![]() |
|
Plagegeister aller Art und deren Bekämpfung: Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter + 2008-04-14 02:23:00 778,240 -c--a-w C:\WINDOWS\system32\dllcache\setup_wm.exe - 2006-02-28 12:00:00 153,600 -c--a-w C:\WINDOWS\system32\dllcache\shmedia.dll + 2008-04-14 02:22:25 154,112 -c--a-w C:\WINDOWS\system32\dllcache\shmedia.dll - 2006-08-24 11:19:40 246,814 -c--a-w C:\WINDOWS\system32\dllcache\strmdll.dll + 2008-04-14 02:22:30 246,814 -c--a-w C:\WINDOWS\system32\dllcache\strmdll.dll - 2008-06-20 10:45:13 360,320 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys + 2008-06-20 11:51:12 361,600 -c----w C:\WINDOWS\system32\dllcache\tcpip.sys - 2008-06-20 09:52:06 225,920 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys + 2008-06-20 11:08:27 225,856 -c----w C:\WINDOWS\system32\dllcache\tcpip6.sys - 2006-02-28 12:00:00 10,240 -c--a-w C:\WINDOWS\system32\dllcache\tmigrate.dll + 2008-04-14 02:21:36 10,240 -c--a-w C:\WINDOWS\system32\dllcache\tmigrate.dll - 2006-02-28 12:00:00 76,288 -c--a-w C:\WINDOWS\system32\dllcache\uniime.dll + 2008-04-14 02:21:37 76,288 -c--a-w C:\WINDOWS\system32\dllcache\uniime.dll - 2006-02-28 12:00:00 212,992 -c--a-w C:\WINDOWS\system32\dllcache\unregmp2.exe + 2008-04-14 02:23:03 212,992 -c--a-w C:\WINDOWS\system32\dllcache\unregmp2.exe - 2006-02-28 12:00:00 426,041 -c--a-w C:\WINDOWS\system32\dllcache\voicepad.dll + 2008-04-14 02:21:38 426,041 -c--a-w C:\WINDOWS\system32\dllcache\voicepad.dll - 2006-02-28 12:00:00 86,073 -c--a-w C:\WINDOWS\system32\dllcache\voicesub.dll + 2008-04-14 02:21:38 86,073 -c--a-w C:\WINDOWS\system32\dllcache\voicesub.dll - 2006-02-28 12:00:00 202,752 -c--a-w C:\WINDOWS\system32\dllcache\wmerror.dll + 2008-04-14 01:54:32 202,752 -c--a-w C:\WINDOWS\system32\dllcache\wmerror.dll - 2007-04-30 00:22:16 4,734,976 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll + 2008-04-14 02:22:32 4,874,240 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll - 2006-02-28 12:00:00 114,688 -c--a-w C:\WINDOWS\system32\dllcache\wmpasf.dll + 2008-04-14 02:22:32 114,688 -c--a-w C:\WINDOWS\system32\dllcache\wmpasf.dll - 2006-02-28 12:00:00 98,304 -c--a-w C:\WINDOWS\system32\dllcache\wmpband.dll + 2008-04-14 02:22:32 98,304 -c--a-w C:\WINDOWS\system32\dllcache\wmpband.dll - 2006-02-28 12:00:00 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpcd.dll + 2008-04-14 02:22:32 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpcd.dll - 2006-02-28 12:00:00 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpcore.dll + 2008-04-14 02:22:32 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpcore.dll - 2006-02-28 12:00:00 233,472 -c--a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll + 2008-04-14 02:22:32 233,472 -c--a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll - 2006-02-28 12:00:00 73,728 -c--a-w C:\WINDOWS\system32\dllcache\wmplayer.exe + 2008-04-14 02:23:06 73,728 -c--a-w C:\WINDOWS\system32\dllcache\wmplayer.exe - 2006-02-28 12:00:00 2,973,696 -c--a-w C:\WINDOWS\system32\dllcache\wmploc.dll + 2008-04-14 01:56:20 2,973,696 -c--a-w C:\WINDOWS\system32\dllcache\wmploc.dll - 2006-02-28 12:00:00 221,184 -c--a-w C:\WINDOWS\system32\dllcache\wmpns.dll + 2008-04-14 02:22:32 221,184 -c--a-w C:\WINDOWS\system32\dllcache\wmpns.dll - 2006-02-28 12:00:00 102,400 -c--a-w C:\WINDOWS\system32\dllcache\wmpshell.dll + 2008-04-14 02:22:32 102,400 -c--a-w C:\WINDOWS\system32\dllcache\wmpshell.dll - 2006-02-28 12:00:00 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpui.dll + 2008-04-14 02:22:32 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmpui.dll - 2006-02-28 12:00:00 115,200 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmoe.dll + 2008-04-14 02:22:32 115,200 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmoe.dll - 2006-02-28 12:00:00 303,616 -c--a-w C:\WINDOWS\system32\dllcache\wmstream.dll + 2008-04-14 02:22:32 303,616 -c--a-w C:\WINDOWS\system32\dllcache\wmstream.dll - 2006-02-28 12:00:00 5,120 ----a-w C:\WINDOWS\system32\dllhost.exe + 2008-04-14 02:22:42 5,120 ----a-w C:\WINDOWS\system32\dllhost.exe - 2006-02-28 12:00:00 225,280 ----a-w C:\WINDOWS\system32\dmadmin.exe + 2008-04-14 02:22:42 225,280 ----a-w C:\WINDOWS\system32\dmadmin.exe - 2006-02-28 12:00:00 28,672 ----a-w C:\WINDOWS\system32\dmband.dll + 2008-04-14 02:22:09 28,672 ----a-w C:\WINDOWS\system32\dmband.dll - 2006-02-28 12:00:00 61,440 ----a-w C:\WINDOWS\system32\dmcompos.dll + 2008-04-14 02:22:09 61,440 ----a-w C:\WINDOWS\system32\dmcompos.dll - 2006-02-28 12:00:00 273,920 ----a-w C:\WINDOWS\system32\dmdlgs.dll + 2008-04-14 02:22:09 285,184 ----a-w C:\WINDOWS\system32\dmdlgs.dll - 2006-02-28 12:00:00 200,704 ----a-w C:\WINDOWS\system32\dmdskmgr.dll + 2008-04-14 02:22:09 200,704 ----a-w C:\WINDOWS\system32\dmdskmgr.dll - 2006-02-28 12:00:00 181,248 ----a-w C:\WINDOWS\system32\dmime.dll + 2008-04-14 02:22:09 181,248 ----a-w C:\WINDOWS\system32\dmime.dll - 2006-02-28 12:00:00 35,840 ----a-w C:\WINDOWS\system32\dmloader.dll + 2008-04-14 02:22:09 35,840 ----a-w C:\WINDOWS\system32\dmloader.dll - 2006-02-28 12:00:00 15,872 ----a-w C:\WINDOWS\system32\dmremote.exe + 2008-04-14 02:22:42 15,872 ----a-w C:\WINDOWS\system32\dmremote.exe - 2006-02-28 12:00:00 82,432 ----a-w C:\WINDOWS\system32\dmscript.dll + 2008-04-14 02:22:09 82,432 ----a-w C:\WINDOWS\system32\dmscript.dll - 2006-02-28 12:00:00 24,064 ----a-w C:\WINDOWS\system32\dmserver.dll + 2008-04-14 02:22:09 24,064 ----a-w C:\WINDOWS\system32\dmserver.dll - 2006-02-28 12:00:00 105,984 ----a-w C:\WINDOWS\system32\dmstyle.dll + 2008-04-14 02:22:09 105,984 ----a-w C:\WINDOWS\system32\dmstyle.dll - 2006-02-28 12:00:00 103,424 ----a-w C:\WINDOWS\system32\dmsynth.dll + 2008-04-14 02:22:09 103,424 ----a-w C:\WINDOWS\system32\dmsynth.dll - 2006-02-28 12:00:00 104,448 ----a-w C:\WINDOWS\system32\dmusic.dll + 2008-04-14 02:22:09 104,448 ----a-w C:\WINDOWS\system32\dmusic.dll - 2006-02-28 12:00:00 59,392 ----a-w C:\WINDOWS\system32\dmutil.dll + 2008-04-14 02:22:09 59,392 ----a-w C:\WINDOWS\system32\dmutil.dll - 2008-06-20 17:39:48 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll + 2008-06-20 17:46:10 147,968 ----a-w C:\WINDOWS\system32\dnsapi.dll - 2008-02-20 05:33:54 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll + 2008-04-14 02:22:09 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll - 2006-02-28 12:00:00 48,640 ----a-w C:\WINDOWS\system32\docprop2.dll + 2008-04-14 02:22:09 48,640 ----a-w C:\WINDOWS\system32\docprop2.dll + 2008-04-14 02:22:09 26,112 ------w C:\WINDOWS\system32\dot3api.dll + 2008-04-14 02:22:09 62,976 ------w C:\WINDOWS\system32\dot3cfg.dll + 2008-04-14 02:22:09 9,216 ------w C:\WINDOWS\system32\dot3dlg.dll + 2008-04-14 02:22:09 39,936 ------w C:\WINDOWS\system32\dot3gpclnt.dll + 2008-04-14 02:22:09 56,832 ------w C:\WINDOWS\system32\dot3msm.dll + 2008-04-14 02:22:09 133,120 ------w C:\WINDOWS\system32\dot3svc.dll + 2008-04-14 02:22:09 651,264 ------w C:\WINDOWS\system32\dot3ui.dll - 2006-02-28 12:00:00 96,768 ----a-w C:\WINDOWS\system32\dpcdll.dll + 2008-04-14 02:22:09 102,912 ----a-w C:\WINDOWS\system32\dpcdll.dll - 2006-02-28 12:00:00 30,208 ----a-w C:\WINDOWS\system32\dplaysvr.exe + 2008-04-14 02:22:43 29,696 ----a-w C:\WINDOWS\system32\dplaysvr.exe - 2006-02-28 12:00:00 229,888 ----a-w C:\WINDOWS\system32\dplayx.dll + 2008-04-14 02:22:09 229,888 ----a-w C:\WINDOWS\system32\dplayx.dll - 2006-02-28 12:00:00 24,064 ----a-w C:\WINDOWS\system32\dpmodemx.dll + 2008-04-14 02:22:09 24,064 ----a-w C:\WINDOWS\system32\dpmodemx.dll - 2006-02-28 12:00:00 3,584 ----a-w C:\WINDOWS\system32\dpnaddr.dll + 2008-04-14 02:20:27 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll - 2006-02-28 12:00:00 375,296 ----a-w C:\WINDOWS\system32\dpnet.dll + 2008-04-14 02:22:09 375,296 ----a-w C:\WINDOWS\system32\dpnet.dll - 2006-02-28 12:00:00 35,328 ----a-w C:\WINDOWS\system32\dpnhpast.dll + 2008-04-14 02:22:09 35,328 ----a-w C:\WINDOWS\system32\dpnhpast.dll - 2006-02-28 12:00:00 60,928 ----a-w C:\WINDOWS\system32\dpnhupnp.dll + 2008-04-14 02:22:09 60,928 ----a-w C:\WINDOWS\system32\dpnhupnp.dll - 2006-02-28 12:00:00 3,584 ----a-w C:\WINDOWS\system32\dpnlobby.dll + 2008-04-14 02:20:27 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll - 2006-02-28 12:00:00 18,432 ----a-w C:\WINDOWS\system32\dpnsvr.exe + 2008-04-14 02:22:43 17,920 ----a-w C:\WINDOWS\system32\dpnsvr.exe - 2006-02-28 12:00:00 21,504 ----a-w C:\WINDOWS\system32\dpvacm.dll + 2008-04-14 02:22:09 21,504 ----a-w C:\WINDOWS\system32\dpvacm.dll - 2006-02-28 12:00:00 214,016 ----a-w C:\WINDOWS\system32\dpvoice.dll + 2008-04-14 02:22:09 214,016 ----a-w C:\WINDOWS\system32\dpvoice.dll - 2006-02-28 12:00:00 83,456 ----a-w