.EXE [2010.09.02 13:54:57 | 000,012,800 | ---- | C] () -- C:\WINNT\SS16FT.DLL [2010.09.02 13:54:57 | 000,011,079 | ---- | C] () -- C:\WINNT\LxUsbOpn.dll [2010.09.02 13:54:57 | 000,002,706 | ---- | C] () -- C:\WINNT\SSDS32.INI [2010.09.02 13:54:57 | 000,002,554 | ---- | C] () -- C:\WINNT\SSDS16.INI [2010.09.02 13:54:57 | 000,002,269 | ---- | C] () -- C:\WINNT\SSDEF32.INI [2010.09.02 13:54:57 | 000,002,267 | ---- | C] () -- C:\WINNT\SSDEF16.INI [2010.09.02 13:54:57 | 000,000,051 | ---- | C] () -- C:\WINNT\MyScan.ini [2010.09.02 13:54:54 | 000,094,208 | ---- | C] () -- C:\WINNT\System32\getpntid.exe [2010.07.07 10:09:21 | 000,354,816 | ---- | C] () -- C:\WINNT\System32\psisdecd.dll [2009.10.21 12:15:33 | 000,000,000 | ---- | C] () -- C:\WINNT\nsreg.dat [2009.10.20 13:51:30 | 000,000,063 | ---- | C] () -- C:\WINNT\mdm.ini [2009.10.20 10:15:34 | 000,000,316 | ---- | C] () -- C:\WINNT\ktel.ini [2009.10.13 10:14:56 | 000,000,052 | ---- | C] () -- C:\WINNT\favreg.ini [2009.10.13 10:14:54 | 000,053,248 | ---- | C] () -- C:\WINNT\System32\zlib.dll [2009.10.13 10:14:20 | 000,000,197 | ---- | C] () -- C:\WINNT\lmicddl4.ini [2009.10.13 10:14:19 | 000,210,944 | ---- | C] () -- C:\WINNT\System32\msvcrt10.dll [2009.10.13 10:14:16 | 000,775,168 | ---- | C] () -- C:\WINNT\System32\corent23.dll [2009.10.13 10:14:16 | 000,613,376 | ---- | C] () -- C:\WINNT\System32\corent.dll [2009.10.13 10:14:07 | 002,281,472 | ---- | C] () -- C:\WINNT\System32\micCrypt.dll [2009.10.13 10:14:07 | 000,494,080 | ---- | C] () -- C:\WINNT\System32\HyperZIP.dll [2009.10.13 10:13:59 | 000,000,940 | ---- | C] () -- C:\WINNT\FBAReg.ini [2009.10.12 18:31:37 | 000,000,919 | ---- | C] () -- C:\WINNT\ODBC.INI [2009.10.12 17:50:30 | 000,041,232 | ---- | C] () -- C:\WINNT\System32\capi2032.dll [2009.10.12 17:49:45 | 000,004,073 | ---- | C] () -- C:\WINNT\ODBCINST.INI [2009.10.12 17:49:17 | 000,095,072 | ---- | C] () -- C:\WINNT\System32\FNTCACHE.DAT [2009.10.12 17:36:04 | 000,049,152 | ---- | C] () -- C:\WINNT\System32\ChCfg.exe [2009.10.12 17:24:56 | 000,001,732 | ---- | C] () -- C:\WINNT\System32\drivers\nvphy.bin [2009.10.12 17:22:36 | 001,626,112 | ---- | C] () -- C:\WINNT\System32\nwiz.exe [2009.10.12 17:22:32 | 001,019,904 | ---- | C] () -- C:\WINNT\System32\nvwimg.dll [2009.10.12 17:22:31 | 001,703,936 | ---- | C] () -- C:\WINNT\System32\nvwdmcpl.dll [2009.10.12 17:22:24 | 000,466,944 | ---- | C] () -- C:\WINNT\System32\nvshell.dll [2009.10.12 17:22:19 | 000,286,720 | ---- | C] () -- C:\WINNT\System32\nvnt4cpl.dll [2009.10.12 17:22:14 | 001,474,560 | ---- | C] () -- C:\WINNT\System32\nview.dll [2009.10.12 17:22:10 | 001,339,392 | ---- | C] () -- C:\WINNT\System32\nvdspsch.exe [2009.10.12 17:21:46 | 000,442,368 | ---- | C] () -- C:\WINNT\System32\nvappbar.exe [2009.10.12 17:21:37 | 000,425,984 | ---- | C] () -- C:\WINNT\System32\keystone.exe [2009.10.12 16:57:52 | 000,022,080 | -H-- | C] () -- C:\Programme\folder.htt [2009.10.12 16:57:24 | 000,015,076 | ---- | C] () -- C:\WINNT\System32\emptyregdb.dat [2003.02.20 16:53:42 | 000,005,702 | ---- | C] () -- C:\WINNT\System32\OUTLPERF.INI [2002.07.24 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINNT\System32\mlang.dat [2002.07.24 13:00:00 | 000,398,006 | ---- | C] () -- C:\WINNT\System32\perfh009.dat [2002.07.24 13:00:00 | 000,397,680 | ---- | C] () -- C:\WINNT\System32\perfh007.dat [2002.07.24 13:00:00 | 000,272,492 | ---- | C] () -- C:\WINNT\System32\perfi009.dat [2002.07.24 13:00:00 | 000,252,934 | ---- | C] () -- C:\WINNT\System32\perfi007.dat [2002.07.24 13:00:00 | 000,217,359 | ---- | C] () -- C:\WINNT\System32\dssec.dat [2002.07.24 13:00:00 | 000,176,400 | ---- | C] () -- C:\WINNT\System32\qcut.dll [2002.07.24 13:00:00 | 000,076,000 | ---- | C] () -- C:\WINNT\System32\perfc007.dat [2002.07.24 13:00:00 | 000,062,416 | ---- | C] () -- C:\WINNT\System32\perfc009.dat [2002.07.24 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINNT\System32\mib.bin [2002.07.24 13:00:00 | 000,034,108 | ---- | C] () -- C:\WINNT\System32\perfd007.dat [2002.07.24 13:00:00 | 000,034,064 | ---- | C] () -- C:\WINNT\System32\efsadu.dll [2002.07.24 13:00:00 | 000,028,270 | ---- | C] () -- C:\WINNT\System32\perfd009.dat [2002.07.24 13:00:00 | 000,014,413 | ---- | C] () -- C:\WINNT\System32\iasperf.ini [2002.07.24 13:00:00 | 000,003,056 | ---- | C] () -- C:\WINNT\System32\faxperf.ini [2002.07.24 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINNT\System32\noise.dat [2002.07.24 13:00:00 | 000,000,023 | ---- | C] () -- C:\WINNT\welcome.ini [1999.09.25 11:36:24 | 000,088,816 | ---- | C] () -- C:\WINNT\System32\drivers\lvcam.sys [1999.09.25 11:36:22 | 000,017,424 | ---- | C] () -- C:\WINNT\System32\drivers\lvsound.sys ========== LOP Check ========== [2009.12.23 17:39:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip [2009.10.20 11:53:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\klickTel ========== Purity Check ========== < End of report > GMER Logfile: Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2011-12-27 11:18:17 Windows 5.0.2195 Service Pack 4 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e ST380815AS rev.3.AAD Running: je1givwm.exe; Driver: C:\DOKUME~1\Seifert\LOKALE~1\Temp\uxtcapoc.sys ---- System - GMER 1.0.15 ---- INT 0x52 ? F90D9AE4 INT 0x72 ? F9250D24 INT 0xA3 ? F924F044 INT 0xB1 ? F928F044 INT 0xB3 ? F90D9D64 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExA] [760B78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [4AD84AE3] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!CreateProcessW] [4AD84C9A] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [760B786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [760B771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [760B7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [760B7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [760B78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINNT\Explorer.EXE[544] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [760B7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Cdfs \Cdfs EB1602F0 ---- EOF - GMER 1.0.15 ---- Geändert von Seifi (27.12.2011 um 11:26 Uhr) |
27.12.2011, 11:52 | #2 |
/// Malware-holic | Trojaner an Board hi
__________________achtung! dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL O4 - HKCU..\Run: [{0B803606-B754-11DE-823B-806D6172696F}] C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe (Mozilla Foundation) :Files C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden öffne arbeitsplatz, öffne C: dann _OTL dort rechtsklick auf moved files wähle zu moved files.rar oder zip hinzufügen. folge dem link, und lade das archiv im upload channel hoch http://www.trojaner-board.de/54791-a...ner-board.html
__________________ |
27.12.2011, 12:15 | #3 | |
| Trojaner an BoardZitat:
