Bernieblue | 07.11.2008 00:12 | Hallo root24,
erstmal VIELEN DANK für die Antwort. Bin bemüht alle Punkte gewissenhaft abzuarbeiten. Frage mich aber, ob vielleicht eine Neuinstallation angebracht wäre - auch um mich damit vom ganzen Datenmüll und nicht mehr benötigten Programmen zu befreien...???
Nichtsdestotrotz hier die ersten Ergebnisse der beiden Dateien von "Virustotal": Code:
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.11.5.3 2008.11.06 -
AntiVir 7.9.0.26 2008.11.06 -
Authentium 5.1.0.4 2008.11.06 -
Avast 4.8.1248.0 2008.11.06 -
AVG 8.0.0.161 2008.11.06 -
BitDefender 7.2 2008.11.06 Generic.Adw.Rotator.F9C1F4A9
CAT-QuickHeal 9.50 2008.11.04 -
ClamAV 0.94.1 2008.11.06 -
DrWeb 4.44.0.09170 2008.11.06 -
eSafe 7.0.17.0 2008.11.06 -
eTrust-Vet 31.6.6195 2008.11.06 -
Ewido 4.0 2008.11.06 -
F-Prot 4.4.4.56 2008.11.06 -
F-Secure 8.0.14332.0 2008.11.06 -
Fortinet 3.117.0.0 2008.11.06 Adware/AdClicker
GData 19 2008.11.06 Generic.Adw.Rotator.F9C1F4A9
Ikarus T3.1.1.45.0 2008.11.06 Generic.Adw.Rotator
K7AntiVirus 7.10.518 2008.11.06 -
Kaspersky 7.0.0.125 2008.11.06 -
McAfee 5426 2008.11.06 -
Microsoft 1.4005 2008.11.06 Adware:Win32/AdRotator
NOD32 3592 2008.11.06 -
Norman 5.80.02 2008.11.06 -
Panda 9.0.0.4 2008.11.06 -
PCTools 4.4.2.0 2008.11.06 -
Prevx1 V2 2008.11.06 Cloaked Malware
Rising 21.02.32.00 2008.11.06 -
SecureWeb-Gateway 6.7.6 2008.11.06 -
Sophos 4.35.0 2008.11.06 -
Sunbelt 3.1.1783.2 2008.11.05 -
Symantec 10 2008.11.06 -
TheHacker 6.3.1.1.142 2008.11.06 -
TrendMicro 8.700.0.1004 2008.11.06 -
VBA32 3.12.8.9 2008.11.06 -
ViRobot 2008.11.6.1455 2008.11.06 -
VirusBuster 4.5.11.0 2008.11.06 -
weitere Informationen
File size: 178176 bytes
MD5...: 883663752423ecaffbdfa3da6c5b3468
SHA1..: 4a215788e9c5a9edd8a62901a1e1d8d54a596c50
SHA256: 47bec02db181834b4381fe22345c2a800ea49cb032160f1b0858bf29ce2e3c77
SHA512: 650a6ac99ab1ee7b602d3ef835619f81bbab27cb505002dbd352396128d00bc3
8d2a102b15085fda44eebd01101af0ecc9339f742e32311c2d5181df86ac9ce0
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x100137f8
timedatestamp.....: 0x490c15fd (Sat Nov 01 08:40:29 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x20c20 0x20e00 6.58 e79e83fffeb18f1d5f934a9dc96adfac
.rdata 0x22000 0x62b7 0x6400 5.28 ebcb0bf711d05b97fb1ce86db356ada0
.data 0x29000 0x30a0 0x1600 3.54 6e49f04ce1d961242d54640006a3a091
.rsrc 0x2d000 0x34c 0x400 4.69 78c79b2295c89456e7d8e51fcd1b7ce1
.reloc 0x2e000 0x26c4 0x2800 4.85 1e897f661a2226e1bbb7775f57e35b38
( 8 imports )
> RPCRT4.dll: UuidToStringW, RpcStringFreeW
> VERSION.dll: VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
> SHLWAPI.dll: StrCmpIW, StrStrIW, PathStripPathW, UrlEscapeW, SHDeleteKeyW
> KERNEL32.dll: ExitThread, WaitForSingleObject, CreateThread, Sleep, GetModuleFileNameW, OpenMutexW, GetSystemTime, CreateEventW, OpenProcess, CreateMutexW, GetLastError, InterlockedIncrement, InterlockedDecrement, lstrcmpW, GetTickCount, SystemTimeToFileTime, GetLocalTime, LocalFree, LoadLibraryA, FreeLibrary, ExpandEnvironmentStringsW, WideCharToMultiByte, MultiByteToWideChar, GetTempFileNameW, GetEnvironmentVariableW, LocalAlloc, VirtualQuery, GetVolumeInformationW, LoadLibraryW, GetSystemInfo, GetStringTypeW, GetStringTypeA, LCMapStringA, GetLocaleInfoA, InitializeCriticalSectionAndSpinCount, GetConsoleMode, GetConsoleCP, SetFilePointer, HeapReAlloc, VirtualAlloc, GetSystemTimeAsFileTime, GetCurrentProcessId, QueryPerformanceCounter, VirtualFree, HeapDestroy, HeapCreate, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetProcAddress, CreateProcessW, CloseHandle, SetEvent, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrlenW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, GetWindowsDirectoryW, GetFileType, SetHandleCount, LCMapStringW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetModuleFileNameA, GetStdHandle, WriteFile, ExitProcess, HeapSize, GetModuleHandleA, SetLastError, TlsFree, TlsSetValue, RaiseException, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, GetCurrentThreadId, GetCommandLineA, HeapFree, HeapAlloc, GetModuleHandleW, TlsGetValue, TlsAlloc
> USER32.dll: GetWindowTextW, EnumChildWindows, RealGetWindowClassW, CallWindowProcW, SetWindowLongW, GetWindowThreadProcessId, SetActiveWindow, SendMessageW, GetPropW, RemovePropW, SetWindowTextW, SetPropW, IntersectRect, InflateRect, ClientToScreen, MsgWaitForMultipleObjects, PeekMessageW, TranslateMessage, DispatchMessageW, GetClassNameW, PostMessageW, OffsetRect
> ADVAPI32.dll: CryptCreateHash, CryptGetHashParam, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, CryptGenRandom, CryptAcquireContextW, CryptHashData, CryptDestroyHash, CryptReleaseContext, RegQueryValueExW, RegCreateKeyW, RegCreateKeyExW, RegSetValueW, RegDeleteValueW, RegOpenKeyExW, RegSetValueExW, RegCloseKey
> ole32.dll: CoInitializeEx, CoCreateInstance, CoTaskMemFree, CoUninitialize