C:\WINDOWS\system32\dpvsetup.exe + 2008-04-14 02:22:43 83,456 ----a-w C:\WINDOWS\system32\dpvsetup.exe - 2006-02-28 12:00:00 116,736 ----a-w C:\WINDOWS\system32\dpvvox.dll + 2008-04-14 02:22:09 116,736 ----a-w C:\WINDOWS\system32\dpvvox.dll - 2006-02-28 12:00:00 57,856 ----a-w C:\WINDOWS\system32\dpwsockx.dll + 2008-04-14 02:22:09 57,856 ----a-w C:\WINDOWS\system32\dpwsockx.dll - 2006-02-28 12:00:00 60,928 ----a-w C:\WINDOWS\system32\driverquery.exe + 2008-04-14 02:22:43 65,536 ----a-w C:\WINDOWS\system32\driverquery.exe - 2006-02-28 12:00:00 53,248 ----a-w C:\WINDOWS\system32\drivers\1394bus.sys + 2008-04-13 18:46:18 53,376 ----a-w C:\WINDOWS\system32\drivers\1394bus.sys - 2006-02-28 12:00:00 188,800 ----a-w C:\WINDOWS\system32\drivers\acpi.sys + 2008-04-14 01:49:03 188,800 ----a-w C:\WINDOWS\system32\drivers\acpi.sys + 2008-04-14 02:22:07 4,255 ------w C:\WINDOWS\system32\drivers\adv01nt5.dll + 2008-04-14 02:22:07 3,967 ------w C:\WINDOWS\system32\drivers\adv02nt5.dll + 2008-04-14 02:22:07 3,615 ------w C:\WINDOWS\system32\drivers\adv05nt5.dll + 2008-04-14 02:22:07 3,647 ------w C:\WINDOWS\system32\drivers\adv07nt5.dll + 2008-04-14 02:22:07 3,135 ------w C:\WINDOWS\system32\drivers\adv08nt5.dll + 2008-04-14 02:22:07 3,711 ------w C:\WINDOWS\system32\drivers\adv09nt5.dll + 2008-04-14 02:22:07 3,775 ------w C:\WINDOWS\system32\drivers\adv11nt5.dll - 2006-02-15 00:22:26 142,464 ----a-w C:\WINDOWS\system32\drivers\aec.sys + 2008-04-13 16:39:23 142,592 ----a-w C:\WINDOWS\system32\drivers\aec.sys - 2008-06-20 10:44:38 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys + 2008-06-20 11:40:08 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys + 2008-04-13 18:36:38 42,368 ------w C:\WINDOWS\system32\drivers\agp440.sys + 2008-04-13 18:36:39 44,928 ------w C:\WINDOWS\system32\drivers\agpcpq.sys + 2008-04-13 18:36:38 42,752 ------w C:\WINDOWS\system32\drivers\alim1541.sys + 2008-04-13 18:36:39 43,008 ------w C:\WINDOWS\system32\drivers\amdagp.sys - 2006-02-28 12:00:00 41,088 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys + 2008-04-14 01:50:05 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys - 2006-02-28 12:00:00 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys + 2008-04-14 01:50:06 41,856 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys - 2006-02-28 12:00:00 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys + 2008-04-13 18:51:25 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys - 2006-02-28 12:00:00 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys + 2008-04-13 18:57:27 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys - 2006-02-28 12:00:00 95,360 ----a-w C:\WINDOWS\system32\drivers\atapi.sys + 2008-04-13 18:40:30 96,512 ----a-w C:\WINDOWS\system32\drivers\atapi.sys + 2004-08-03 20:29:30 56,623 ------w C:\WINDOWS\system32\drivers\ati1btxx.sys + 2004-08-03 20:29:30 11,615 ------w C:\WINDOWS\system32\drivers\ati1mdxx.sys + 2004-08-03 20:29:30 12,047 ------w C:\WINDOWS\system32\drivers\ati1pdxx.sys + 2004-08-03 20:29:32 30,671 ------w C:\WINDOWS\system32\drivers\ati1raxx.sys + 2004-08-03 20:29:32 63,663 ------w C:\WINDOWS\system32\drivers\ati1rvxx.sys + 2004-08-03 20:29:32 26,367 ------w C:\WINDOWS\system32\drivers\ati1snxx.sys + 2004-08-03 20:29:32 21,343 ------w C:\WINDOWS\system32\drivers\ati1ttxx.sys + 2004-08-03 20:29:32 36,463 ------w C:\WINDOWS\system32\drivers\ati1tuxx.sys + 2004-08-03 20:29:32 29,455 ------w C:\WINDOWS\system32\drivers\ati1xbxx.sys + 2004-08-03 20:29:32 34,735 ------w C:\WINDOWS\system32\drivers\ati1xsxx.sys + 2004-08-03 22:38:56 327,168 ------w C:\WINDOWS\system32\drivers\ati2mtaa.sys + 2004-08-03 20:29:28 57,856 ------w C:\WINDOWS\system32\drivers\atinbtxx.sys + 2004-08-03 20:29:30 13,824 ------w C:\WINDOWS\system32\drivers\atinmdxx.sys + 2004-08-03 20:29:30 14,336 ------w C:\WINDOWS\system32\drivers\atinpdxx.sys + 2004-08-03 20:29:30 52,224 ------w C:\WINDOWS\system32\drivers\atinraxx.sys + 2004-08-03 20:29:32 104,960 ------w C:\WINDOWS\system32\drivers\atinrvxx.sys + 2004-08-03 20:29:32 28,672 ------w C:\WINDOWS\system32\drivers\atinsnxx.sys + 2004-08-03 20:29:32 13,824 ------w C:\WINDOWS\system32\drivers\atinttxx.sys + 2004-08-03 20:29:32 73,216 ------w C:\WINDOWS\system32\drivers\atintuxx.sys + 2004-08-03 20:29:32 31,744 ------w C:\WINDOWS\system32\drivers\atinxbxx.sys + 2004-08-03 20:29:32 63,488 ------w C:\WINDOWS\system32\drivers\atinxsxx.sys - 2006-02-28 12:00:00 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys + 2008-04-13 18:51:25 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys - 2006-02-28 12:00:00 55,936 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys + 2008-04-13 18:51:30 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys + 2008-04-14 02:22:07 21,183 ------w C:\WINDOWS\system32\drivers\atv01nt5.dll + 2008-04-14 02:22:07 11,359 ------w C:\WINDOWS\system32\drivers\atv02nt5.dll + 2008-04-14 02:22:07 25,471 ------w C:\WINDOWS\system32\drivers\atv04nt5.dll + 2008-04-14 02:22:07 14,143 ------w C:\WINDOWS\system32\drivers\atv06nt5.dll + 2008-04-14 02:22:07 17,279 ------w C:\WINDOWS\system32\drivers\atv10nt5.dll - 2006-02-28 12:00:00 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys + 2008-04-13 18:53:23 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys + 2008-04-13 18:46:33 17,024 ------w C:\WINDOWS\system32\drivers\bthenum.sys + 2008-04-13 18:46:33 37,888 ------w C:\WINDOWS\system32\drivers\bthmodem.sys + 2008-04-13 18:51:34 101,120 ------w C:\WINDOWS\system32\drivers\bthpan.sys - 2008-06-14 17:57:40 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys + 2008-06-14 17:32:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys + 2008-04-13 18:46:31 36,480 ------w C:\WINDOWS\system32\drivers\bthprint.sys + 2008-04-13 18:46:29 18,944 ------w C:\WINDOWS\system32\drivers\bthusb.sys - 2006-02-28 12:00:00 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys + 2008-04-13 19:14:21 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys - 2006-02-28 12:00:00 49,536 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys + 2008-04-13 18:40:46 62,976 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys + 2008-04-14 02:22:07 15,423 ------w C:\WINDOWS\system32\drivers\ch7xxnt5.dll - 2006-02-28 12:00:00 49,664 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys + 2008-04-13 19:16:22 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys - 2006-02-28 12:00:00 40,576 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys + 2008-04-14 01:56:30 40,832 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys - 2006-02-28 12:00:00 36,352 ----a-w C:\WINDOWS\system32\drivers\disk.sys + 2008-04-13 18:40:47 36,352 ----a-w C:\WINDOWS\system32\drivers\disk.sys - 2006-02-28 12:00:00 14,208 ----a-w C:\WINDOWS\system32\drivers\diskdump.sys + 2008-04-13 18:40:44 14,208 ----a-w C:\WINDOWS\system32\drivers\diskdump.sys - 2006-02-28 12:00:00 800,384 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys + 2008-04-14 01:58:13 800,384 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys - 2006-02-28 12:00:00 154,112 ----a-w C:\WINDOWS\system32\drivers\dmio.sys + 2008-04-14 01:58:18 154,112 ----a-w C:\WINDOWS\system32\drivers\dmio.sys - 2004-08-03 22:07:40 52,864 ----a-w C:\WINDOWS\system32\drivers\DMusic.sys + 2008-04-13 18:45:01 52,864 ----a-w C:\WINDOWS\system32\drivers\dmusic.sys - 2004-08-03 21:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys + 2008-04-13 18:45:14 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys - 2004-08-03 22:07:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys + 2008-04-13 18:45:13 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys - 2006-02-28 12:00:00 71,040 ----a-w C:\WINDOWS\system32\drivers\dxg.sys + 2008-04-13 18:38:29 71,168 ----a-w C:\WINDOWS\system32\drivers\dxg.sys - 2006-02-28 12:00:00 143,360 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys + 2008-04-13 19:14:29 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys - 2006-02-28 12:00:00 27,392 ----a-w C:\WINDOWS\system32\drivers\fdc.sys + 2008-04-13 18:40:25 27,392 ----a-w C:\WINDOWS\system32\drivers\fdc.sys - 2006-02-28 12:00:00 35,072 ----a-w C:\WINDOWS\system32\drivers\fips.sys + 2008-04-14 01:52:51 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys - 2006-02-28 12:00:00 20,480 ----a-w C:\WINDOWS\system32\drivers\flpydisk.sys + 2008-04-13 18:40:25 20,480 ----a-w C:\WINDOWS\system32\drivers\flpydisk.sys - 2006-08-21 09:14:58 128,896 ----a-w C:\WINDOWS\system32\drivers\fltmgr.sys + 2008-04-13 18:32:59 129,792 ----a-w C:\WINDOWS\system32\drivers\fltmgr.sys + 2008-04-13 18:36:40 46,464 ------w C:\WINDOWS\system32\drivers\gagp30kx.sys + 2008-04-13 16:36:05 144,384 ------w