jetzt muss ich mich erst mal herzlich bei dir bedanken markusg!!! ich finde das super, was du und die anderen hier für uns machen!!! All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{0B803606-B754-11DE-823B-806D6172696F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B803606-B754-11DE-823B-806D6172696F}\ not found. C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe moved successfully. ========== FILES ========== File\Folder C:\Dokumente und Einstellungen\Seifert\Anwendungsdaten\Microsoft\dllhsts.exe not found. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User User: Seifert ->Flash cache emptied: 470 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 263691 bytes User: Seifert ->Temp folder emptied: 738788353 bytes ->Temporary Internet Files folder emptied: 16361149 bytes ->Java cache emptied: 107055 bytes ->FireFox cache emptied: 52207556 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1809951 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 11658632 bytes RecycleBin emptied: shell32.dll unable to determine bytes removed. Total Files Cleaned = 783,00 mb OTL by OldTimer - Version 3.2.31.0 log created on 12272011_120648 Files\Folders moved on Reboot... File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\OLYFWLUF\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\OLYFWLUF\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[2] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\OLYFWLUF\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[3] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\OLYFWLUF\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[4] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_ExtendedSearch;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=0;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;E CO=NO;gear=0;seg=mass_oem;seg=utilities;seg=low[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_ExtendedSearch;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=0;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;E CO=NO;gear=0;seg=mass_oem;seg=utilities;seg=low[2] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[2] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[3] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\8XQRS5IJ\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[4] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\85MZOTUF\UsedCars_Detailpage;make=29;model=2160;zip=D64289;art=6;fr=11;price=4;hp=3;miles=2;fuel=D;ad=dealer;acc=U;ECO=NO;gear=5;seg =mass_oem;seg=utilities;seg=low_hp;seg=mid_pric[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\85MZOTUF\UsedCars_ExtendedSearch;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=0;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;E CO=NO;gear=0;seg=mass_oem;seg=utilities;seg=low[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\85MZOTUF\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\4L6BCDYB\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[1] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\4L6BCDYB\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[2] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\4L6BCDYB\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[3] not found! File\Folder C:\Dokumente und Einstellungen\Seifert\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5\4L6BCDYB\UsedCars_List;make=29;model=2160;zip=D;art=0;fr=11;price=1;hp=2;hp=3;miles=0;miles=1;miles=2;fuel=D;ad=0;acc=N;acc=U;ECO=NO ;gear=M;seg=mass_oem;seg=utilities;seg=low_hp;s[4] not found! Registry entries deleted on Reboot... |
27.12.2011, 12:21 | #4 |
/// Malware-holic | Trojaner an Board bitte verzichte auf komplette zitate, das ist unnötig. upload nicht vergessen!
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu Trojaner an Board |
0x00000001, antivir, board, erhalte, fenster, freue, guten, locker, meldung, morgen, msvcrt, nichts, plug-in, safer networking, scan, scanner, sched.exe, system, troja, trojaner, virenscan, virenscanner, windows, zusammen, öffnet |