Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows Security Alert geht nicht weg. (https://www.trojaner-board.de/47600-windows-security-alert-geht-weg.html)

atomkerN 01.01.2008 18:30

Windows Security Alert geht nicht weg.
 
Hi @ll,
wie ihr seht bin ich (noch) neu hier. Also wie die meistenhier denke ich mal habe ich auch ein Problem. Also ich benutze Windows XP Home SP2 habe Bitdefender v.10 und Antivir Personaledition Classic drauf und neugeupdated. So ich habe alles gescannt im abgesicherten modus (vollständiger systemscan). Sogar schon mehrmals und dann noch ClearProg, CCleaner und SmitFraudFix (auch alles neueste version + update) alles gecleant. (abgesicherter modus). So nochmal alles von hand die Temo Files gelöscht, und nix bringts. Dieser Tronjaner kommt immer wieder. Naja Hier mal mein Hijack Log und der von SmitFraudFix (hab auch schon alles gefixt mit Hijackthis was nötig war, kommt aber auch wieder):

Hijack this:

Code:

Logfile of HijackThis v1.99.1
Scan saved at 18:25:09, on 15.01.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\TortoiseSVN\bin\TSVNCache.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programme\VMware\VMware Server\vmware-authd.exe
C:\Programme\Gemeinsame Dateien\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Programme\Softwin\BitDefender10\bdmcon.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Programme\Softwin\BitDefender10\bdagent.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programme\Razer\Copperhead\razerhid.exe
C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe
C:\Programme\Razer\Tarantula\razerhid.exe
C:\Programme\Winamp\winampa.exe
C:\WINDOWS\TBPanel.exe
C:\Programme\Java\jre1.6.0_03\bin\jusched.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Steam\Steam.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Dokumente und Einstellungen\***\Eigene Dateien\vista style\VisualTooltip22\VisualToolTip.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Programme\Razer\Copperhead\razertra.exe
C:\Programme\Razer\Copperhead\razerofa.exe
C:\Programme\Razer\Tarantula\razertra.exe
C:\Programme\VMware\VMware Server\vmserverdWin32.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Programme\ICQ6\ICQ.exe
C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
C:\Programme\Softwin\BitDefender10\vsserv.exe
C:\Dokumente und Einstellungen\***\Desktop\HijackThis.exe

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O4 - HKLM\..\Run: [BDMCon] "C:\Programme\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Programme\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [amd_dc_opt] C:\Programme\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Copperhead] C:\Programme\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Tarantula] C:\Programme\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programme\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programme\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VIPv3_Auto_Update] C:\WINDOWS\VIPv3\CheckForUpdates.exe
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\VIPv3\VIPhd\vsdrv.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Programme\Steam\Steam.exe" -silent
O4 - Startup: VisualToolTip.exe.lnk = C:\Dokumente und Einstellungen\***\Eigene Dateien\vista style\VisualTooltip22\VisualToolTip.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Erinnerungen in Microsoft Works-Kalender.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche-Assistent - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe
O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {0e921e80-267a-42aa-aee4-60b9a1222a44} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {0e921e80-267a-42aa-aee4-60b9a1222a44} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O17 - HKLM\System\CS1\Services\Tcpip\..\{236621D1-D2F1-43C6-B969-BB259B37C942}: NameServer = 192.168.2.1
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: bvtqfvx - {FD8CCEEC-B154-4835-9F5C-DCBB16F11291} - C:\WINDOWS\bvtqfvx.dll
O21 - SSODL: alxvdvm - {A170787D-4676-4F58-8A93-60E6306E74D0} - C:\WINDOWS\alxvdvm.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programme\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: DSL-Manager (TDslMgrService) - T-Systems Enterprise Services GmbH - C:\Programme\DSL-Manager\DslMgrSvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programme\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Programme\Gemeinsame Dateien\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Programme\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Programme\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

so das war hijack this und jetz kommt smitfraudfix:

Code:

SmitFraudFix v2.274

Scan done at 18:09:36,46, 15.01.2008
Run from C:\Dokumente und Einstellungen\***\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1      localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOKUME~1\***\FAVORI~1\Error Cleaner.url Deleted
C:\DOKUME~1\***\FAVORI~1\Privacy Protector.url Deleted
C:\DOKUME~1\***\FAVORI~1\Spyware?Malware Protection.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce Networking Controller - Paketplaner-Miniport
DNS Server Search Order: 192.168.2.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{236621D1-D2F1-43C6-B969-BB259B37C942}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{236621D1-D2F1-43C6-B969-BB259B37C942}: NameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{236621D1-D2F1-43C6-B969-BB259B37C942}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{236621D1-D2F1-43C6-B969-BB259B37C942}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
Registry Cleaning done.
 
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

so ma gucken ob ihr mir helfen könnt dis ding wegzumachen.

mfg atomkerN

P.S.

nochwass- mit Ad Aware 2007 aktuelles update habe ich auch schon alles gescannt. Er hat auch 33 funde gehabt aber naja... die wegzumachen hat nix gebracht...