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -
( 4 exports )
DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=891B173A0037052DB898024827A87D00F27D9B68 Code:
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 - - Win-Trojan/Xema.variant
AntiVir - - TR/BHO.Gen
Authentium - - -
Avast - - Win32:Trojan-gen {Other}
AVG - - Generic3.AAHJ
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - Win32.Vapsup.nbh
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
F-Secure - - Trojan.Win32.Vapsup.nbh
Fortinet - - -
GData - - Win32:Trojan-gen {Other}
Ikarus - - BHO.Win32.Fotomoto
K7AntiVirus - - -
Kaspersky - - Trojan.Win32.Vapsup.nbh
McAfee - - Generic.dx
Microsoft - - BrowserModifier:Win32/Fotomoto
NOD32 - - probably a variant of Win32/Adware.AdzgaloreBiz
Norman - - -
Panda - - -
PCTools - - -
Prevx1 - - Malicious Software
Rising - - Trojan.Win32.Vapsup.evj
SecureWeb-Gateway - - Trojan.BHO.Gen
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
TrendMicro - - -
VBA32 - - -
ViRobot - - Trojan.Win32.Agent.364032.C
VirusBuster - - -
weitere Informationen
MD5: 487321bcdb3983a95aaff98d769bdd45
SHA1: 7cf9af7eb642e524979539e02bb358b3faaf2eee
SHA256: 98ec82f4e8dc24b8e69e70e3bb2fd579daa42052761b1120add92415f490bf4c
SHA512: 23440ad9266b9bf2ac1319aa0e59daeefcc4524eca1237405b40f2f81fe6e4d896c74d35eaecaee9a24234d5ccb788483c5ed7d945a8cfd528a11953e8a2ad2f Hier das Ergebnis vom MBR-Tool: Code:
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK Blacklight fand keine versteckten Dateien. Ein log-file scheint es dafür nicht zu geben.
Hier der Scan von Malwarebytes: Code:
Malwarebytes' Anti-Malware 1.30
Datenbank Version: 1367
Windows 5.1.2600 Service Pack 3
07.11.2008 01:06:13
mbam-log-2008-11-07 (01-06-05).txt
Scan-Methode: Quick-Scan
Durchsuchte Objekte: 46268
Laufzeit: 3 minute(s), 57 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 28
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 5
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\browsingenhancer.browserwatcher (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\browsingenhancer.browserwatcher.1 (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\browsingenhancer.pornpro_bho (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\browsingenhancer.pornpro_bho.1 (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\browsingenhancer.precachebrowserhost (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\browsingenhancer.precachebrowserhost.1 (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{125e9d24-2428-38d2-8e23-804e3275209c} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3f2579e9-ec37-3112-9bde-d2db14e95c32} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e12688ce-9384-28e3-a041-4e1a9ce14506} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5abbd91b-0215-2fe1-7a7e-753f05b40cb8} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{96fdc0f6-929e-e96c-597f-386cd3c7d7aa} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{b056fd59-0c72-3878-da81-4c5239908200} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{98d555cc-a569-43fb-2f43-3a98ccda4b50} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{40b2127e-cc18-37d0-43ca-afa158c64001} (Adware.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5abbd91b-0215-2fe1-7a7e-753f05b40cb8} (Adware.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e} (Adware.Mirar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e} (Adware.Mirar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\playmp3 (Adware.PlayMP3Z) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BrowsingEnhancer.DLL (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\BrowsingEnhancer (Adware.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cont_offersfortoday (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Mirar (Adware.Mirar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\PlayMP3 (Adware.PlayMP3Z) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b1db207-75ad-ebb9-4e85-3fb96b8a9a66} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3b1db207-75ad-ebb9-4e85-3fb96b8a9a66} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d697c788-8f51-e16e-f57c-2854a3979a10} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d697c788-8f51-e16e-f57c-2854a3979a10} (Adware.BHO) -> No action taken.
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\udljczqjdtocr (Trojan.Agent) -> No action taken.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
C:\Programme\PlayMP3z (Adware.PlayMP3Z) -> No action taken.
Infizierte Dateien:
C:\Programme\PlayMP3z\PlayMP3.exe (Adware.PlayMP3Z) -> No action taken.
C:\Programme\PlayMP3z\uninstall.exe (Adware.PlayMP3Z) -> No action taken.
C:\WINDOWS\system32\kqyxlrrusqpjoiv.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\cont_offersfortoday-remove.exe (Adware.Agent) -> No action taken.
C:\WINDOWS\system32\nsaF.dll (Adware.BHO) -> No action taken. |