Sorry :P das ist jettz von dem ersten. Das andere war von dem zweiten
die 3. datei findet der nicht :( Code:
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.10.10.1 2008.10.10 -
AntiVir 7.8.1.34 2008.10.11 -
Authentium 5.1.0.4 2008.10.11 -
Avast 4.8.1248.0 2008.10.10 Win32:Lighty
AVG 8.0.0.161 2008.10.10 Downloader.Generic7.AXLP
BitDefender 7.2 2008.10.11 -
CAT-QuickHeal 9.50 2008.10.11 -
ClamAV 0.93.1 2008.10.11 -
DrWeb 4.44.0.09170 2008.10.11 -
eSafe 7.0.17.0 2008.10.08 -
eTrust-Vet 31.6.6141 2008.10.10 -
Ewido 4.0 2008.10.11 -
F-Prot 4.4.4.56 2008.10.10 -
F-Secure 8.0.14332.0 2008.10.11 Suspicious:W32/Malware!Gemini
Fortinet 3.113.0.0 2008.10.11 -
GData 19 2008.10.11 Win32:Lighty
Ikarus T3.1.1.34.0 2008.10.11 Virus.Win32.Lighty
K7AntiVirus 7.10.491 2008.10.11 -
Kaspersky 7.0.0.125 2008.10.11 -
McAfee 5403 2008.10.11 -
Microsoft 1.4005 2008.10.11 TrojanDownloader:Win32/Renos
NOD32 3515 2008.10.11 a variant of Win32/TrojanDownloader.FakeAlert.LG
Norman 5.80.02 2008.10.10 W32/Lighty.D
Panda 9.0.0.4 2008.10.11 -
PCTools 4.4.2.0 2008.10.11 -
Prevx1 V2 2008.10.11 Cloaked Malware
Rising 20.65.42.00 2008.10.10 -
SecureWeb-Gateway 6.7.6 2008.10.11 -
Sophos 4.34.0 2008.10.11 -
Sunbelt 3.1.1715.1 2008.10.11 -
Symantec 10 2008.10.11 -
TheHacker 6.3.1.0.106 2008.10.10 -
TrendMicro 8.700.0.1004 2008.10.10 -
VBA32 3.12.8.6 2008.10.10 OScope.Downloader.Braviax.3
ViRobot 2008.10.10.1416 2008.10.10 -
VirusBuster 4.5.11.0 2008.10.11 Trojan.DR.Renos.ATB
weitere Informationen
File size: 9728 bytes
MD5...: 2669a713f96a2533c91cd59c4fc79fc4
SHA1..: b0080bc76a15c6a1b41535be9529a4ae324765d1
SHA256: 34b3efbc2658152fed6564682806674a987c28574d17bf741181b86b97e1998e
SHA512: 31879af1c40807a12434ebedf9448532fa2c61bdb05b522c6dbee426f63521b2
c0302a2f1ff008ba4562ab85ba15aeb569a37ffd7ad96bc1a89799ea9bd43306
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x401000
timedatestamp.....: 0x0 (Thu Jan 01 00:00:00 1970)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4000 0x200 4.89 34bd25994ec81ad385c92bb46805cd7e
.data 0x5000 0x3000 0x2000 7.50 6c43ac81f586120d4d00a1ad3594a5cc
.rdata 0x8000 0x3000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0xb000 0x3000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
( 3 imports )
> KERNEL32.DLL: CancelDeviceWakeupRequest, CreateTapePartition, DeleteFileA, ExitProcess, GetCurrentDirectoryW, GetProcessHeap, GetTapeParameters, GetThreadContext, GetVolumeInformationW, GlobalCompact, HeapCreate, HeapFree, HeapValidate, HeapWalk, LoadResource, ReadFileEx, ResetWriteWatch, SleepEx, TerminateThread, WaitCommEvent, lstrcat, lstrcatA
> USER32.DLL: AdjustWindowRectEx, BroadcastSystemMessageA, CharToOemBuffA, DdeGetLastError, DefMDIChildProcW, DeleteMenu, DrawAnimatedRects, DrawCaptionTempA, DrawCaptionTempW, DrawIconEx, GetKBCodePage, GetShellWindow, GetThreadDesktop, IMPGetIMEW, IntersectRect, LockWindowUpdate, MapVirtualKeyExA, RegisterSystemThread, RegisterWindowMessageW, RemovePropW, SendIMEMessageExW, SetDebugErrorLevel, SetMenu, SetWindowRgn, ShowScrollBar, UnhookWinEvent, ValidateRgn
> GDI32.DLL: AnimatePalette, ColorMatchToTarget, CopyMetaFileW, CreateMetaFileW, CreateScalableFontResourceA, CreateScalableFontResourceW, GetAspectRatioFilterEx, GetColorAdjustment, GetEnhMetaFileHeader, GetEnhMetaFileW, GetKerningPairsW, GetMetaRgn, GetPixelFormat, GetTextFaceW, RealizePalette, ResetDCW, SetICMMode, SetPixel, SetViewportOrgEx, SwapBuffers
( 0 exports )
Hier ist das Ergebnis von Malwarebytes. Code:
Malwarebytes' Anti-Malware 1.28
Datenbank Version: 1255
Windows 5.1.2600 Service Pack 2
11.10.2008 16:53:28
mbam-log-2008-10-11 (16-53-28).txt
Scan-Methode: Vollständiger Scan (C:\|F:\|G:\|)
Durchsuchte Objekte: 90539
Laufzeit: 49 minute(s), 12 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 11
Infizierte Registrierungswerte: 6
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 4
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\CLSID\{73D0635E-0B2F-7247-33FF-02C10A20279A} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolband.xttbpos00 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{77d6ddfa-7834-4541-b2b3-a8b0fb0e3924} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4bd2d6c3-31dc-b947-23d0-dc52ec4f0c4c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{855f3b16-6d32-4fe6-8a56-bbb695989046} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolband.xttbpos00.1 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\comdbadm (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winutildb (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{855f3b16-6d32-4fe6-8a56-bbb695989046} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{855f3b16-6d32-4fe6-8a56-bbb695989046} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{855f3b16-6d32-4fe6-8a56-bbb695989046} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\Programme\chcedyf\comdbadm.dll (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spgbijgb.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\Programme\ICQToolbar\toolbaru.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\brastk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. Combofix folgt noch, aber vllt kannst du damit schon was anfangen
LG Fako :) |