Clermont-Ferrand 01.01.2008 19:20

atomkerN

Zunächst: Frohes neues Jahr. ;)

Lade folgende Dateien bei VirusTotal hoch und poste das Ergebnis aller Scanner inkl. Dateigröße: (Link in meiner Signatur)

Code:

C:\WINDOWS\alxvdvm.dll
C:\WINDOWS\bvtqfvx.dll


atomkerN 01.01.2008 20:09

Code:

///C:\WINDOWS\alxvdvm.dll///

Antivirus          Version          letzte aktualisierung          Ergebnis
AhnLab-V3        2008.1.1.10        2007.12.31        -
AntiVir        7.6.0.46        2007.12.31        -
Authentium        4.93.8        2007.12.31        -
Avast        4.7.1098.0        2007.12.31        -
AVG        7.5.0.516        2008.01.01        Clicker.KNK
BitDefender        7.2        2008.01.01        -
CAT-QuickHeal        9.00        2007.12.31        -
ClamAV        0.91.2        2008.01.01        -
DrWeb        4.44.0.09170        2007.12.31        -
eSafe        7.0.15.0        2008.01.01        -
eTrust-Vet        31.3.5421        2008.01.01        -
Ewido        4.0        2008.01.01        -
FileAdvisor        1        2008.01.01        -
Fortinet        3.14.0.0        2008.01.01        Adware/AdClicker
F-Prot        4.4.2.54        2007.12.31        -
F-Secure        6.70.13030.0        2008.01.01        -
Ikarus        T3.1.1.15        2008.01.01        Virus.Win32.Agent.LTS
Kaspersky        7.0.0.125        2008.01.01        -
McAfee        5196        2007.12.31        AdClicker-FC
Microsoft        1.3109        2008.01.01        Adware:Win32/SmitFraud
NOD32v2        2759        2008.01.01        -
Norman        5.80.02        2007.12.31        -
Panda        9.0.0.4        2008.01.01        -
Prevx1        V2        2008.01.01        -
Rising        20.24.52.00        2007.12.29        -
Sophos        4.24.0        2008.01.01        -
Sunbelt        2.2.907.0        2007.12.30        -
Symantec        10        2008.01.01        -
TheHacker        6.2.9.176        2008.01.01        -
VBA32        3.12.2.5        2007.12.31        -
VirusBuster        4.3.26:9        2008.01.01        -
Webwasher-Gateway        6.6.2        2007.12.31        -
weitere Informationen
File size: 270336 bytes
MD5: 0d6be4d731a87b28b15a5000eaf6b0e0
SHA1: f214210d67122b77c6aeea2d3f820ff91bcb79f1
PEiD: -

Code:

///C:\WINDOWS\bvtqfvx.dll///

Antivirus          Version          letzte aktualisierung          Ergebnis
AhnLab-V3        2008.1.1.10        2007.12.31        -
AntiVir        7.6.0.46        2007.12.31        ADSPY/Agent.PB
Authentium        4.93.8        2007.12.31        -
Avast        4.7.1098.0        2007.12.31        Win32:Agent-LTS
AVG        7.5.0.516        2008.01.01        -
BitDefender        7.2        2008.01.01        -
CAT-QuickHeal        9.00        2007.12.31        -
ClamAV        0.91.2        2008.01.01        -
DrWeb        4.44.0.09170        2007.12.31        -
eSafe        7.0.15.0        2008.01.01        -
eTrust-Vet        31.3.5421        2008.01.01        -
Ewido        4.0        2008.01.01        -
FileAdvisor        1        2008.01.01        -
Fortinet        3.14.0.0        2008.01.01        -
F-Prot        4.4.2.54        2007.12.31        -
F-Secure        6.70.13030.0        2008.01.01        W32/Zlob.AXCU
Ikarus        T3.1.1.15        2008.01.01        Virus.Win32.Agent.LTS
Kaspersky        7.0.0.125        2008.01.01        -
McAfee        5196        2007.12.31        -
Microsoft        1.3109        2008.01.01        Adware:Win32/SmitFraud
NOD32v2        2759        2008.01.01        -
Norman        5.80.02        2007.12.31        W32/Zlob.AXCU
Panda        9.0.0.4        2008.01.01        -
Prevx1        V2        2008.01.01        -
Rising        20.24.52.00        2007.12.29        -
Sophos        4.24.0        2008.01.01        -
Sunbelt        2.2.907.0        2007.12.30        -
Symantec        10        2008.01.01        -
TheHacker        6.2.9.176        2008.01.01        -
VBA32        3.12.2.5        2007.12.31        -
VirusBuster        4.3.26:9        2008.01.01        -
Webwasher-Gateway        6.6.2        2007.12.31        Ad-Spyware.Agent.PB
weitere Informationen
File size: 253952 bytes
MD5: 9c11ef8914eaa1efe9c011129a89bf97
SHA1: 02b1599278c4ce766b597f52533dff8c6460bb9c
PEiD: -


