Hallo,
ich habe wg. eines Virus sshnas21.dll auf dem Rechner meiner Freundin mal OTM runtergeladen und gestartet.
Aus Neugier habe ich mal auf 'CleanUp' geklickt, worauf mir dieses OTM wohl etwas gelöscht hat:
Zitat:
File/Folder avenger.* not found.
File/Folder Avenger not found.
File/Folder bfu.zip not found.
File/Folder BFU not found.
File/Folder combofix.* not found.
File/Folder combo-fix.* not found.
File/Folder ComboFix*.txt not found.
File/Folder ComboFix not found.
C:\WINDOWS\subs folder deleted successfully.
C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-KeyMapperStarup.reg.dat deleted successfully.
C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-MSMSGS.reg.dat deleted successfully.
C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Kleptomania.reg.dat deleted successfully.
C:\Qoobox\Quarantine\Registry_backups\Notify-AtiExtEvent.reg.dat deleted successfully.
C:\Qoobox\Quarantine\Registry_backups\tcpip.reg deleted successfully.
C:\Qoobox\Quarantine\Registry_backups folder deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\mdm.exe.vir deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\n.exe.vir deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32 folder deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\IE4 Error Log.txt.vir deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS folder deleted successfully.
C:\Qoobox\Quarantine\C\Programme\MakeInst9\test\_Install.exe.vir deleted successfully.
C:\Qoobox\Quarantine\C\Programme\MakeInst9\test folder deleted successfully.
C:\Qoobox\Quarantine\C\Programme\MakeInst9\InstData\_Install.exe.vir deleted successfully.
C:\Qoobox\Quarantine\C\Programme\MakeInst9\InstData folder deleted successfully.
C:\Qoobox\Quarantine\C\Programme\MakeInst9 folder deleted successfully.
C:\Qoobox\Quarantine\C\Programme\INSTALL.LOG.vir deleted successfully.
C:\Qoobox\Quarantine\C\Programme folder deleted successfully.
C:\Qoobox\Quarantine\C\test.txt.vir deleted successfully.
C:\Qoobox\Quarantine\C folder deleted successfully.
C:\Qoobox\Quarantine\catchme.log deleted successfully.
C:\Qoobox\Quarantine folder deleted successfully.
C:\Qoobox\BackEnv\appdata.folder.dat deleted successfully.
C:\Qoobox\BackEnv\cache.folder.dat deleted successfully.
C:\Qoobox\BackEnv\Cookies.folder.dat deleted successfully.
C:\Qoobox\BackEnv\desktop.folder.dat deleted successfully.
C:\Qoobox\BackEnv\favorites.folder.dat deleted successfully.
C:\Qoobox\BackEnv\localappdata.folder.dat deleted successfully.
C:\Qoobox\BackEnv\localsettings.folder.dat deleted successfully.
C:\Qoobox\BackEnv\mypictures.folder.dat deleted successfully.
C:\Qoobox\BackEnv\personal.folder.dat deleted successfully.
C:\Qoobox\BackEnv\Profiles.Folder.dat deleted successfully.
C:\Qoobox\BackEnv\programs.folder.dat deleted successfully.
C:\Qoobox\BackEnv\SetPath.bat deleted successfully.
C:\Qoobox\BackEnv\startmenu.folder.dat deleted successfully.
C:\Qoobox\BackEnv\startup.folder.dat deleted successfully.
C:\Qoobox\BackEnv\SysPath.dat deleted successfully.
C:\Qoobox\BackEnv\templates.folder.dat deleted successfully.
C:\Qoobox\BackEnv folder deleted successfully.
C:\Qoobox\Add-Remove Programs.txt deleted successfully.
C:\Qoobox\ComboFix-quarantined-files.txt deleted successfully.
C:\Qoobox\SnapShot@2009-02-18_11.53.27.79.dat deleted successfully.
C:\Qoobox\SnapShot@2009-02-18_11.53.27.79_B.dat deleted successfully.
C:\Qoobox folder deleted successfully.
Error: No service named catchme was found to stop!
Service\Driver key catchme not found.
C:\WINDOWS\fdsv.exe deleted successfully.
C:\WINDOWS\grep.exe deleted successfully.
C:\WINDOWS\NIRCMD.exe deleted successfully.
D:\MAIL_USW\totalcmd\totalcmd\nircmd.exe deleted successfully.
C:\WINDOWS\sed.exe deleted successfully.
C:\WINDOWS\SWREG.exe deleted successfully.
C:\WINDOWS\SWSC.exe deleted successfully.
C:\WINDOWS\SWXCACLS.exe deleted successfully.
C:\WINDOWS\VFIND.exe deleted successfully.
C:\WINDOWS\zip.exe deleted successfully.
Error: No service named GMER was found to stop!
Service\Driver key GMER not found.
C:\Dokumente und Einstellungen\xxx\Desktop\OTM.exe deleted successfully.
File delete failed. D:\BACKUP\totalcmd\totalcmd\OTM.exe scheduled to be deleted on reboot.
File delete failed. D:\BACKUP\totalcmd\totalcmd\OTM.exe scheduled to be deleted on reboot.
|
Ist das OK so, oder hat mir dieses OTM jetzt was kaputt gemacht?
Wofür ist das überhaupt?
Danke, Gruß, franc