|
Log-Analyse und Auswertung: IDS105 "TROJAN-ACTIVE-DELTASOURCE"Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.04.2005, 10:57 | #1 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" hi all,weiss nicht ob das hier ne fake meldung ist oder nicht...meine kerio meldete folgendes " IDS105 TROJAN-ACTIVE-DELTASOURCE". 3 angriffe mit priorität "high". ist das vieleicht mit den ständigen stressmeldungen der bekannten zone alarm zu vergleichen oder geht hier tatsächlich was kurioses auf meinem rechner vor? Logfile of HijackThis v1.99.1 Scan saved at 11:42:45, on 11.04.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe C:\WINDOWS\system32\devldr32.exe C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe C:\Programme\Kerio\Personal Firewall 4\kpf4ss.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\supervisor.exe C:\Programme\ICQLite\ICQLite.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\PROGRA~1\WINZIP\winzip32.exe C:\WINDOWS\Temp\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goggle.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.internetcologne.de O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\Programme\INSTAFINK\instafink.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [KAV50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0 -chkss O4 - HKCU\..\Run: [Steam] C:\Programme\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [supervisor.exe] C:\WINDOWS\supervisor.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {986B8E45-9EC9-463D-B608-76C1AB01D79B} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {986B8E45-9EC9-463D-B608-76C1AB01D79B} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O14 - IERESET.INF: START_PAGE_URL=http://www.internetcologne.de O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1107707403406 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Kaspersky Anti-Virus Service (KLBLMain) - Unknown owner - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe" -run bl -n PersonalPro -v 5.0.0.0 -ttsr 10000000 (file missing) O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Programme\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE |
11.04.2005, 11:14 | #2 | |||
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" @tamas
__________________Zitat:
Zitat:
Zitat:
|
11.04.2005, 11:16 | #3 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" Hi
__________________vermutlich liegt Dein Problem bei C:\WINDOWS\system32\devldr32.exe In meinen Augen, solltest Du Dein System mit eScan scnanne lassen (bitte Anleitung in meiner Signatur folgen) und das log posten, bzw. den teil den Du erhälst, wenn Du nach "Infected" suchst und dann kopierst Du daraus, was wo und wie oft gefunden wurde (Heuristic nennt sich das). Alternativ auch diese Datei bei Jotti scannen lassen Dann sehen wir mal weiter Gruß Andy
__________________ |
11.04.2005, 11:19 | #4 | |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" @FancyAndy Zitat:
|
11.04.2005, 11:24 | #5 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" @Rene-gad : Ich beziehe mich dadrauf, FALLS das der "Doppelgänger" sein sollte , ansonsten hassu recht, dann sollte man diese Datei tunlichst in Ruhe lassen...ich heiße ja nicht R*** *g* Du weißt was ich meine :aplaus:
__________________ Fragen, die die Welt nicht braucht (oder doch ?) Wie setze ich mein System neu auf ? |
11.04.2005, 13:10 | #6 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" thx erstmal für die schnelle hilfe :aplaus: hab die datei supervisor.exe bei jotti checken lassen aber nix gefunden und InstaFinderK über software-manager deinstalliert hier der bericht von eScan: File System Found infected by "Gator Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "myway Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\adm.exe infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\adm25.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\adm4.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\admdloader.dll infected by "not-a-virus:AdWare.BrilliantDigital.3039" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\admfdi.dll infected by "not-a-virus:AdWare.Altnet.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\admprog.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\Altnet\Setup.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\tamas&iris\Lokale Einstellungen\Temp\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\tamas&iris\Lokale Einstellungen\Temp\__unin__.exe infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken. File C:\Programme\INSTAFINK\InstaFinderK_inst.exe infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP118\A0136029.dll infected by "not-a-virus:AdWare.Altnet.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP118\A0136059.exe infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP118\A0136061.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136214.exe infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136216.dll infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136224.dll infected by "not-a-virus:AdWare.Altnet.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136233.exe infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136238.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136239.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136240.exe infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136242.dll infected by "not-a-virus:AdWare.BrilliantDigital.3039" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136243.dll infected by "not-a-virus:AdWare.Altnet.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136244.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136245.exe infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136247.dll infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136258.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136259.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136260.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136261.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136262.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136263.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136264.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136265.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136266.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136267.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136268.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136269.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136272.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136274.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136275.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136276.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136277.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136278.exe infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136289.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136290.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136291.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136354.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136565.dll infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0136720.exe infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP119\A0137404.dll infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP120\A0137830.dll infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP120\A0137835.exe infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP122\A0138641.dll infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP122\A0140416.exe infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP122\A0148670.dll infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{04626380-DA0E-4081-A073-559A6040665E}\RP122\A0149606.exe infected by "not-a-virus:AdWare.ToolBar.404Search.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\adm.exe infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\adm25.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\adm4.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\admdloader.dll infected by "not-a-virus:AdWare.BrilliantDigital.3039" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\admfdi.dll infected by "not-a-virus:AdWare.Altnet.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\admprog.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Altnet\Setup.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. Geändert von tamas (11.04.2005 um 15:58 Uhr) |
11.04.2005, 22:52 | #7 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" Hallo tamas, lade Dir clearprog 1.4.1 final. Wechsel in den abgesicherten Modus bei deaktivierter Systemwiederherstellung http://www.systemwiederherstellung-d...indows-xp.html. Starte clearprog --> setze alle Häckchen bei Windows und bei Internet Explorer-->auf Löschen klicken Lass dann nochmal Escan laufen und löschen alle Funde Neustart -->Systemwiederherstellung aktivieren--> Neues Logfile dartus
__________________ Kein Support per PN |
12.04.2005, 09:56 | #8 |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" moin.... wie lösch ich die datein im eScan? hab irgendwo gelesen mit windowstaste +e aber irgenwie geht das net |
12.04.2005, 10:18 | #9 | |
| IDS105 "TROJAN-ACTIVE-DELTASOURCE" Hallo tamas, Zitat:
Löschen brauchst Du lt. Deinem letzten Escan nur diesen Ordner: C:\Programme\INSTAFINK Mit "clearprog" werden alle "TEMP"-Ordner geleert. Mit Ausschalten der Systemwiederherstellung diese alle: C:\System Volume Information\_restore (Dateien/Ordner löschen = markieren--> Rechtsklick dann löschen oder markieren und die Taste "Entf" drücken, nur 2 Möglichkeiten) dartus
__________________ Kein Support per PN |
Themen zu IDS105 "TROJAN-ACTIVE-DELTASOURCE" |
bho, button, dateien, explorer, fake, file missing, firewall, folge, helper, hijack, hijackthis, hotkey, internet, internet explorer, kaspersky, microsoft, programme, rechner, server, software, start, system, system32, temp, windows, windows xp, windows\temp, zone alarm |