*Christian* 01.01.2008 20:15

Sende die beiden Dateien an die Virenschutzhersteller:

Ad-aware: research(at)lavasoft.com
Ahnlab: v3sos(at)ahnlab.com
AntiVir: virus(at)free-av.de
ArcaVir: virus(at)arcabit.com
Avast: virus(at)asw.cz
AVG: virus(at)grisoft.cz
A²: submit(at)emsisoft.com
Bitdefender: virus_submission(at)bitdefender.com
Clam: ClamAV VirusDB submission
Command: virus(at)commandsoftware.com
Comodo BoClean: bocleansubmissions(at)comodo.com
DrWeb: vms(at)drweb.com
Ewido: submit(at)ewido.net
eSafe: virus(at)esafe.com
eTrust: virus(at)ca.com
F-Prot: viruslab(at)f-prot.com
Fortinet: submitvirus(at)fortinet.com
FP-Win: samples(at)percomp.de
F-Secure: vsamples(at)f-secure.com
G-DATA: samples(at)gdatasoftware.com
Hauri: viruslab(at)hauri.co.kr
Ikarus: samples(at)ikarus.at
Kaspersky: newvirus(at)kaspersky.com
McAfee: virus_research_de(at)avertlabs.com
MKS-Vir: wirus(at)mks.com.pl
Microsoft AntiVirus: onecare(at)submit.microsoft.com
Microsoft Anti-Spyware: windefend(at)submit.microsoft.com
Nod32: samples(at)eset.com
Norman: analysis(at)norman.no
Panda: virus(at)pandasecurity.com
PestPatrol: helpdesk(at)pestpatrol.com
Quickheal: viruslab(at)quickheal.com
SecureComputing: samples(at)securecomputing.com
Sophos: samples(at)sophos.com
Spybot: detections(at)spybot.info
Symantec Norton: avsubmit(at)symantec.com
Sunbelt: malware-cruncher(at)sunbelt-software.com
Tauscan: trojans(at)agnitum.com
Trendmicro: VirusLab(at)trendmicro-europe.com
TrojanHunter: submit(at)trojanhunter.com
VBA32: newvirus(at)anti-virus.by
Vexira: virus(at)centralcommand.com
Virudin: labor(at)virudin.com
Virusbuster: virus(at)virusbuster.hu

Bitte ersetze "(at)" mit "@". Wenn du möchtest, kann ich dir die Adressen auch im Textformat nennen. Du kannst dann den Text einfach in dein E-Mail-Programm kopieren.
Es wäre sehr sehr hilfreich, wenn du die Dateien an die Virenschutzhersteller senden würdest - es handelt sich hierbei um neue Malware.



Anschließend lösche die Dateien im abgesicherten Modus.
Fixe anschließend dies mit HijackThis:

O21 - SSODL: bvtqfvx - {FD8CCEEC-B154-4835-9F5C-DCBB16F11291} - C:\WINDOWS\bvtqfvx.dll
O21 - SSODL: alxvdvm - {A170787D-4676-4F58-8A93-60E6306E74D0} - C:\WINDOWS\alxvdvm.dll

atomkerN 01.01.2008 20:26

hmm naja ok mache ich, aber wie schicke ich denn die beiden viren im zip oder rar format an soviele gleichzeitig?

P.S.

Ich benutze kein emailprogramm. ich nehme die internetoberfläche von googlemail.

edit:

ich hab übrigens nicht nur die dlls gefunden - nebenn den dlls wa auch eine datei namens fvkwdrt.exe und zwei textdateien mit komischen internetseiten- unerwünschte wie pornoseiten und securecleaner usw...

*Christian* 01.01.2008 20:33

Ja, bitte Zip-Verpackt mit dem Passwort "infected". An alle gleichzeitig; das macht gar nichts. Du kannst die Adressen dann auch in die Weboberfläche eingeben.

Wo liegen die Dateien?

atomkerN 01.01.2008 20:40

rar verpackt grad auf meinem laptop und noch in meinem windows verzeichnis.

Hier mal ergebnisse von der fvkwdrt.exe

Code:

Antivirus          Version          letzte aktualisierung          Ergebnis
AhnLab-V3        2008.1.1.10        2007.12.31        -
AntiVir        7.6.0.46        2007.12.31        -
Authentium        4.93.8        2007.12.31        -
Avast        4.7.1098.0        2007.12.31        -
AVG        7.5.0.516        2008.01.01        -
BitDefender        7.2        2008.01.01        -
CAT-QuickHeal        9.00        2007.12.31        AdWare.Vapsup.ta (Not a Virus)
ClamAV        0.91.2        2008.01.01        -
DrWeb        4.44.0.09170        2007.12.31        -
eSafe        7.0.15.0        2008.01.01        -
eTrust-Vet        31.3.5421        2008.01.01        -
Ewido        4.0        2008.01.01        -
FileAdvisor        1        2008.01.01        -
Fortinet        3.14.0.0        2008.01.01        -
F-Prot        4.4.2.54        2008.01.01        -
F-Secure        6.70.13030.0        2008.01.01        -
Ikarus        T3.1.1.15        2008.01.01        not-a-virus:AdWare.Win32.Vapsup.tz
Kaspersky        7.0.0.125        2008.01.01        not-a-virus:AdWare.Win32.Vapsup.vq
McAfee        5196        2007.12.31        -
Microsoft        1.3109        2008.01.01        Adware:Win32/SmitFraud
NOD32v2        2759        2008.01.01        -
Norman        5.80.02        2007.12.31        -
Panda        9.0.0.4        2008.01.01        -
Prevx1        V2        2008.01.01        -
Rising        20.24.52.00        2007.12.29        -
Sophos        4.24.0        2008.01.01        -
Sunbelt        2.2.907.0        2007.12.30        -
Symantec        10        2008.01.01        -
TheHacker        6.2.9.176        2008.01.01        -
VBA32        3.12.2.5        2007.12.31        -
VirusBuster        4.3.26:9        2008.01.01        -
Webwasher-Gateway        6.6.2        2007.12.31        -
weitere Informationen
File size: 90112 bytes
MD5: 34f50801ae9cfb9ce8a64f725cf44aa5
SHA1: f9df6b33dfa94e9a5a0317b22c030002484ce242
PEiD: -

dann noch die dat.txt

Code:

82.103.137.14_;_1075706818
securepccleaner.com_;_1075708239
mediasmegaportal.com_;_1075707143
_;_1075708333
de.msn.com_;_1075708335
search.icq.com_;_1075708336
%sd%_;_1075708336

und die rs.txt

Code:

redirect-settings
version: 4
save-dt: 1075707142
domain:9mmporn.com
domain:adult-xxx-world.com
domain:allhentaimovies.com
domain:allsexfiles.com
domain:americanthumbs.com
domain:animetgp.lookitnow.com
domain:aquatgp.com
domain:asiansexstation.com
domain:babe5.com
domain:bighands-club.com
domain:blackbootyjuice.com
domain:bootybone.com
domain:celebrities-a-z.com
domain:celebrity-tgp.com
domain:clickhere4hardcore.com
domain:dailymoviepost.com
domain:eljardinsecreto.com
domain:eutopiamovies.com
domain:fasteddiesclips.com
domain:fetishscreen.com
domain:findpornstar.com
domain:freematureporn.org
domain:freepetites.com
domain:freeporndivxs.com
domain:granny-series.com
domain:jesuslovesporn.net
domain:laylaj.com
domain:legs-fetish.com
domain:leslickers.com
domain:linxxxzone.com
domain:listasian.com
domain:lostbush.com
domain:mature.poonfarm.com
domain:matureguide.com
domain:movie-gallery-post.com
domain:movies.allwayslinks.com
domain:nude-art.net
domain:obscenethumbs.com
domain:onlinestars.net
domain:oosex.net
domain:pantgp.com
domain:pantyhose.hotpornindex.com
domain:pictures-free.org
domain:pornstarsmaster.com
domain:pornstarstgp.com
domain:quierobdsm.com
domain:sexbane.com
domain:sinful-bordello.top-sex.us
domain:strapontgp.com
domain:submit.asianxangels.com
domain:submit.thehun.net
domain:sweetypics.com
domain:teenfirsttimers.com
domain:tgp.comfortsex.com
domain:tgpsubmit.persiankitty.com
domain:thumbsgallerypost.com
domain:top-sex-movies.com
domain:ultratoon4you.com
domain:undergroundlinks.com
domain:wannashagg.com
domain:www.000x.us
domain:www.100freeteenseries.com
domain:www.101sexmovies.com
domain:www.101teengirls.com
domain:www.123latex4free.com
domain:www.150teengalleries.com
domain:www.181st.net
domain:www.19young.com
domain:www.1eyesex.com
domain:www.2xfree.com
domain:www.3pic.com
domain:www.3xmania.com
domain:www.4whw.com
domain:www.69pornoplace.com
domain:www.69style.com
domain:www.6tgp.com
domain:www.7feel.net
domain:www.8teenporn.com
domain:www.8teenxxx.com
domain:www.aaasexpictures.com
domain:www.absolute-grannies.com
domain:www.actual-porn.com
domain:www.adultbigmovies.com
domain:www.adult-clips.com
domain:www.adultmoviespad.com
domain:www.ahvids.com
domain:www.al4a.com
domain:www.alexmovies.com
domain:www.allasiangals.com
domain:www.allassgals.com
domain:www.allblackgals.com
domain:www.allblowjobgals.com
domain:www.allbusty.net
domain:www.allbuttgals.com
domain:www.allcelebmovies.com
domain:www.allebonygals.com
domain:www.allgangbanggals.com
domain:www.allgaygals.com
domain:www.allgirlsalley.com
domain:www.allgrannygals.com
domain:www.allhairygals.com
domain:www.allhandjobgals.com
domain:www.allhentaigals.com
domain:www.allhousewifegals.com
domain:www.allindiangals.com
domain:www.alllatinagals.com
domain:www.alllesbiangals.com
domain:www.allmaturegals.com
domain:www.all-nude-celebrities.net
domain:www.all-nude-celebs.net
domain:www.alloldgals.com
domain:www.allpartygals.com
domain:www.allplumpergals.com
domain:www.allpreggogals.com
domain:www.allshavedgals.com
domain:www.allshemalegals.com
domain:www.allsweetbabes.com
domain:www.allthechicks.com
domain:www.alltittygals.com
domain:www.alltrannygals.com
domain:www.allwayslinks.com
domain:www.allwifegals.com
domain:www.alphathumbs.com
domain:www.amandalist.com
domain:www.amandapics.com
domain:www.amateurabuse.com
domain:www.amateurporns.com
domain:www.amatgp.com
domain:www.ambushinterview.com
domain:www.amplandmovies.com
domain:www.amsterdamsexxx.com
domain:www.analx2.com
domain:www.andrewlinks.com
domain:www.angelslinks.com
domain:www.angelsspot.com
domain:www.animaltgp2.com
domain:www.anyvids.com
domain:www.aroundtheworldsex.com
domain:www.asian-eros.com
domain:www.asianladyboytgp.com
domain:www.asianpic.org
domain:www.asianporntgp.com
domain:www.asiansexyshemales.com
domain:www.asiansmaster.com
domain:www.asianzilla.com
domain:www.askjolene.com
domain:www.assfilled.com
domain:www.asspussy.com
domain:www.assuwish.com
domain:www.assuwish.nl
domain:www.auntpolly.com
domain:www.awesomeporn.com
domain:www.babeaddicts.com
domain:www.baberankings.com
domain:www.badassteens.com
domain:www.barely18movies.com
domain:www.bdsmbookmarks.com
domain:www.bdw-movies.com
domain:www.beastyhunt.com
domain:www.beastyporn.com
domain:www.bestfacialmovies.com
domain:www.bestxxxseries.com
domain:www.bgchicks.com
domain:www.bgthumbs.com
domain:www.bigbustymania.com
domain:www.bigtitpornstars.net
domain:www.bigtitscastle.com
domain:www.bigtitsgalleries.com
domain:www.bigtittygals.com
domain:www.bigvids.com
domain:www.bizarre-rituals.com
