Ich bräuchte Hilfe da IE bei mir ein Pop up öffnet, ohne das ich es möchte?
Code:
Alles auswählen Aufklappen ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Header
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Microsoft Windows XP [Version 5.1.2600]
Fri Aug 03 10:10:10 2007 => ProxyServer: Software\Microsoft\Windows\CurrentVersion\Internet Settings
Fri Aug 03 10:10:31 2007 => Virus Database Date: 8/2/2007
Fri Aug 03 11:32:52 2007 => Virus Database Date: 8/2/2007
Fri Aug 03 11:33:46 2007 => Virus Database Date: 8/2/2007
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infektionsmeldungen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Aug 03 10:12:12 2007 => System found infected with flashfxp Spyware/Adware ({e5a1691b-d188-4419-ad02-90002030b8ee})! Action taken: No Action Taken.
Fri Aug 03 10:12:12 2007 => System found infected with flashfxp Spyware/Adware ({e5a1691b-d188-4419-ad02-90002030b8ee})! Action taken: No Action Taken.
Fri Aug 03 10:13:10 2007 => System found infected with netpumper Spyware/Adware ({f7258f6e-9f60-49c0-8c82-f0a0993d68e0})! Action taken: No Action Taken.
Fri Aug 03 10:13:10 2007 => System found infected with netpumper Spyware/Adware ({a8b0f390-e6bf-4027-a4d4-1e4363f5e27b})! Action taken: No Action Taken.
Fri Aug 03 10:13:10 2007 => System found infected with netpumper Spyware/Adware ({a9e33220-0b05-11d7-88d2-444553540000})! Action taken: No Action Taken.
Fri Aug 03 10:13:10 2007 => System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken.
Fri Aug 03 10:13:10 2007 => System found infected with netpumper Spyware/Adware ({e0abbf96-17dc-44ca-96d0-6217064a97ba})! Action taken: No Action Taken.
Fri Aug 03 10:13:26 2007 => System found infected with lop.com Spyware/Adware (sta3.exe)! Action taken: No Action Taken.
Fri Aug 03 10:13:26 2007 => System found infected with superutilbar Adware (temp.exe)! Action taken: No Action Taken.
Fri Aug 03 10:13:53 2007 => System found infected with smitfraud Browser Hijacker (antivirus test online.url)! Action taken: No Action Taken.
Fri Aug 03 10:13:53 2007 => System found infected with ezula Spyware/Adware (ebay.url)! Action taken: No Action Taken.
Fri Aug 03 10:14:13 2007 => System found infected with uplink Adware (installoptions.dll)! Action taken: No Action Taken.
Fri Aug 03 10:14:13 2007 => System found infected with uplink Adware (installoptions.dll)! Action taken: No Action Taken.
Fri Aug 03 10:14:13 2007 => System found infected with lop.com Spyware/Adware (sta3.exe)! Action taken: No Action Taken.
Fri Aug 03 10:14:13 2007 => System found infected with superutilbar Adware (temp.exe)! Action taken: No Action Taken.
Fri Aug 03 10:14:26 2007 => System found infected with netpumper Spyware/Adware (C:\Programme\netpumper\zm\minime.exe)! Action taken: No Action Taken.
Fri Aug 03 10:14:26 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware (C:\WINDOWS\unvise32.exe)! Action taken: No Action Taken.
Fri Aug 03 10:14:26 2007 => System found infected with holistyc Dialer (C:\WINDOWS\icons)! Action taken: No Action Taken.
~~~~~~~~~~~
Dateien
~~~~~~~~~~~
~~~~ Infected files
~~~~~~~~~~~
Fri Aug 03 10:11:54 2007 => File C:\DOKUME~1\ALLUSE~1\ANWEND~1\LICENS~1\BITSCH~1.EXE infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:11:54 2007 => File C:\DOKUME~1\ALLUSE~1\ANWEND~1\DEAFME~1\BONERD~1.EXE infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:11:55 2007 => File C:\DOKUME~1\Fridge\ANWEND~1\PLANAM~1\BOOBSH~1.EXE infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:16:31 2007 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Deaf Meal Log License\Bone Rdr Jugs.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:16:31 2007 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LICENSE ADMIN OPTION BIB\bits chin.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:16:33 2007 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PILE INTER ACE REF\DOWNLOAD META.exe infected by "Trojan.Win32.Inject.au" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:16:33 2007 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PILE INTER ACE REF\send open.exe infected by "Trojan.Win32.Inject.au" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\afgcocmh.exe infected by "Trojan.Win32.Inject.au" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\avvthgtf.exe infected by "Trojan.Win32.Inject.au" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\bitlqrzt.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\boob shim.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\idle bits blue.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:18:57 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Planamenscr\idle mfcd grey.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:19:42 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\36\383a6924-49c3f349/BaaaaBaa.class infected by "Trojan.Java.ClassLoader.ao" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:19:51 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\43\5af4726b-28621864/Dummy.class infected by "Trojan-Downloader.Java.OpenStream.v" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:20:10 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\60\6ac9be3c-56cb6f3d/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:20:48 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-13161adf-73c5c7bf.zip/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:20:50 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-4ace4a3-2f02005c.zip/BaaaaBaa.class infected by "Trojan.Java.ClassLoader.ao" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:20:50 2007 => File C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\dialarch.jar-571971d9-71081099.zip/Dummy.class infected by "Trojan-Downloader.Java.OpenStream.v" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:33:31 2007 => File C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\Temp\AutoDL%3FBundleId=11026_b197d946.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:33:40 2007 => File C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\Temp\bis78.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 10:34:22 2007 => File C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\Temp\sta3.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 11:05:50 2007 => File C:\Programme\Media-Codec\uninst.exe infected by "Trojan-Downloader.Win32.Zlob.vn" Virus! Action Taken: No Action Taken.