C:\WINDOWS\system32\drivers\hdaudbus.sys + 2008-04-14 01:54:49 25,856 ------w C:\WINDOWS\system32\drivers\hidbth.sys - 2006-02-28 12:00:00 36,224 ----a-w C:\WINDOWS\system32\drivers\hidclass.sys + 2008-04-13 18:45:26 36,864 ----a-w C:\WINDOWS\system32\drivers\hidclass.sys + 2008-04-13 18:45:26 19,200 ------w C:\WINDOWS\system32\drivers\hidir.sys - 2006-02-28 12:00:00 24,960 ----a-w C:\WINDOWS\system32\drivers\hidparse.sys + 2008-04-13 18:45:22 24,960 ----a-w C:\WINDOWS\system32\drivers\hidparse.sys - 2001-08-17 12:02:20 9,600 ----a-w C:\WINDOWS\system32\drivers\hidusb.sys + 2008-04-13 18:45:27 10,368 ----a-w C:\WINDOWS\system32\drivers\hidusb.sys + 2004-08-03 20:41:48 220,032 ------w C:\WINDOWS\system32\drivers\hsfbs2s2.sys + 2004-08-03 20:41:50 685,056 ------w C:\WINDOWS\system32\drivers\hsfcxts2.sys + 2004-08-03 20:41:56 1,041,536 ------w C:\WINDOWS\system32\drivers\hsfdpsp2.sys - 2006-03-17 00:33:10 262,784 ----a-w C:\WINDOWS\system32\drivers\http.sys + 2008-04-13 18:53:53 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys - 2006-02-28 12:00:00 53,248 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys + 2008-04-14 01:55:34 52,992 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys - 2006-02-28 12:00:00 41,856 ----a-w C:\WINDOWS\system32\drivers\imapi.sys + 2008-04-13 18:40:58 42,112 ----a-w C:\WINDOWS\system32\drivers\imapi.sys - 2006-02-28 12:00:00 40,192 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys + 2008-04-14 01:57:20 40,448 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys - 2006-02-28 12:00:00 29,056 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys + 2008-04-13 18:53:34 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys - 2006-02-28 12:00:00 20,992 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys + 2008-04-13 18:57:07 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys - 2004-09-29 22:28:37 134,912 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys + 2008-04-13 18:57:15 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys - 2006-02-28 12:00:00 74,752 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys + 2008-04-13 19:19:42 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys + 2008-04-13 18:45:34 46,592 ------w C:\WINDOWS\system32\drivers\irbus.sys - 2006-02-28 12:00:00 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys + 2008-04-13 18:54:28 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys - 2006-02-28 12:00:00 36,224 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys + 2008-04-14 01:58:03 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys - 2006-02-28 12:00:00 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys + 2008-04-14 01:58:36 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys - 2006-06-14 08:47:45 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys + 2008-04-13 18:45:09 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys - 2004-08-03 21:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys + 2008-04-13 19:16:36 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys - 2006-02-28 12:00:00 92,032 ----a-w C:\WINDOWS\system32\drivers\ksecdd.sys + 2008-04-13 18:31:43 92,288 ----a-w C:\WINDOWS\system32\drivers\ksecdd.sys + 2004-08-03 20:41:56 11,868 ------w C:\WINDOWS\system32\drivers\mdmxsdk.sys - 2006-02-28 12:00:00 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys + 2008-04-13 18:36:41 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys - 2006-02-28 12:00:00 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys + 2008-04-14 01:49:32 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys - 2006-02-28 12:00:00 23,552 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys + 2008-04-14 01:49:36 23,552 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys - 2006-02-28 12:00:00 42,240 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys + 2008-04-13 18:39:46 42,368 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys - 2007-07-06 10:05:47 72,960 ----a-w C:\WINDOWS\system32\drivers\mqac.sys + 2008-04-13 18:39:44 92,544 ----a-w C:\WINDOWS\system32\drivers\mqac.sys - 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys + 2008-04-13 18:32:44 180,608 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys - 2006-05-05 09:41:45 453,120 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys + 2008-04-13 19:17:01 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys - 2006-02-28 12:00:00 19,072 ----a-w C:\WINDOWS\system32\drivers\msfs.sys + 2008-04-13 18:32:39 19,072 ----a-w C:\WINDOWS\system32\drivers\msfs.sys - 2006-02-28 12:00:00 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys + 2008-04-13 18:56:32 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys - 2004-08-03 21:58:42 7,552 ----a-w C:\WINDOWS\system32\drivers\MSKSSRV.sys + 2008-04-13 18:39:52 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys - 2004-08-03 21:58:40 5,376 ----a-w C:\WINDOWS\system32\drivers\MSPCLOCK.sys + 2008-04-13 18:39:50 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys - 2004-08-03 21:58:42 4,992 ----a-w C:\WINDOWS\system32\drivers\MSPQM.sys + 2008-04-13 18:39:51 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys - 2006-02-28 12:00:00 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys + 2008-04-13 18:36:46 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys + 2004-08-03 20:41:40 126,686 ------w C:\WINDOWS\system32\drivers\mtlmnt5.sys + 2004-08-03 20:41:38 1,309,184 ------w C:\WINDOWS\system32\drivers\mtlstrm.sys + 2004-08-03 20:29:38 452,736 ------w C:\WINDOWS\system32\drivers\mtxparhm.sys - 2006-02-28 12:00:00 107,904 ----a-w C:\WINDOWS\system32\drivers\mup.sys + 2008-04-13 19:17:05 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys + 2008-04-13 18:43:55 12,672 ------w C:\WINDOWS\system32\drivers\mutohpen.sys - 2006-02-28 12:00:00 182,912 ----a-w C:\WINDOWS\system32\drivers\ndis.sys + 2008-04-13 19:20:37 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys - 2006-02-28 12:00:00 9,600 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys + 2008-04-13 18:57:27 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys - 2006-02-28 12:00:00 12,928 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys + 2008-04-13 18:55:58 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys - 2006-02-28 12:00:00 91,776 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys + 2008-04-13 19:20:42 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys - 2006-02-28 12:00:00 38,016 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys + 2008-04-13 18:57:29 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys - 2006-02-28 12:00:00 34,560 ----a-w C:\WINDOWS\system32\drivers\netbios.sys + 2008-04-13 18:56:02 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys |
![]() | #2 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2005-10-20 22:25:05 1,094,144 ----a-w C:\WINDOWS\system32\esent.dll + 2008-04-14 02:22:10 1,094,144 ----a-w C:\WINDOWS\system32\esent.dll - 2006-02-28 12:00:00 195,584 ----a-w C:\WINDOWS\system32\eudcedit.exe + 2008-04-14 02:22:44 195,584 ----a-w C:\WINDOWS\system32\eudcedit.exe - 2006-02-28 12:00:00 52,224 ----a-w C:\WINDOWS\system32\eventcreate.exe + 2008-04-14 02:22:44 52,736 ----a-w C:\WINDOWS\system32\eventcreate.exe - 2006-02-28 12:00:00 55,808 ----a-w C:\WINDOWS\system32\eventlog.dll + 2008-04-14 02:22:10 56,320 ----a-w C:\WINDOWS\system32\eventlog.dll - 2006-02-28 12:00:00 80,384 ----a-w C:\WINDOWS\system32\eventtriggers.exe + 2008-04-14 02:22:44 85,504 ----a-w C:\WINDOWS\system32\eventtriggers.exe - 2006-02-28 12:00:00 380,957 ----a-w C:\WINDOWS\system32\expsrv.dll + 2008-04-14 02:22:10 380,445 ----a-w C:\WINDOWS\system32\expsrv.dll - 2006-02-28 12:00:00 45,568 ----a-w C:\WINDOWS\system32\extrac32.exe + 2008-04-14 02:22:45 24,064 ----a-w C:\WINDOWS\system32\extrac32.exe - 2006-02-28 12:00:00 121,856 ----a-w C:\WINDOWS\system32\exts.dll + 2008-04-14 02:22:10 125,952 ----a-w C:\WINDOWS\system32\exts.dll - 2006-02-28 12:00:00 80,896 ----a-w C:\WINDOWS\system32\faultrep.dll + 2008-04-14 02:22:10 80,896 ----a-w C:\WINDOWS\system32\faultrep.dll + 2008-04-14 02:22:45 20,992 ------w C:\WINDOWS\system32\faxpatch.exe - 2006-02-28 12:00:00 118,784 ----a-w C:\WINDOWS\system32\fde.dll + 2008-04-14 02:22:10 125,952 ----a-w C:\WINDOWS\system32\fde.dll - 2006-02-28 12:00:00 76,800 ----a-w C:\WINDOWS\system32\fdeploy.dll + 2008-04-14 02:22:10 76,800 ----a-w C:\WINDOWS\system32\fdeploy.dll - 2006-02-28 12:00:00 21,504 ----a-w C:\WINDOWS\system32\feclient.dll + 2008-04-14 02:22:10 21,504 ----a-w C:\WINDOWS\system32\feclient.dll - 2006-02-28 12:00:00 345,600 ----a-w C:\WINDOWS\system32\filemgmt.dll + 2008-04-14 02:22:10 345,600 ----a-w C:\WINDOWS\system32\filemgmt.dll - 2006-02-28 12:00:00 28,160 ----a-w C:\WINDOWS\system32\findstr.exe + 2008-04-14 02:22:45 28,160 ----a-w C:\WINDOWS\system32\findstr.exe - 2006-02-28 12:00:00 88,576 ----a-w C:\WINDOWS\system32\fldrclnr.dll + 2008-04-14 02:22:10 88,576 ----a-w C:\WINDOWS\system32\fldrclnr.dll - 2006-08-21 12:26:05 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll + 2008-04-14 02:22:10 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll - 2006-08-21 09:14:58 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe + 2008-04-14 02:22:46 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe |
![]() | #3 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2006-02-28 12:00:00 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys + 2008-04-13 19:21:00 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys - 2006-02-28 12:00:00 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys + 2008-04-13 18:51:25 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys - 2006-02-28 12:00:00 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys + 2008-04-13 18:53:09 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys - 2006-02-28 12:00:00 30,848 ----a-w C:\WINDOWS\system32\drivers\npfs.sys + 2008-04-13 18:32:39 30,848 ----a-w C:\WINDOWS\system32\drivers\npfs.sys - 2007-02-09 11:10:35 574,464 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys + 2008-04-13 19:15:53 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys + 2004-08-03 20:41:40 180,360 ------w C:\WINDOWS\system32\drivers\ntmtlfax.sys - 2006-02-28 12:00:00 88,448 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys + 2008-04-13 18:56:06 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys - 2006-10-13 10:23:15 163,584 ----a-w C:\WINDOWS\system32\drivers\nwrdr.sys + 2008-04-13 18:34:12 163,584 ----a-w C:\WINDOWS\system32\drivers\nwrdr.sys - 2006-02-28 12:00:00 61,056 ----a-w C:\WINDOWS\system32\drivers\ohci1394.sys + 2008-04-13 18:46:18 61,696 ----a-w C:\WINDOWS\system32\drivers\ohci1394.sys - 2006-02-28 12:00:00 46,592 ----a-w C:\WINDOWS\system32\drivers\p3.sys + 2008-04-14 02:02:08 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys - 2006-02-28 12:00:00 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys + 2008-04-14 02:02:10 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys - 2006-02-28 12:00:00 18,688 ----a-w C:\WINDOWS\system32\drivers\partmgr.sys + 2008-04-13 18:40:49 19,712 ----a-w C:\WINDOWS\system32\drivers\partmgr.sys - 2006-02-28 12:00:00 68,224 ----a-w C:\WINDOWS\system32\drivers\pci.sys + 2008-04-14 02:02:13 68,224 ----a-w C:\WINDOWS\system32\drivers\pci.sys - 2006-02-28 12:00:00 25,088 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys + 2008-04-13 18:40:29 24,960 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys - 2006-02-28 12:00:00 120,320 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys + 2008-04-14 02:02:16 120,576 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys - 2004-08-03 21:15:50 145,792 ----a-w C:\WINDOWS\system32\drivers\portcls.sys + 2008-04-13 19:19:41 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys - 2006-02-28 12:00:00 39,424 ----a-w C:\WINDOWS\system32\drivers\processr.sys + 2008-04-14 01:51:21 39,936 ----a-w C:\WINDOWS\system32\drivers\processr.sys - 2006-02-28 12:00:00 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys + 2008-04-13 18:56:38 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys - 2006-02-28 12:00:00 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys + 2008-04-13 19:19:43 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys - 2006-02-28 12:00:00 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys + 2008-04-13 18:57:32 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys - 2006-02-28 12:00:00 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys + 2008-04-13 19:19:48 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys - 2006-05-05 09:47:57 174,592 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys + 2008-04-13 19:28:39 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys - 2004-08-03 21:01:16 196,864 ----a-w C:\WINDOWS\system32\drivers\rdpdr.sys + 2008-04-13 18:32:51 196,224 ----a-w C:\WINDOWS\system32\drivers\rdpdr.sys - 2005-06-10 04:10:27 139,528 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys + 2008-04-14 02:23:27 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys + 2004-08-03 20:41:40 13,776 ------w C:\WINDOWS\system32\drivers\recagent.sys - 2004-08-03 23:40:08 57,600 ----a-w C:\WINDOWS\system32\drivers\redbook.sys + 2008-04-14 01:52:51 57,728 ----a-w C:\WINDOWS\system32\drivers\redbook.sys + 2008-04-13 18:46:32 59,136 ------w C:\WINDOWS\system32\drivers\rfcomm.sys - 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys + 2008-05-08 14:02:52 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys - 2006-02-28 12:00:00 30,080 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys + 2008-04-13 18:56:49 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys + 2008-04-13 18:56:49 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys + 2004-08-03 20:29:52 166,912 ------w C:\WINDOWS\system32\drivers\s3gnbm.sys - 2006-02-28 12:00:00 96,256 ----a-w C:\WINDOWS\system32\drivers\scsiport.sys + 2008-04-13 18:40:30 96,384 ----a-w C:\WINDOWS\system32\drivers\scsiport.sys - 2006-02-28 12:00:00 67,584 ----a-w C:\WINDOWS\system32\drivers\sdbus.sys + 2008-04-13 18:36:44 79,232 ----a-w C:\WINDOWS\system32\drivers\sdbus.sys - 2006-02-28 12:00:00 15,488 ----a-w C:\WINDOWS\system32\drivers\serenum.sys + 2008-04-13 18:40:12 15,744 ----a-w C:\WINDOWS\system32\drivers\serenum.sys - 2006-02-28 12:00:00 65,920 ----a-w C:\WINDOWS\system32\drivers\serial.sys + 2008-04-14 01:54:59 65,536 ----a-w C:\WINDOWS\system32\drivers\serial.sys - 2006-02-28 12:00:00 11,136 ----a-w C:\WINDOWS\system32\drivers\sffdisk.sys + 2008-04-13 18:40:47 11,904 ----a-w C:\WINDOWS\system32\drivers\sffdisk.sys + 2008-04-13 18:40:48 10,240 ------w C:\WINDOWS\system32\drivers\sffp_mmc.sys - 2006-02-28 12:00:00 10,240 ----a-w C:\WINDOWS\system32\drivers\sffp_sd.sys + 2008-04-13 18:40:47 11,008 ----a-w C:\WINDOWS\system32\drivers\sffp_sd.sys - 2006-02-28 12:00:00 11,392 ----a-w C:\WINDOWS\system32\drivers\sfloppy.sys + 2008-04-13 18:40:48 11,392 ----a-w C:\WINDOWS\system32\drivers\sfloppy.sys + 2008-04-14 02:22:25 3,901 ------w C:\WINDOWS\system32\drivers\siint5.dll + 2008-04-13 18:36:39 40,960 ------w C:\WINDOWS\system32\drivers\sisagp.sys + 2004-08-03 20:41:42 129,535 ------w C:\WINDOWS\system32\drivers\slnt7554.sys + 2004-08-03 20:41:44 404,990 ------w C:\WINDOWS\system32\drivers\slntamr.sys + 2004-08-03 20:41:46 95,424 ------w C:\WINDOWS\system32\drivers\slnthal.sys + 2004-08-03 20:41:46 13,240 ------w C:\WINDOWS\system32\drivers\slwdmsup.sys + 2008-04-13 18:36:34 5,888 ------w C:\WINDOWS\system32\drivers\smbali.sys - 2006-02-28 12:00:00 25,472 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys + 2008-04-13 18:46:07 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys - 2006-06-14 08:47:46 6,400 ----a-w C:\WINDOWS\system32\drivers\splitter.sys + 2008-04-13 18:45:07 6,272 ----a-w C:\WINDOWS\system32\drivers\splitter.sys - 2006-02-28 12:00:00 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys + 2008-04-14 02:02:33 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys - 2006-08-14 10:34:41 332,928 ----a-w C:\WINDOWS\system32\drivers\srv.sys + 2008-04-13 19:15:11 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys - 2004-08-03 21:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys + 2008-04-13 18:45:15 49,408 ----a-w C:\WINDOWS\system32\drivers\stream.sys - 2006-02-28 12:00:00 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys + 2008-04-13 18:39:53 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys - 2001-08-17 13:00:52 54,272 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys + 2008-04-13 18:45:09 56,576 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys - 2004-08-03 22:15:56 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys + 2008-04-13 19:15:55 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys - 2006-02-28 12:00:00 14,976 ----a-w C:\WINDOWS\system32\drivers\tape.sys + 2008-04-13 18:40:50 14,976 ----a-w C:\WINDOWS\system32\drivers\tape.sys - 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys + 2008-06-20 11:51:12 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys - 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys + 2008-06-20 11:08:27 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys - 2006-02-28 12:00:00 18,560 ----a-w C:\WINDOWS\system32\drivers\tdi.sys + 2008-04-13 19:00:05 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys - 2006-02-28 