domain:www.blackgallery.com
domain:www.blackgirls.ws
domain:www.blackporno.net
domain:www.blacksmut.com
domain:www.blaxxxploitation.com
domain:www.bluecelebrities.com
domain:www.blue-kitty.com
domain:www.bluemoonporn.com
domain:www.bobsspot.com
domain:www.boneme.com
domain:www.bonerfuel.com
domain:www.boobbutler.net
domain:www.booblord.com
domain:www.boobslinks.com
domain:www.boobsmates.com
domain:www.boobware.com
domain:www.boobway.org
domain:www.book-mark.net
domain:www.bottomspanked.com
domain:www.bravsfreeporn.com
domain:www.brazilla.com
domain:www.brdteengal.com
domain:www.brutaltgp.com
domain:www.bukkakepool.com
domain:www.bulkmature.com
domain:www.bunnyteens.com
domain:www.busty-stars.net
domain:www.call-kelly.com
domain:www.candycoatedteens.com
domain:www.candylist.com
domain:www.cartoonella.com
domain:www.catlist.com
domain:www.celebbox.com
domain:www.celeb-cafe.net
domain:www.celebrities-collection.com
domain:www.celebritiesempire.com
domain:www.celebrityacademy.com
domain:www.celebritygalleriesfree.com
domain:www.celebsdb.com
domain:www.cherryasia.com
domain:www.chilidot.com
domain:www.chubbyland.com
domain:www.chubbyland.com
domain:www.chubbytgp.com
domain:www.cindymovies.com
domain:www.cleanmoviepost.com
domain:www.clean-porn-movies.com
domain:www.clubsexy.net
domain:www.coedcherry.com
domain:www.connysthumbs.com
domain:www.cowlist.com
domain:www.crazynakedchick.com
domain:www.creamasia.com
domain:www.cultofslavery.com
domain:www.cumshotplanet.com
domain:www.cunt4all.com
domain:www.cutemovies.com
domain:www.dailybasis.com
domain:www.dailypornmovies.com
domain:www.daily-tits.com
domain:www.daily-video.com
domain:www.danishhardcore.net
domain:www.dansmovies.com
domain:www.defaceherface.com
domain:www.deliciousmovies.com
domain:www.digiporn.nl
domain:www.direct-porn.com
domain:www.dirtydaughter.com
domain:www.dirtylittleamateurs.com
domain:www.dirty-movies.com
domain:www.dirtyrhino.com
domain:www.djcelebs.com
domain:www.doctorsexy.com
domain:www.downassbitches.com
domain:www.dragonthumbz.com
domain:www.drunklife.com
domain:www.duckyporn.com
domain:www.easypic.com
domain:www.ebonyabuse.com
domain:www.ebonyblack.net
domain:www.ebonymaster.com
domain:www.ebonyxxxmovies.com
domain:www.edengay.com
domain:www.elephantlist.com
domain:www.elephantlist.com
domain:www.eljardinsecreto.net
domain:www.empirekink.com
domain:www.erobytes.com
domain:www.eroticamoviestation.com
domain:www.erotica-toon.com
domain:www.ethnicmaster.com
domain:www.ethnicpassion.com
domain:www.extrabigboobs.com
domain:www.extreme-anne.com
domain:www.extrememature.com
domain:www.famouspornstars.com
domain:www.fantasyold.com
domain:www.fatfucks.com
domain:www.fathut.com
domain:www.fat-old-movies.com
domain:www.feetmate.com
domain:www.fetishbank.net
domain:www.fetishpig.com
domain:www.finechixxx.com
domain:www.footfetishavenue.com
domain:www.footfetishdirectory.com
domain:www.footfetishgallery.net
domain:www.footster.net
domain:www.foxyteen.net
domain:www.freakthumbs.com
domain:www.free6.com
domain:www.free-adult-celebrities.com
domain:www.freebigmovies.com
domain:www.freeblackmovies.com
domain:www.freefemdom.org
domain:www.freegirlspictures.com
domain:www.freeheaven.com
domain:www.freeheaven.com
domain:www.freemilfs.com
domain:www.freemovieportal.com
domain:www.freemoviesdeluxe.com
domain:www.freepics.tv
domain:www.freepicseries.com
domain:www.free-pics-gallery.com
domain:www.freeporn4you.com
domain:www.free-porn-pages.net
domain:www.freepornpictures.org
domain:www.freepornvideos.tv
domain:www.freesexbomb.com
domain:www.freesexmgp.com
domain:www.free-sex-pics-tgp.com
domain:www.freesex-tgp.com
domain:www.free-teen-babes.com
domain:www.free-teen-sex-sex.com
domain:www.freexsite.com
domain:www.frenchcum.com
domain:www.fuckfaster.com
domain:www.fuckingfreemovies.com
domain:www.fuckk.com
domain:www.fucksakes.net
domain:www.fullvidz.com
domain:www.gaggedlist.com
domain:www.galleries4free.com
domain:www.galleryheaven.com
domain:www.gallerykeepers.com
domain:www.gen-sex.com
domain:www.get-vids.com
domain:www.getyerrocksoff.com
domain:www.goatlist.com
domain:www.goodnightsex.com
domain:www.goth-fetish.com
domain:www.gotmilkers.com
domain:www.grammasthumbs.com
domain:www.grannyfreesex.com
domain:www.grannypictures.com
domain:www.grannyplanet.com
domain:www.granny-post.com
domain:www.grannysextgp.com
domain:www.grannytitty.com
domain:www.hanksgalleries.com
domain:www.hanksgalleries.com
domain:www.hankshoneys.com
domain:www.happypinx.com
domain:www.hardcoregif.com
domain:www.hardcorepornfinder.com
domain:www.hardcorexxx.nl