Fri Aug 03 11:09:53 2007 => File C:\Programme\NetPumper\ZM\minime.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
Fri Aug 03 11:13:11 2007 => File C:\Programme\totalcommander\run.exe infected by "Trojan-Downloader.Win32.Zlob.ta" Virus! Action Taken: No Action Taken.
Fri Aug 03 11:13:13 2007 => File C:\Programme\totalcommander\twkt654a.exe/run.exe infected by "Trojan-Downloader.Win32.Zlob.ta" Virus! Action Taken: No Action Taken.
~~~~~~~~~~~
~~~~ Tagged files
~~~~~~~~~~~
Fri Aug 03 10:15:23 2007 => File C:\Dokumente und Einstellungen\Administrator\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe tagged as "not-a-virus:RiskTool.Win32.Reboot.f". Action Taken: No Action Taken.
Fri Aug 03 10:15:26 2007 => File C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\kewhhjsh.default\Cache\0C5F542Cd01/SmitfraudFix/Reboot.exe tagged as "not-a-virus:RiskTool.Win32.Reboot.f". Action Taken: No Action Taken.
Fri Aug 03 11:16:43 2007 => File C:\RECYCLER\S-1-5-21-1839656885-3724385041-1575707048-500\Dc1.zip/SmitfraudFix/Reboot.exe tagged as "not-a-virus:RiskTool.Win32.Reboot.f". Action Taken: No Action Taken.
Fri Aug 03 11:29:40 2007 => File C:\WINDOWS\system32\cmdow.exe tagged as "not-a-virus:RiskTool.Win32.HideWindows". Action Taken: No Action Taken.
~~~~~~~~~~~
~~~~ Offending files
~~~~~~~~~~~
Fri Aug 03 10:13:26 2007 => Offending file found: C:\DOKUME~1\Fridge\LOKALE~1\Temp\sta3.exe
Fri Aug 03 10:13:26 2007 => Offending file found: C:\DOKUME~1\Fridge\LOKALE~1\Temp\temp.exe
Fri Aug 03 10:13:53 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Favoriten\antivirus test online.url
Fri Aug 03 10:13:53 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Favoriten\ebay.url
Fri Aug 03 10:14:13 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\temp\nse1b.tmp\installoptions.dll
Fri Aug 03 10:14:13 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\temp\nsu16.tmp\installoptions.dll
Fri Aug 03 10:14:13 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\temp\sta3.exe
Fri Aug 03 10:14:13 2007 => Offending file found: C:\Dokumente und Einstellungen\Fridge\Lokale Einstellungen\temp\temp.exe
Fri Aug 03 10:14:26 2007 => Offending file found: C:\Programme\netpumper\zm\minime.exe
Fri Aug 03 10:14:26 2007 => Offending file found: C:\WINDOWS\unvise32.exe
Fri Aug 03 10:14:26 2007 => Offending file found: C:\WINDOWS\icons
~~~~~~~~~~~
Ordner
~~~~~~~~~~~
Fri Aug 03 10:13:22 2007 => Offending Folder found: C:\Programme\netpumper
Fri Aug 03 10:13:36 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\netpumper
Fri Aug 03 10:13:44 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Fridge\Anwendungsdaten\toshiba\pcdiag\v3.0
Fri Aug 03 10:13:57 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Fridge\Eigene Dateien\eigene musik\metallica\load
Fri Aug 03 10:14:23 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Fridge\Eigene Dateien\Eigene Musik\metallica\load
Fri Aug 03 10:14:25 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Fridge\Eigene Dateien\eigene musik\metallica\load
~~~~~~~~~~~
Registry
~~~~~~~~~~~
Fri Aug 03 10:13:12 2007 => Offending Key found: HKLM\Software\netpumper !!!
Fri Aug 03 10:13:12 2007 => Offending Key found: HKCU\Software\whenu !!!
Fri Aug 03 10:13:12 2007 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu2\programs\netpumper !!!
Fri Aug 03 10:13:12 2007 => Offending Key found: HKCU\\media-codec.chl !!!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Aug 03 10:27:12 2007 => [Scanning Folder: C:\Dokumente und Einstellungen\Fridge\Eigene Dateien\Eigene Bilder\Adobe\Gescannte Fotos]