Ich habe zufällig noch eben einen "ADS"-Stream Check mit HijackThis gemacht und musste feststellen dass genau die Files die in Frage kommen, exakt dieselben MD5 Checks. habe:
Auszug: Code:
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$R3WTJUJ.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$R8ILY4N.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RCJTGT1.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RFDO46M.dvl : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RFMI2PX.jpg : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RFROCJA.14 : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RHUDW6A\GoogleUpdateSetup.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RLVFIVY.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RMX0W2G.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RP3VZY5\English.lng : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RQR6HPK.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RTVRYTO.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RVLXPE0.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RX0CZMB.rtf : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RXWYYQV.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RZ6EAK1.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\$RECYCLE.BIN\S-1-5-21-2330493419-2886327782-1176343205-1000\$RZP1GDN.rtf : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\firefox.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\firefox.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\firefox.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\firefox.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\chameleon.chm : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\chameleon.chm : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\firefox.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\firefox.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\firefox.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\firefox.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\iexplore.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\mbam-chameleon.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\mbam-chameleon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\mbam-chameleon.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\mbam-chameleon.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\rundll32.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\svchost.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\Chameleon\winlogon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\chameleon.chm : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\firefox.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\firefox.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\firefox.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\firefox.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\iexplore.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\mbam-chameleon.com : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\mbam-chameleon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\mbam-chameleon.pif : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\mbam-chameleon.scr : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\rundll32.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\svchost.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Malwarebytes' Anti-Malware232\winlogon.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Avion - Chatviews.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Avion - Themes.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls - Cards.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls - Contact List.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls - Private Message.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls - Profile Tools.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls - Socials.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Controls.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\desc.ini : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\Files.xml : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Button.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Button_trans.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatcount.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\AvionSepLocal.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\AvionSepRemote.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\ChatAvionLocal.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\ChatAvionRemote.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\Nameback.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\preview-Avion.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\Thumbs.db : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\Avion\typing.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\BigBubbles\ChatViewLocal.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\BigBubbles\ChatViewRemote.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\BigBubbles\DisplayTypingRemote.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Program Files (x86)\Trillian\skins\Avion Pro 5\images\Chatviews\BigBubbles\preview-bigbubbles.png : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
...
C:\Users\PanIngo\Downloads\mbam-setup-1.75.0.1300(1).exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbam-setup-1.75.0.1300.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\Data\actions.ref : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\Data\Configuration\build.conf : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\Data\Configuration\config.conf : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\Data\Configuration\manifest.conf : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\imageformats\qico4.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\imageformats\qicod4.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\mbam.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\mbamcore.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\mbamnet.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\mbar.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\msvcp100.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\msvcr100.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\Plugins\fixdamage.exe : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\QtCore4.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar\QtGui4.dll : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
C:\Users\PanIngo\Downloads\mbar-1.05.0.1001.zip : Zone.Identifier (26 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
Und was ist mit diesem Dir : "C:\Users\PanIngo\AppData\Local\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC~1\APPLIC ~1\A pplication Data" ? - Da bricht doch jeder Scanner (vermutlich) ab ... ;( |