domain:www.hardcorexxxmpegs.com
domain:www.hardhut.com
domain:www.home-made-videos.com
domain:www.honeymature.com
domain:www.hornyjessica.com
domain:www.horny-pornstar.com
domain:www.hotbabes4u.com
domain:www.hotfreesex4all.com
domain:www.hotfunhouse.com
domain:www.hotjapanesebabes.com
domain:www.hot-lesbian-porn-pictures.com
domain:www.hotorange.net
domain:www.hpornstars.com
domain:www.hqgal.com
domain:www.hqmovies.com
domain:www.hugeboobpics.com
domain:www.hugevids.com
domain:www.humansex.org
domain:www.hydroporn.com
domain:www.idealbabes.net
domain:www.ilovebigbreasts.com
domain:www.imoviepost.com
domain:www.jackstroker.com
domain:www.jamies-galleries.com
domain:www.japanesebeauties.net
domain:www.japanesefuck.com
domain:www.japan-kiss.com
domain:www.jennysbookmarks.com
domain:www.jerk-off-tgp.com
domain:www.jizzhut.com
domain:www.jizzonline.com
domain:www.joggs.com
domain:www.johnnypoker.com
domain:www.juggmovies.com
domain:www.juicyclips.com
domain:www.juicyshemales.com
domain:www.justgetnaked.com
domain:www.kainssexyteens.com
domain:www.kingofboobs.com
domain:www.kinkykarla.com
domain:www.kiss7-11.com
domain:www.kittyvids.com
domain:www.lanasbigboobs.com
domain:www.latexclub.com
domain:www.legfetishpost.com
domain:www.leggytgp.com
domain:www.lesbofuck.com
domain:www.lezpic.com
domain:www.libraryofthumbs.com
domain:www.libraryofthumbs.com
domain:www.lifeofslaves.com
domain:www.live-hot-sex.com
domain:www.longmovies.com
domain:www.lumberjack-links.com
domain:www.madrus.com
domain:www.madthumbs.com
domain:www.massgals.com
domain:www.mature-for-you.com
domain:www.maturehoes.com
domain:www.maturekingdom.com
domain:www.maturelinks.net
domain:www.mature-post.com
domain:www.maxsiu.com
domain:www.megapornolinks.com
domain:www.meoland.com
domain:www.met-free.com
domain:www.mikos-asian-thumbs.com
domain:www.missfemdom.com
domain:www.mmm100.com
domain:www.mobys-free-porn.com
domain:www.mojomansfreeporn.com
domain:www.mom-nude.com
domain:www.moviegalleries.com
domain:www.moviekitten.com
domain:www.moviepost.com
domain:www.moviesgold.com
domain:www.moviesguy.com
domain:www.movieshark.com
domain:www.moviesorgy.com
domain:www.movietitan.com
domain:www.movietomb.com
domain:www.movietrials.com
domain:www.movx.com
domain:www.myfreemilf.com
domain:www.myfreesexmovies.com
domain:www.mypornvids.com
domain:www.mysecretmovies.com
domain:www.n2teens.com
domain:www.nakedcelebspictures.com
domain:www.nastyniches.com
domain:www.nastyrat.com
domain:www.naughtylinks.net
domain:www.need4sex.com
domain:www.nextpicturez.com
domain:www.nipplee.com
domain:www.nipponidols.com
domain:www.no1pics.com
domain:www.nobullshits.com
domain:www.nude-bollywood.com
domain:www.nudecelebsmagazine.com
domain:www.nude-celebs-online.com
domain:www.nudestarz.com
domain:www.nudetitty.com
domain:www.nylonempire.com
domain:www.old69.com
domain:www.olderthumbs.com
domain:www.onlygonzo.net
domain:www.orangetgp.com
domain:www.orgyfuck.com
domain:www.osaka69.com
domain:www.pandamovies.com
domain:www.pantyhosefuckers.com
domain:www.pantyhosemania.com
domain:www.pantyhose-photo-art.com
domain:www.pantylegs.com
domain:www.pantywhores.com
domain:www.paradisex.net
domain:www.paysitetrailers.com
domain:www.p-bot.com
domain:www.peachydream.com
domain:www.perfect-babes.net
domain:www.perfectgirls.net
domain:www.persiankitty.com
domain:www.pervclips.com
domain:www.pichunter.com
domain:www.pinkworld.com
domain:www.planetfootfetish.com
domain:www.playmymovie.com
domain:www.pmsgalleries.com
domain:www.pornchixmovies.com
domain:www.pornno.com
domain:www.pornopanda.com
domain:www.porno-pics-free.com
domain:www.pornranger.net
domain:www.pornstarbook.com
domain:www.pornstarfinder.net
domain:www.pornstargalore.com
domain:www.pornstar-hangout.com
domain:www.pornstarhoes.com
domain:www.pornstarlibrary.com
domain:www.pornstarloverz.com
domain:www.pornstarmoviezone.com
domain:www.pornstar-paradise.com
domain:www.pornstarvid.com
domain:www.pornstar-world.net
domain:www.porntextlinks.com
domain:www.pornthunder.com
domain:www.premiumxxxcore.com
domain:www.purescans.com
domain:www.puresexmovies.com
domain:www.pussy.org
domain:www.pussydivine.com
domain:www.pussy-dreams.com
domain:www.ratedxcafe.com
domain:www.raunchymature.com
domain:www.realbignaturaltits.com
domain:www.realxworld.com
domain:www.redhotlatina.com
domain:www.ricefever.com
domain:www.richardsrealm.com
domain:www.rosethumbs.org
domain:www.rude-bitch.com
domain:www.santasporngirls.com
domain:www.scandalthumbs.com
domain:www.schnaggle.com
domain:www.schoolgirls4all.com
domain:www.schoolgirls-heaven.com