12:00:00 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys + 2008-04-14 02:23:26 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys - 2006-02-28 12:00:00 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys + 2008-04-14 02:23:26 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys - 2004-08-03 22:58:36 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys + 2008-04-14 02:23:26 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys - 2006-02-28 12:00:00 12,416 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys + 2008-04-13 18:56:01 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys + 2008-04-13 18:36:40 44,672 ------w C:\WINDOWS\system32\drivers\uagp35.sys - 2006-02-28 12:00:00 66,176 ----a-w C:\WINDOWS\system32\drivers\udfs.sys + 2008-04-13 18:32:36 66,048 ----a-w C:\WINDOWS\system32\drivers\udfs.sys - 2006-02-28 12:00:00 209,408 ----a-w C:\WINDOWS\system32\drivers\update.sys + 2008-04-13 18:39:46 384,768 ----a-w C:\WINDOWS\system32\drivers\update.sys - 2006-02-28 12:00:00 12,672 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys + 2008-04-13 18:56:49 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys + 2008-04-13 18:56:49 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys - 2004-08-03 22:07:56 59,264 ----a-w C:\WINDOWS\system32\drivers\USBAUDIO.sys + 2008-04-13 18:45:12 60,032 ----a-w C:\WINDOWS\system32\drivers\usbaudio.sys - 2006-02-28 12:00:00 23,808 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys + 2008-04-13 18:45:40 25,600 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys - 2006-02-28 12:00:00 23,936 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys + 2008-04-13 18:45:41 25,728 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys - 2006-02-28 12:00:00 31,616 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys + 2008-04-13 18:45:39 32,128 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys - 2006-02-28 12:00:00 26,624 ----a-w C:\WINDOWS\system32\drivers\usbehci.sys + 2008-04-13 18:45:35 30,208 ----a-w C:\WINDOWS\system32\drivers\usbehci.sys - 2006-02-28 12:00:00 57,600 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys + 2008-04-13 18:45:37 59,520 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys - 2006-02-28 12:00:00 16,000 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys + 2008-04-13 18:45:43 15,872 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys - 2006-02-28 12:00:00 17,024 ----a-w C:\WINDOWS\system32\drivers\usbohci.sys + 2008-04-13 18:45:35 17,152 ----a-w C:\WINDOWS\system32\drivers\usbohci.sys - 2006-02-28 12:00:00 142,976 ----a-w C:\WINDOWS\system32\drivers\usbport.sys + 2008-04-13 18:45:36 143,872 ----a-w C:\WINDOWS\system32\drivers\usbport.sys - 2004-08-03 21:08:48 26,496 ----a-w C:\WINDOWS\system32\drivers\USBSTOR.SYS + 2008-04-13 18:45:38 26,368 ----a-w C:\WINDOWS\system32\drivers\usbstor.sys + 2008-04-13 18:46:20 121,984 ------w C:\WINDOWS\system32\drivers\usbvideo.sys + 2008-04-14 02:22:31 11,325 ------w C:\WINDOWS\system32\drivers\vchnt5.dll - 2006-02-28 12:00:00 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys + 2008-04-13 18:44:40 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys + 2008-04-13 18:36:40 42,240 ------w C:\WINDOWS\system32\drivers\viaagp.sys - 2006-02-28 12:00:00 79,744 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys + 2008-04-13 18:44:40 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys - 2006-02-28 12:00:00 53,760 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys + 2008-04-14 01:52:02 53,760 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys + 2008-04-13 18:43:55 14,208 ------w C:\WINDOWS\system32\drivers\wacompen.sys + 2004-08-03 20:29:40 11,807 ------w C:\WINDOWS\system32\drivers\wadv07nt.sys + 2004-08-03 20:29:40 11,295 ------w C:\WINDOWS\system32\drivers\wadv08nt.sys + 2004-08-03 20:29:42 11,871 ------w C:\WINDOWS\system32\drivers\wadv09nt.sys + 2004-08-03 20:29:42 11,935 ------w C:\WINDOWS\system32\drivers\wadv11nt.sys - 2006-02-28 12:00:00 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys + 2008-04-13 18:57:21 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys + 2004-08-03 20:29:46 22,271 ------w C:\WINDOWS\system32\drivers\watv06nt.sys + 2004-08-03 20:29:46 25,471 ------w C:\WINDOWS\system32\drivers\watv10nt.sys - 2006-06-14 09:00:45 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys + 2008-04-13 19:17:18 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys - 2006-02-28 12:00:00 14,336 ----a-w C:\WINDOWS\system32\drprov.dll + 2008-04-14 02:22:09 14,336 ----a-w C:\WINDOWS\system32\drprov.dll - 2006-02-28 12:00:00 16,384 ----a-w C:\WINDOWS\system32\ds32gt.dll + 2008-04-14 02:22:09 16,384 ----a-w C:\WINDOWS\system32\ds32gt.dll - 2006-02-28 12:00:00 181,760 ----a-w C:\WINDOWS\system32\dsdmo.dll + 2008-04-14 02:22:09 181,248 ----a-w C:\WINDOWS\system32\dsdmo.dll - 2006-02-28 12:00:00 74,240 ----a-w C:\WINDOWS\system32\dsdmoprp.dll + 2008-04-14 02:22:09 74,240 ----a-w C:\WINDOWS\system32\dsdmoprp.dll - 2006-02-28 12:00:00 93,184 ----a-w C:\WINDOWS\system32\dskquota.dll + 2008-04-14 02:22:09 93,184 ----a-w C:\WINDOWS\system32\dskquota.dll - 2006-02-28 12:00:00 149,504 ----a-w C:\WINDOWS\system32\dskquoui.dll + 2008-04-14 02:22:09 160,768 ----a-w C:\WINDOWS\system32\dskquoui.dll - 2006-02-28 12:00:00 367,616 ----a-w C:\WINDOWS\system32\dsound.dll + 2008-04-14 02:22:09 367,616 ----a-w C:\WINDOWS\system32\dsound.dll - 2006-02-28 12:00:00 1,294,336 ----a-w C:\WINDOWS\system32\dsound3d.dll + 2008-04-14 02:22:09 1,293,824 ----a-w C:\WINDOWS\system32\dsound3d.dll - 2006-02-28 12:00:00 146,432 ----a-w C:\WINDOWS\system32\dsprop.dll + 2008-04-14 02:22:09 146,944 ----a-w C:\WINDOWS\system32\dsprop.dll - 2006-02-28 12:00:00 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll + 2008-04-14 01:59:20 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll - 2006-02-28 12:00:00 240,128 ----a-w C:\WINDOWS\system32\dsquery.dll + 2008-04-14 02:22:09 240,128 ----a-w C:\WINDOWS\system32\dsquery.dll - 2006-02-28 12:00:00 52,224 ----a-w C:\WINDOWS\system32\dssec.dll + 2008-04-14 02:22:09 52,224 ----a-w C:\WINDOWS\system32\dssec.dll - 2006-02-28 12:00:00 137,216 ----a-w C:\WINDOWS\system32\dssenh.dll + 2008-04-13 17:37:57 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll - 2006-02-28 12:00:00 113,664 ----a-w C:\WINDOWS\system32\dsuiext.dll + 2008-04-14 02:22:09 113,664 ----a-w C:\WINDOWS\system32\dsuiext.dll - 2006-02-28 12:00:00 19,456 ----a-w C:\WINDOWS\system32\dswave.dll + 2008-04-14 02:22:09 19,456 ----a-w C:\WINDOWS\system32\dswave.dll - 2006-02-28 12:00:00 10,752 ----a-w C:\WINDOWS\system32\dumprep.exe + 2008-04-14 02:22:43 10,752 ----a-w C:\WINDOWS\system32\dumprep.exe - 2006-02-28 12:00:00 304,128 ----a-w C:\WINDOWS\system32\duser.dll + 2008-04-14 02:22:09 304,128 ----a-w C:\WINDOWS\system32\duser.dll - 2006-02-28 12:00:00 17,920 ----a-w C:\WINDOWS\system32\dvdupgrd.exe + 2008-04-14 02:22:43 17,920 ----a-w C:\WINDOWS\system32\dvdupgrd.exe - 2006-02-28 12:00:00 180,224 ----a-w C:\WINDOWS\system32\dwwin.exe + 2008-04-14 02:22:43 180,224 ----a-w C:\WINDOWS\system32\dwwin.exe - 2006-02-28 12:00:00 619,008 ----a-w C:\WINDOWS\system32\dx7vb.dll + 2008-04-14 02:22:09 619,008 ----a-w C:\WINDOWS\system32\dx7vb.dll - 2006-02-28 12:00:00 1,227,264 ----a-w C:\WINDOWS\system32\dx8vb.dll + 2008-04-14 02:22:09 1,227,264 ----a-w C:\WINDOWS\system32\dx8vb.dll - 2006-02-28 12:00:00 1,298,432 ----a-w C:\WINDOWS\system32\dxdiag.exe + 2008-04-14 02:22:43 1,298,432 ----a-w C:\WINDOWS\system32\dxdiag.exe - 2006-02-28 12:00:00 2,113,536 ----a-w C:\WINDOWS\system32\dxdiagn.dll + 2008-04-14 02:22:09 2,113,536 ----a-w C:\WINDOWS\system32\dxdiagn.dll - 2006-08-24 11:17:12 500,278 ----a-w C:\WINDOWS\system32\dxmasf.dll + 2008-04-14 02:22:09 500,278 ----a-w C:\WINDOWS\system32\dxmasf.dll + 2008-04-14 02:22:09 30,720 ------w C:\WINDOWS\system32\eapolqec.dll + 2008-04-14 02:22:09 184,832 ------w C:\WINDOWS\system32\eapp3hst.dll + 2008-04-14 02:22:09 126,976 ------w C:\WINDOWS\system32\eappcfg.dll + 2008-04-14 02:22:09 95,232 ------w C:\WINDOWS\system32\eappgnui.dll + 2008-04-14 02:22:09 182,272 ------w C:\WINDOWS\system32\eapphost.dll + 2008-04-14 02:22:09 40,960 ------w C:\WINDOWS\system32\eappprxy.dll + 2008-04-14 02:22:09 59,392 ------w C:\WINDOWS\system32\eapqec.dll + 2008-04-14 02:22:09 33,792 ------w C:\WINDOWS\system32\eapsvc.dll - 2006-02-28 12:00:00 27,136 ----a-w C:\WINDOWS\system32\efsadu.dll + 2008-04-14 02:22:09 27,136 ----a-w C:\WINDOWS\system32\efsadu.dll - 2006-02-28 12:00:00 186,880 ----a-w C:\WINDOWS\system32\els.dll + 2008-04-14 02:22:10 186,880 ----a-w C:\WINDOWS\system32\els.dll - 2006-02-28 12:00:00 20,480 ----a-w