domain:www.screwedupmovies.com
domain:www.secretasiangirls.com
domain:www.series-tgp.com
domain:www.setsofsexygirls.com
domain:www.sex.com
domain:www.sex4it.com
domain:www.sexfoil.com
domain:www.sexgrannies.com
domain:www.sexismylife.com
domain:www.sexkanjer.nl
domain:www.sexmoviesnet.com
domain:www.sexmoviesportal.com
domain:www.sexmoviesworld.com
domain:www.sexoasis.com
domain:www.sexogratis.com.mx
domain:www.sexpoison.com
domain:www.sex-series.net
domain:www.sextitan.com
domain:www.sexwerold.com
domain:www.sexxx.ro
domain:www.sexxxyteenies.net
domain:www.sexyamateurcouples.com
domain:www.sexycelebritygallery.com
domain:www.sexygalleries.com
domain:www.sexyteenmodels.net
domain:www.sexzool.com
domain:www.shemaleexpose.com
domain:www.shemalesfantasy.com
domain:www.shemalesweeties.com
domain:www.shemaletrans.com
domain:www.shemp.com
domain:www.showthumbs.com
domain:www.silent-screams.com
domain:www.simplyvids.com
domain:www.sleazydream.com
domain:www.smileboobs.com
domain:www.smokinmovies.com
domain:www.smutblaster.com
domain:www.smutgod.com
domain:www.snakesworld.com
domain:www.spacethumbs.com
domain:www.spankingtgp.com
domain:www.spermpost.com
domain:www.spermshack.com
domain:www.spunklords.com
domain:www.starcelebs.com
domain:www.starletsofporn.com
domain:www.starletvids.com
domain:www.stickyhole.com
domain:www.stockingsempire.com
domain:www.stockingseries.com
domain:www.stockingtemptation.com
domain:www.sublimedirectory.com
domain:www.sublimepie.com
domain:www.suckbabe.com
domain:www.suckthis7.com
domain:www.sun69.com
domain:www.sunporno.com
domain:www.superhugetits.com
domain:www.superpornlist.com
domain:www.sweetcollegegirls.com
domain:www.sweet-hot-sex.com
domain:www.sweethotteens.com
domain:www.tattletails.com
domain:www.teenaffection.com
domain:www.teenbabes.ca
domain:www.teendolly.com
domain:www.teenfuckin.com
domain:www.teenie-action.com
domain:www.teeniefiles.com
domain:www.teeniemovies.com
domain:www.teeniesxxx.com
domain:www.teenpicseries.com
domain:www.teenplanet4free.com
domain:www.teens-lover.com
domain:www.tgpornstars.com
domain:www.tgpxtreme.com
domain:www.thebestselectiontgp.com
domain:www.thebookofporn.com
domain:www.thecun.com
domain:www.thehun.net
domain:www.thesexmatrice.com
domain:www.thevideodude.com
domain:www.thumbalalaika.com
domain:www.thumbbrain.com
domain:www.thumbgenie.com
domain:www.thumbnailpost.com
domain:www.thumboracle.com
domain:www.thumbzilla.com
domain:www.timsmovies.com
domain:www.tinyteentitties.net
domain:www.titmaniac.com
domain:www.titsfarm.com
domain:www.titsmaster.com
domain:www.todayshentai.com
domain:www.toons-for-adult.com
domain:www.topnudegalleries.com
domain:www.totally-free-bondage.com
domain:www.trannypornmovies.com
domain:www.trannysaloon.com
domain:www.triplecrownthreat.net
domain:www.truegalleries.net
domain:www.tslist.com
domain:www.tspartygirls.com
domain:www.ttporn.com
domain:www.twinkgals.com
domain:www.twinkys.com
domain:www.ultraflix.com
domain:www.ultrahardcoremovies.com
domain:www.ultra-pornstars.com
domain:www.ultrasexmovies.com
domain:www.unrealboobs.com
domain:www.usshemales.com
domain:www.video-post.com
domain:www.videosboard.com
domain:www.vidsgal.com
domain:www.vidsvidsvids.com
domain:www.virtualtgp.com
domain:www.vixen-domme.com
domain:www.voyeurzine.com
domain:www.webporns.com
domain:www.werold4sex.com
domain:www.wet-teen-pussy.net
domain:www.winabegos.com
domain:www.worldsex.com
domain:www.worldvideo.us
domain:www.x3movies.com
domain:www.x-clips.com
domain:www.xgirls.org
domain:www.xmovienow.com
domain:www.xnxx.com
domain:www.xtube.com
domain:www.xxl-tits.com
domain:www.xxx-attack.com
domain:www.xxxgalleries4free.com
domain:www.xxxgroupsex.com
domain:www.xxxstarters.com
domain:www.xxxthumbs4free.com
domain:www.youngerpost.com
domain:www.young-sexy.com
domain:www.your-free-porn.com
domain:www.youwantlinks.com
domain:www.youwantsex.net
domain:www.zthumbs.com

edit:

nochwass, in infected.rar kann ich kein standartpasswort reinmachen. die option gibt es zwar für die dateien aber sie geht nicht.

*Christian* 01.01.2008 20:47

Bitte nehm die beiden EXE-Dateien auch in das Archiv mit rein. Die Text-Dateien können vernachlässigt werden.
Von einigen Virenschutzherstellern wirst du eine Antwort erhalten - von anderen wiederrum nicht.


Anschließend kannst du die Dateien alle im abgesicherten Modus löschen.
Poste dann bitte nochmal ein HijackThis-Log und mache einen Online-Scan mit Kaspersky-AV.


Alle Zeitangaben in WEZ +1. Es ist jetzt 07:07 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131