C:\WINDOWS\system32\encapi.dll + 2008-04-14 02:22:10 20,480 ----a-w C:\WINDOWS\system32\encapi.dll - 2006-02-28 12:00:00 186,368 ----a-w C:\WINDOWS\system32\encdec.dll + 2008-04-14 02:22:10 186,880 ----a-w C:\WINDOWS\system32\encdec.dll - 2006-02-28 12:00:00 23,040 ----a-w C:\WINDOWS\system32\ersvc.dll + 2008-04-14 02:22:10 23,040 ----a-w C:\WINDOWS\system32\ersvc.dll - 2008-07-07 20:30:55 253,952 ----a-w C:\WINDOWS\system32\es.dll + 2008-07-07 20:26:58 253,952 ----a-w C:\WINDOWS\system32\es.dll - 2005-10-20 22:25:05 1,094,144 ----a-w C:\WINDOWS\system32\esent.dll + 2008-04-14 02:22:10 1,094,144 ----a-w C:\WINDOWS\system32\esent.dll - 2006-02-28 12:00:00 195,584 ----a-w C:\WINDOWS\system32\eudcedit.exe + 2008-04-14 02:22:44 195,584 ----a-w C:\WINDOWS\system32\eudcedit.exe - 2006-02-28 12:00:00 52,224 ----a-w C:\WINDOWS\system32\eventcreate.exe + 2008-04-14 02:22:44 52,736 ----a-w C:\WINDOWS\system32\eventcreate.exe - 2006-02-28 12:00:00 55,808 ----a-w C:\WINDOWS\system32\eventlog.dll + 2008-04-14 02:22:10 56,320 ----a-w C:\WINDOWS\system32\eventlog.dll - 2006-02-28 12:00:00 80,384 ----a-w C:\WINDOWS\system32\eventtriggers.exe + 2008-04-14 02:22:44 85,504 ----a-w C:\WINDOWS\system32\eventtriggers.exe - 2006-02-28 12:00:00 380,957 ----a-w C:\WINDOWS\system32\expsrv.dll + 2008-04-14 02:22:10 380,445 ----a-w C:\WINDOWS\system32\expsrv.dll - 2006-02-28 12:00:00 45,568 ----a-w C:\WINDOWS\system32\extrac32.exe + 2008-04-14 02:22:45 24,064 ----a-w C:\WINDOWS\system32\extrac32.exe - 2006-02-28 12:00:00 121,856 ----a-w C:\WINDOWS\system32\exts.dll + 2008-04-14 02:22:10 125,952 ----a-w C:\WINDOWS\system32\exts.dll - 2006-02-28 12:00:00 80,896 ----a-w C:\WINDOWS\system32\faultrep.dll + 2008-04-14 02:22:10 80,896 ----a-w C:\WINDOWS\system32\faultrep.dll + 2008-04-14 02:22:45 20,992 ------w C:\WINDOWS\system32\faxpatch.exe - 2006-02-28 12:00:00 118,784 ----a-w C:\WINDOWS\system32\fde.dll + 2008-04-14 02:22:10 125,952 ----a-w C:\WINDOWS\system32\fde.dll - 2006-02-28 12:00:00 76,800 ----a-w C:\WINDOWS\system32\fdeploy.dll + 2008-04-14 02:22:10 76,800 ----a-w C:\WINDOWS\system32\fdeploy.dll - 2006-02-28 12:00:00 21,504 ----a-w C:\WINDOWS\system32\feclient.dll + 2008-04-14 02:22:10 21,504 ----a-w C:\WINDOWS\system32\feclient.dll - 2006-02-28 12:00:00 345,600 ----a-w C:\WINDOWS\system32\filemgmt.dll + 2008-04-14 02:22:10 345,600 ----a-w C:\WINDOWS\system32\filemgmt.dll - 2006-02-28 12:00:00 28,160 ----a-w C:\WINDOWS\system32\findstr.exe + 2008-04-14 02:22:45 28,160 ----a-w C:\WINDOWS\system32\findstr.exe - 2006-02-28 12:00:00 88,576 ----a-w C:\WINDOWS\system32\fldrclnr.dll + 2008-04-14 02:22:10 88,576 ----a-w C:\WINDOWS\system32\fldrclnr.dll - 2006-08-21 12:26:05 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll + 2008-04-14 02:22:10 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll - 2006-08-21 09:14:58 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe + 2008-04-14 02:22:46 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe - 2008-05-31 12:34:49 188,200 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2008-10-13 12:05:44 189,792 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT - 2006-02-28 12:00:00 386,560 ----a-w C:\WINDOWS\system32\fontext.dll + 2008-04-14 02:22:10 386,560 ----a-w C:\WINDOWS\system32\fontext.dll - 2005-10-17 21:20:02 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll + 2008-04-14 02:22:10 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll - 2006-02-28 12:00:00 21,504 ----a-w C:\WINDOWS\system32\fontview.exe + 2008-04-14 02:22:46 21,504 ----a-w C:\WINDOWS\system32\fontview.exe - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\forcedos.exe + 2008-04-14 02:22:46 7,680 ----a-w C:\WINDOWS\system32\forcedos.exe - 2006-02-28 12:00:00 25,600 ----a-w C:\WINDOWS\system32\format.com + 2008-04-14 02:23:07 29,696 ----a-w C:\WINDOWS\system32\format.com - 2006-02-28 12:00:00 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll + 2008-04-14 02:20:34 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll - 2006-02-28 12:00:00 193,024 ----a-w C:\WINDOWS\system32\fsquirt.exe + 2008-04-14 02:22:46 193,024 ----a-w C:\WINDOWS\system32\fsquirt.exe - 2006-02-28 12:00:00 45,056 ----a-w C:\WINDOWS\system32\ftp.exe + 2008-04-14 02:22:46 45,056 ----a-w C:\WINDOWS\system32\ftp.exe - 2006-02-28 12:00:00 60,416 ----a-w C:\WINDOWS\system32\fwcfg.dll + 2008-04-14 02:22:10 60,416 ----a-w C:\WINDOWS\system32\fwcfg.dll - 2008-02-20 06:50:29 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll + 2008-04-14 02:22:10 285,184 ----a-w C:\WINDOWS\system32\gdi32.dll - 2006-02-28 12:00:00 56,832 ----a-w C:\WINDOWS\system32\getmac.exe + 2008-04-14 02:22:47 61,440 ----a-w C:\WINDOWS\system32\getmac.exe - 2006-02-28 12:00:00 122,880 ----a-w C:\WINDOWS\system32\glu32.dll + 2008-04-14 02:22:10 122,880 ----a-w C:\WINDOWS\system32\glu32.dll - 2006-02-28 12:00:00 577,024 ----a-w C:\WINDOWS\system32\gpedit.dll + 2008-04-14 02:22:10 577,024 ----a-w C:\WINDOWS\system32\gpedit.dll - 2006-02-28 12:00:00 10,752 ----a-w C:\WINDOWS\system32\gpkrsrc.dll + 2008-04-14 01:54:15 10,752 ----a-w C:\WINDOWS\system32\gpkrsrc.dll - 2006-02-28 12:00:00 122,368 ----a-w C:\WINDOWS\system32\gpresult.exe + 2008-04-14 02:22:47 123,392 ----a-w C:\WINDOWS\system32\gpresult.exe - 2006-02-28 12:00:00 201,216 ----a-w C:\WINDOWS\system32\gptext.dll + 2008-04-14 02:22:11 202,240 ----a-w C:\WINDOWS\system32\gptext.dll - 2006-02-28 12:00:00 39,424 ----a-w C:\WINDOWS\system32\grpconv.exe + 2008-04-14 02:22:47 39,424 ----a-w C:\WINDOWS\system32\grpconv.exe - 2006-02-28 12:00:00 614,912 ----a-w C:\WINDOWS\system32\h323msp.dll + 2008-04-14 02:22:11 614,912 ----a-w C:\WINDOWS\system32\h323msp.dll - 2006-02-28 12:00:00 134,400 ----a-w C:\WINDOWS\system32\hal.dll + 2008-04-13 18:31:28 134,400 ----a-w C:\WINDOWS\system32\HAL.DLL - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\hccoin.dll + 2008-04-14 02:22:11 7,168 ----a-w C:\WINDOWS\system32\hccoin.dll - 2006-02-28 12:00:00 16,384 ----a-w C:\WINDOWS\system32\help.exe + 2008-04-14 02:22:47 17,408 ----a-w C:\WINDOWS\system32\help.exe - 2005-05-27 02:04:47 41,472 ----a-w C:\WINDOWS\system32\hhsetup.dll + 2008-04-14 02:22:11 41,472 ----a-w C:\WINDOWS\system32\hhsetup.dll - 2006-02-28 12:00:00 20,992 ----a-w C:\WINDOWS\system32\hid.dll + 2008-04-14 02:22:11 20,992 ----a-w C:\WINDOWS\system32\hid.dll - 2006-07-21 08:29:00 72,704 ----a-w C:\WINDOWS\system32\hlink.dll + 2008-04-14 02:22:11 72,704 ----a-w C:\WINDOWS\system32\hlink.dll - 2006-02-28 12:00:00 348,672 ----a-w C:\WINDOWS\system32\hnetcfg.dll + 2008-04-14 02:22:11 348,672 ----a-w C:\WINDOWS\system32\hnetcfg.dll - 2006-02-28 12:00:00 338,432 ----a-w C:\WINDOWS\system32\hnetwiz.dll + 2008-04-14 02:22:11 338,432 ----a-w C:\WINDOWS\system32\hnetwiz.dll - 2006-02-28 12:00:00 146,432 ----a-w C:\WINDOWS\system32\hotplug.dll + 2008-04-14 02:22:11 146,432 ----a-w C:\WINDOWS\system32\hotplug.dll + 2008-04-14 02:22:11 32,285 ------w C:\WINDOWS\system32\hsfcisp2.dll |
![]() | #4 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2006-02-28 12:00:00 24,576 ----a-w C:\WINDOWS\system32\httpapi.dll + 2008-04-14 02:22:11 24,576 ----a-w C:\WINDOWS\system32\httpapi.dll - 2006-02-28 12:00:00 43,008 ----a-w C:\WINDOWS\system32\htui.dll + 2008-04-14 02:22:11 43,008 ----a-w C:\WINDOWS\system32\htui.dll - 2004-11-17 17:42:24 356,352 ----a-w C:\WINDOWS\system32\hypertrm.dll + 2008-04-14 02:22:12 356,352 ----a-w C:\WINDOWS\system32\hypertrm.dll - 2006-02-28 12:00:00 119,808 ----a-w C:\WINDOWS\system32\iasrad.dll + 2008-04-14 02:22:12 119,808 ----a-w C:\WINDOWS\system32\iasrad.dll - 2006-02-28 12:00:00 11,264 ----a-w C:\WINDOWS\system32\icaapi.dll + 2008-04-14 02:22:12 11,264 ----a-w C:\WINDOWS\system32\icaapi.dll - 2006-02-28 12:00:00 80,384 ----a-w C:\WINDOWS\system32\iccvid.dll + 2008-04-14 02:22:12 80,384 ----a-w C:\WINDOWS\system32\iccvid.dll - 2005-06-29 01:49:39 254,976 ----a-w C:\WINDOWS\system32\icm32.dll + 2008-04-14 02:22:12 254,976 ----a-w C:\WINDOWS\system32\icm32.dll - 2006-02-28 12:00:00 3,584 ----a-w C:\WINDOWS\system32\icmp.dll + 2008-04-14 02:20:41 3,584 ----a-w C:\WINDOWS\system32\icmp.dll - 2006-02-28 12:00:00 73,728 ----a-w C:\WINDOWS\system32\icwdial.dll + 2008-04-14 02:22:12 73,728 ----a-w C:\WINDOWS\system32\icwdial.dll - 2006-02-28 12:00:00 65,536 ----a-w C:\WINDOWS\system32\icwphbk.dll + 2008-04-14 02:22:12 65,536 ----a-w C:\WINDOWS\system32\icwphbk.dll - 2006-02-28 12:00:00 121,344 ----a-w C:\WINDOWS\system32\idq.dll + 2008-04-14 02:22:12 121,344 ----a-w C:\WINDOWS\system32\idq.dll - 2007-08-13 16:45:18 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll + 2008-04-14 02:22:12 81,920 ----a-w C:\WINDOWS\system32\ieencode.dll - 2006-02-28 12:00:00 114,688 ----a-w C:\WINDOWS\system32\iexpress.exe + 2008-04-14 02:22:48 114,688 ----a-w C:\WINDOWS\system32\iexpress.exe - 2006-02-28 12:00:00 135,680 ----a-w C:\WINDOWS\system32\ifmon.dll + 2008-04-14 02:22:12 135,680 ----a-w C:\WINDOWS\system32\ifmon.dll - 2006-02-28 12:00:00 8,192 ----a-w C:\WINDOWS\system32\igmpagnt.dll + 2008-04-14 02:22:12 8,192 ----a-w C:\WINDOWS\system32\igmpagnt.dll - 2006-02-28 12:00:00 81,920 ----a-w C:\WINDOWS\system32\ils.dll + 2008-04-14 02:22:12 81,920 ----a-w C:\WINDOWS\system32\ils.dll - 2006-02-28 12:00:00 144,384 ----a-w C:\WINDOWS\system32\imagehlp.dll + 2008-04-14 02:22:12 144,384 ----a-w C:\WINDOWS\system32\imagehlp.dll - 2006-02-28 12:00:00 150,016 ----a-w C:\WINDOWS\system32\imapi.exe + 2008-04-14 02:22:48 150,528 ----a-w C:\WINDOWS\system32\imapi.exe - 2006-02-28 12:00:00 36,921 ----a-w C:\WINDOWS\system32\imeshare.dll + 2008-04-14 02:22:12 36,921 ----a-w C:\WINDOWS\system32\imeshare.dll - 2006-02-28 12:00:00 110,080 ----a-w C:\WINDOWS\system32\imm32.dll + 2008-04-14 02:22:12 110,080 ----a-w C:\WINDOWS\system32\imm32.dll - 2006-02-28 12:00:00 282,624 ----a-w C:\WINDOWS\system32\inetcfg.dll + 2008-04-14 02:22:12 282,624 ----a-w C:\WINDOWS\system32\inetcfg.dll - 2008-04-11 18:50:09 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll + 2008-04-11 19:04:24 691,712 ----a-w C:\WINDOWS\system32\inetcomm.dll - 2006-02-28 12:00:00 33,280 ----a-w C:\WINDOWS\system32\inetmib1.dll + 2008-04-14 02:22:12 32,768 ----a-w C:\WINDOWS\system32\inetmib1.dll - 2006-02-28 12:00:00 75,264 ----a-w C:\WINDOWS\system32\inetpp.dll + 2008-04-14 02:22:12 75,264 ----a-w C:\WINDOWS\system32\inetpp.dll - 2006-02-28 12:00:00 16,384 ----a-w C:\WINDOWS\system32\inetppui.dll + 2008-04-14 02:22:12 16,384 ----a-w C:\WINDOWS\system32\inetppui.dll - 2006-02-28 12:00:00 51,712 ----a-w C:\WINDOWS\system32\inetres.dll + 2008-04-14 01:56:57 51,712 ----a-w C:\WINDOWS\system32\inetres.dll + 2008-04-14 02:22:24 221,696 ------w C:\WINDOWS\system32\inetsrv\seo.dll + 2008-04-14 02:22:25 189,952 ------w C:\WINDOWS\system32\inetsrv\smtpadm.dll + 2008-04-14 02:22:25 2,134,528 ------w C:\WINDOWS\system32\inetsrv\smtpsnap.dll - 2006-02-28 12:00:00 147,456 ----a-w C:\WINDOWS\system32\initpki.dll + 2008-04-14 02:22:12 147,456 ----a-w C:\WINDOWS\system32\initpki.dll - 2006-02-28 12:00:00 127,488 ----a-w C:\WINDOWS\system32\input.dll + 2008-04-14 02:22:12 127,488 ----a-w C:\WINDOWS\system32\input.dll - 2006-02-28 12:00:00 58,368 ----a-w C:\WINDOWS\system32\ipconfig.exe + 2008-04-14 02:22:49 58,368 ----a-w C:\WINDOWS\system32\ipconfig.exe - 2006-05-19 13:09:50 95,744 ----a-w C:\WINDOWS\system32\iphlpapi.dll + 2008-04-14 02:22:12 95,744 ----a-w C:\WINDOWS\system32\iphlpapi.dll - 2006-02-28 12:00:00 154,112 ----a-w C:\WINDOWS\system32\ipmontr.dll + 2008-04-14 02:22:12 161,280 ----a-w C:\WINDOWS\system32\ipmontr.dll - 2006-02-28 12:00:00 334,336 ----a-w C:\WINDOWS\system32\ipnathlp.dll + 2008-04-14 02:22:12 334,336 ----a-w C:\WINDOWS\system32\ipnathlp.dll - 2006-02-28 12:00:00 345,600 ----a-w C:\WINDOWS\system32\ippromon.dll + 2008-04-14 02:22:12 345,600 ----a-w C:\WINDOWS\system32\ippromon.dll - 2006-02-28 12:00:00 169,984 ----a-w C:\WINDOWS\system32\iprtrmgr.dll + 2008-04-14 02:22:12 177,152 ----a-w C:\WINDOWS\system32\iprtrmgr.dll - 2006-02-28 12:00:00 361,472 ----a-w C:\WINDOWS\system32\ipsecsnp.dll + 2008-04-14 02:22:12 361,472 ----a-w C:\WINDOWS\system32\ipsecsnp.dll - 2006-02-28 12:00:00 184,320 ----a-w C:\WINDOWS\system32\ipsecsvc.dll + 2008-04-14 02:22:12 185,344 ----a-w C:\WINDOWS\system32\ipsecsvc.dll - 2006-02-28 12:00:00 387,584 ----a-w C:\WINDOWS\system32\ipsmsnap.dll + 2008-04-14 02:22:12 387,584 ----a-w C:\WINDOWS\system32\ipsmsnap.dll - 2006-02-28 12:00:00 53,248 ----a-w C:\WINDOWS\system32\ipv6.exe + 2008-04-14 02:22:50 53,248 ----a-w C:\WINDOWS\system32\ipv6.exe - 2006-02-28 12:00:00 59,904 ----a-w C:\WINDOWS\system32\ipv6mon.dll + 2008-04-14 02:22:12 59,904 ----a-w C:\WINDOWS\system32\ipv6mon.dll - 2006-02-28 12:00:00 24,064 ----a-w C:\WINDOWS\system32\ipxroute.exe + 2008-04-14 02:22:50 24,064 ----a-w C:\WINDOWS\system32\ipxroute.exe - 2006-02-28 12:00:00 20,992 ----a-w C:\WINDOWS\system32\ipxwan.dll + 2008-04-14 02:22:12 22,016 ----a-w C:\WINDOWS\system32\ipxwan.dll - 2006-02-28 12:00:00 120,320 ----a-w C:\WINDOWS\system32\ir41_qc.dll + 2008-04-14 02:22:12 120,320 ----a-w C:\WINDOWS\system32\ir41_qc.dll - 2006-02-28 12:00:00 338,432 ----a-w C:\WINDOWS\system32\ir41_qcx.dll + 2008-04-14 02:22:12 338,432 ----a-w C:\WINDOWS\system32\ir41_qcx.dll - 2006-02-28 12:00:00 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll + 2008-04-14 02:22:12 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll - 2006-02-28 12:00:00 200,192 ----a-w C:\WINDOWS\system32\ir50_qc.dll + 2008-04-14 02:22:12 200,192 ----a-w C:\WINDOWS\system32\ir50_qc.dll - 2006-02-28 12:00:00 183,808 ----a-w C:\WINDOWS\system32\ir50_qcx.dll + 2008-04-14 02:22:12 183,808 ----a-w C:\WINDOWS\system32\ir50_qcx.dll - 2006-02-28 12:00:00 86,016 ----a-w C:\WINDOWS\system32\isign32.dll + 2008-04-14 02:22:12 86,016 ----a-w C:\WINDOWS\system32\isign32.dll - 2006-02-28 12:00:00 32,768 ----a-w C:\WINDOWS\system32\isrdbg32.dll + 2008-04-14 02:22:12 32,768 ----a-w C:\WINDOWS\system32\isrdbg32.dll - 2005-05-27 02:04:47 155,136 ----a-w C:\WINDOWS\system32\itircl.dll + 2008-04-14 02:22:12 155,136 ----a-w C:\WINDOWS\system32\itircl.dll - 2005-05-27 02:04:47 137,216 ----a-w C:\WINDOWS\system32\itss.dll + 2008-04-14 02:22:12 138,240 ----a-w C:\WINDOWS\system32\itss.dll - 2006-02-28 12:00:00 192,000 ----a-w C:\WINDOWS\system32\iuengine.dll + 2008-04-14 02:22:12 191,488 ----a-w C:\WINDOWS\system32\iuengine.dll - 2006-02-28 12:00:00 54,784 ----a-w C:\WINDOWS\system32\ixsso.dll + 2008-04-14 02:22:12 54,784 ----a-w C:\WINDOWS\system32\ixsso.dll - 2006-02-28 12:00:00 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll + 2008-04-14 02:22:12 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll - 2006-06-01 18:47:07 163,840 ----a-w C:\WINDOWS\system32\jgdw400.dll + 2008-04-14 02:22:12 163,840 ----a-w C:\WINDOWS\system32\jgdw400.dll - 2006-06-01 18:47:07 27,648 ----a-w C:\WINDOWS\system32\jgpl400.dll + 2008-04-14 02:22:13 27,648 ----a-w C:\WINDOWS\system32\jgpl400.dll - 2007-08-13 16:38:04 491,520 ----a-w C:\WINDOWS\system32\jscript.dll + 2008-04-14 02:22:13 512,000 ----a-w C:\WINDOWS\system32\jscript.dll + 2008-04-14 02:20:50 6,144 ------w C:\WINDOWS\system32\kbdbhc.dll - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\kbdfi1.dll + 2008-04-14 02:20:50 7,168 ----a-w C:\WINDOWS\system32\kbdfi1.dll - 2006-02-28 12:00:00 6,144 ----a-w C:\WINDOWS\system32\kbdinbe1.dll + 2008-04-14 02:20:50 6,144 ----a-w C:\WINDOWS\system32\kbdinbe1.dll - 2006-02-28 12:00:00 6,656 ----a-w C:\WINDOWS\system32\kbdinben.dll + 2008-04-14 02:20:50 6,144 ----a-w C:\WINDOWS\system32\kbdinben.dll - 2006-02-28 12:00:00 6,656 ----a-w C:\WINDOWS\system32\kbdinmal.dll + 2008-04-14 02:20:50 6,656 ----a-w C:\WINDOWS\system32\kbdinmal.dll + 2008-04-14 02:20:50 6,144 ------w C:\WINDOWS\system32\kbdiultn.dll - 2006-02-28 12:00:00 5,632 ----a-w C:\WINDOWS\system32\kbdmaori.dll + 2008-04-14 02:20:50 5,632 ----a-w C:\WINDOWS\system32\kbdmaori.dll - 2006-02-28 12:00:00 6,144 ----a-w C:\WINDOWS\system32\kbdmlt47.dll + 2008-04-14 02:20:50 6,144 ----a-w C:\WINDOWS\system32\kbdmlt47.dll - 2006-02-28 12:00:00 6,144 ----a-w C:\WINDOWS\system32\kbdmlt48.dll + 2008-04-14 02:20:50 6,144 ----a-w C:\WINDOWS\system32\kbdmlt48.dll - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\kbdnec.dll + 2008-04-14 02:20:50 7,168 ----a-w C:\WINDOWS\system32\kbdnec.dll + 2008-04-14 02:20:50 6,144 ------w C:\WINDOWS\system32\kbdnepr.dll - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\kbdno1.dll + 2008-04-14 02:20:50 7,168 ----a-w C:\WINDOWS\system32\kbdno1.dll + 2008-04-14 02:20:50 6,144 ------w C:\WINDOWS\system32\kbdpash.dll - 2006-02-28 12:00:00 7,680 ----a-w C:\WINDOWS\system32\kbdsmsfi.dll + 2008-04-14 02:20:50 7,680 ----a-w C:\WINDOWS\system32\kbdsmsfi.dll - 2006-02-28 12:00:00 7,680 ----a-w C:\WINDOWS\system32\kbdsmsno.dll + 2008-04-14 02:20:50 7,680 ----a-w C:\WINDOWS\system32\kbdsmsno.dll - 2006-02-28 12:00:00 7,168 ----a-w C:\WINDOWS\system32\kbdukx.dll + 2008-04-14 02:20:50 7,168 ----a-w C:\WINDOWS\system32\kbdukx.dll - 2006-02-28 12:00:00 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll + 2008-04-13 18:31:35 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll - 2005-06-15 17:49:56 295,936 ----a-w C:\WINDOWS\system32\kerberos.dll + 2008-04-14 02:22:13 299,520 ----a-w C:\WINDOWS\system32\kerberos.dll - 2007-04-16 15:53:05 1,058,304 ----a-w C:\WINDOWS\system32\kernel32.dll + 2008-04-14 02:22:13 1,063,424 ----a-w C:\WINDOWS\system32\kernel32.dll - 2006-02-28 12:00:00 156,160 ----a-w C:\WINDOWS\system32\keymgr.dll + 2008-04-14 02:22:13 156,160 ----a-w C:\WINDOWS\system32\keymgr.dll + 2008-04-14 02:22:13 61,440 ------w C:\WINDOWS\system32\kmsvc.dll - 2004-08-03 22:57:24 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll + 2008-04-14 02:22:13 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll + 2008-04-14 02:22:13 37,376 ------w C:\WINDOWS\system32\l2gpstore.dll - 2006-02-28 12:00:00 425,472 ----a-w C:\WINDOWS\system32\licdll.dll + 2008-04-14 05:52:14 425,472 ----a-w C:\WINDOWS\system32\licdll.dll - 2006-02-28 12:00:00 58,880 ----a-w C:\WINDOWS\system32\licwmi.dll + 2008-04-14 02:22:13 58,880 ----a-w C:\WINDOWS\system32\licwmi.dll - 2005-09-01 01:44:41 19,968 ----a-w C:\WINDOWS\system32\linkinfo.dll + 2008-04-14 02:22:13 19,968 ----a-w C:\WINDOWS\system32\linkinfo.dll - 2006-02-28 12:00:00 13,824 ----a-w C:\WINDOWS\system32\lmhsvc.dll + 2008-04-14 02:22:13 13,824 ----a-w C:\WINDOWS\system32\lmhsvc.dll - 2006-02-28 12:00:00 399,872 ----a-w C:\WINDOWS\system32\lmrt.dll + 2008-04-14 02:22:13 399,872 ----a-w C:\WINDOWS\system32\lmrt.dll - 2006-02-28 12:00:00 99,840 ----a-w C:\WINDOWS\system32\loadperf.dll + 2008-04-14 02:22:13 99,840 ----a-w C:\WINDOWS\system32\loadperf.dll - 2006-02-28 12:00:00 226,304 ----a-w C:\WINDOWS\system32\localsec.dll + 2008-04-14 02:22:13 226,304 ----a-w C:\WINDOWS\system32\localsec.dll - 2006-02-28 12:00:00 344,064 ----a-w C:\WINDOWS\system32\localspl.dll + 2008-04-14 02:22:13 345,600 ----a-w C:\WINDOWS\system32\localspl.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\localui.dll + 2008-04-14 02:22:13 12,288 ----a-w C:\WINDOWS\system32\localui.dll - 2006-02-28 12:00:00 75,264 ----a-w C:\WINDOWS\system32\locator.exe + 2008-04-14 02:22:50 75,264 ----a-w C:\WINDOWS\system32\locator.exe - 2006-02-28 12:00:00 61,440 ----a-w C:\WINDOWS\system32\logman.exe + 2008-04-14 02:22:50 61,440 ----a-w C:\WINDOWS\system32\logman.exe - 2006-02-28 12:00:00 220,672 ----a-w C:\WINDOWS\system32\logon.scr + 2008-04-14 02:23:07 220,672 ----a-w C:\WINDOWS\system32\logon.scr - 2006-02-28 12:00:00 515,072 ----a-w C:\WINDOWS\system32\logonui.exe + 2008-04-14 02:22:51 515,072 ----a-w C:\WINDOWS\system32\logonui.exe - 2006-02-28 12:00:00 22,016 ----a-w C:\WINDOWS\system32\lpk.dll + 2008-04-14 02:22:14 22,016 ----a-w C:\WINDOWS\system32\lpk.dll - 2006-02-28 12:00:00 10,240 ----a-w C:\WINDOWS\system32\lprhelp.dll + 2008-04-14 02:22:14 10,240 ----a-w C:\WINDOWS\system32\lprhelp.dll - 2007-11-07 09:27:10 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll + 2008-04-14 02:22:14 735,744 ----a-w C:\WINDOWS\system32\lsasrv.dll - 2006-02-28 12:00:00 13,312 ----a-w C:\WINDOWS\system32\lsass.exe + 2008-04-14 02:22:51 13,312 ----a-w C:\WINDOWS\system32\lsass.exe - 2006-02-28 12:00:00 73,216 ----a-w C:\WINDOWS\system32\magnify.exe + 2008-04-14 02:22:51 73,216 ----a-w C:\WINDOWS\system32\magnify.exe - 2006-02-28 12:00:00 85,504 ----a-w C:\WINDOWS\system32\makecab.exe + 2008-04-14 02:22:51 57,344 ----a-w C:\WINDOWS\system32\makecab.exe - 2006-02-28 12:00:00 14,848 ----a-w C:\WINDOWS\system32\mcastmib.dll + 2008-04-14 02:22:14 14,336 ----a-w C:\WINDOWS\system32\mcastmib.dll - 2006-02-28 12:00:00 85,504 ----a-w C:\WINDOWS\system32\mciavi32.dll + 2008-04-14 02:22:14 85,504 ----a-w C:\WINDOWS\system32\mciavi32.dll - 2006-02-28 12:00:00 35,328 ----a-w C:\WINDOWS\system32\mciqtz32.dll + 2008-04-14 02:22:14 35,328 ----a-w C:\WINDOWS\system32\mciqtz32.dll - 2006-02-28 12:00:00 23,040 ----a-w C:\WINDOWS\system32\mciseq.dll + 2008-04-14 02:22:14 23,040 ----a-w C:\WINDOWS\system32\mciseq.dll - 2006-02-28 12:00:00 23,552 ----a-w C:\WINDOWS\system32\mciwave.dll + 2008-04-14 02:22:14 23,552 ----a-w C:\WINDOWS\system32\mciwave.dll - 2006-02-28 12:00:00 121,344 ----a-w C:\WINDOWS\system32\mdminst.dll + 2008-04-14 02:22:14 121,344 ----a-w C:\WINDOWS\system32\mdminst.dll + 2008-04-14 02:22:14 86,016 ------w C:\WINDOWS\system32\mdmxsdk.dll - 2007-03-08 15:36:30 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll + 2008-04-14 02:22:14 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll - 2006-11-01 19:17:41 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll + 2008-04-14 02:22:14 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll - 2006-02-28 12:00:00 1,028,096 ----a-w C:\WINDOWS\system32\mfc42.dll + 2008-04-14 02:22:14 1,028,096 ----a-w C:\WINDOWS\system32\mfc42.dll - 2006-02-28 12:00:00 22,528 ----a-w C:\WINDOWS\system32\mfcsubs.dll + 2008-04-14 02:22:14 22,528 ----a-w C:\WINDOWS\system32\mfcsubs.dll - 2006-02-28 12:00:00 14,848 ----a-w C:\WINDOWS\system32\mgmtapi.dll + 2008-04-14 02:22:14 14,848 ----a-w C:\WINDOWS\system32\mgmtapi.dll + 2008-04-14 02:22:14 184,320 ------w C:\WINDOWS\system32\microsoft.managementconsole.dll |
![]() | #5 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\midimap.dll + 2008-04-14 02:22:14 18,944 ----a-w C:\WINDOWS\system32\midimap.dll - 2006-02-28 12:00:00 60,928 ----a-w C:\WINDOWS\system32\miglibnt.dll + 2008-04-14 02:22:14 60,928 ----a-w C:\WINDOWS\system32\miglibnt.dll - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\mimefilt.dll + 2008-04-14 02:22:14 29,696 ----a-w C:\WINDOWS\system32\mimefilt.dll - 2006-02-28 12:00:00 586,240 ----a-w C:\WINDOWS\system32\mlang.dll + 2008-04-14 02:22:14 586,240 ----a-w C:\WINDOWS\system32\mlang.dll - 2006-02-28 12:00:00 815,616 ----a-w C:\WINDOWS\system32\mmc.exe + 2008-04-14 02:22:52 1,415,168 ----a-w C:\WINDOWS\system32\mmc.exe - 2006-02-28 12:00:00 77,824 ----a-w C:\WINDOWS\system32\mmcbase.dll + 2008-04-14 02:22:14 169,984 ----a-w C:\WINDOWS\system32\mmcbase.dll + 2008-04-14 02:22:14 397,312 ------w C:\WINDOWS\system32\mmcex.dll + 2008-04-14 02:22:15 106,496 ------w C:\WINDOWS\system32\mmcfxcommon.dll - 2006-02-28 12:00:00 1,197,568 ----a-w C:\WINDOWS\system32\mmcndmgr.dll + 2008-04-14 02:22:15 1,877,504 ----a-w C:\WINDOWS\system32\mmcndmgr.dll + 2008-04-14 02:22:52 33,792 ------w C:\WINDOWS\system32\mmcperf.exe - 2006-02-28 12:00:00 50,688 ----a-w C:\WINDOWS\system32\mmcshext.dll + 2008-04-14 02:22:15 61,440 ----a-w C:\WINDOWS\system32\mmcshext.dll - 2006-02-28 12:00:00 17,920 ----a-w C:\WINDOWS\system32\mmfutil.dll + 2008-04-14 02:22:15 17,920 ----a-w C:\WINDOWS\system32\mmfutil.dll - 2006-02-28 12:00:00 34,560 ----a-w C:\WINDOWS\system32\mnmdd.dll + 2008-04-14 02:22:15 34,560 ----a-w C:\WINDOWS\system32\mnmdd.dll - 2006-02-28 12:00:00 32,768 ----a-w C:\WINDOWS\system32\mnmsrvc.exe + 2008-04-14 02:22:52 32,768 ----a-w C:\WINDOWS\system32\mnmsrvc.exe - 2006-02-28 12:00:00 209,408 ----a-w C:\WINDOWS\system32\mobsync.dll + 2008-04-14 02:22:15 209,408 ----a-w C:\WINDOWS\system32\mobsync.dll - 2006-02-28 12:00:00 144,384 ----a-w C:\WINDOWS\system32\mobsync.exe + 2008-04-14 02:22:52 144,384 ----a-w C:\WINDOWS\system32\mobsync.exe - 2006-02-28 12:00:00 156,672 ----a-w C:\WINDOWS\system32\modemui.dll + 2008-04-14 02:22:15 156,672 ----a-w C:\WINDOWS\system32\modemui.dll - 2006-02-28 12:00:00 15,872 ----a-w C:\WINDOWS\system32\more.com + 2008-04-14 02:23:07 16,896 ----a-w C:\WINDOWS\system32\more.com - 2006-02-28 12:00:00 216,064 ----a-w C:\WINDOWS\system32\moricons.dll + 2008-04-13 16:45:30 216,064 ----a-w C:\WINDOWS\system32\moricons.dll - 2006-02-28 12:00:00 310,272 ----a-w C:\WINDOWS\system32\mp43dmod.dll + 2008-04-14 02:22:15 310,272 ----a-w C:\WINDOWS\system32\mp43dmod.dll - 2006-02-28 12:00:00 384,512 ----a-w C:\WINDOWS\system32\mp4sdmod.dll + 2008-04-14 02:22:15 384,512 ----a-w C:\WINDOWS\system32\mp4sdmod.dll - 2006-02-28 12:00:00 240,640 ----a-w C:\WINDOWS\system32\mpg4dmod.dll + 2008-04-14 02:22:15 240,640 ----a-w C:\WINDOWS\system32\mpg4dmod.dll - 2006-02-28 12:00:00 124,928 ----a-w C:\WINDOWS\system32\mplay32.exe + 2008-04-14 02:22:53 124,928 ----a-w C:\WINDOWS\system32\mplay32.exe - 2006-02-28 12:00:00 59,904 ----a-w C:\WINDOWS\system32\mpr.dll + 2008-04-14 02:22:15 59,904 ----a-w C:\WINDOWS\system32\mpr.dll - 2006-02-28 12:00:00 87,040 ----a-w C:\WINDOWS\system32\mprapi.dll + 2008-04-14 02:22:15 87,040 ----a-w C:\WINDOWS\system32\mprapi.dll - 2006-02-28 12:00:00 49,152 ----a-w C:\WINDOWS\system32\mprdim.dll + 2008-04-14 02:22:15 53,248 ----a-w C:\WINDOWS\system32\mprdim.dll - 2007-07-06 12:49:58 138,240 ----a-w C:\WINDOWS\system32\mqad.dll + 2008-04-14 02:22:15 138,240 ----a-w C:\WINDOWS\system32\mqad.dll - 2006-02-28 12:00:00 19,968 ----a-w C:\WINDOWS\system32\mqbkup.exe + 2008-04-14 02:22:53 19,968 ----a-w C:\WINDOWS\system32\mqbkup.exe - 2007-07-06 12:49:58 47,104 ----a-w C:\WINDOWS\system32\mqdscli.dll + 2008-04-14 02:22:15 47,616 ----a-w C:\WINDOWS\system32\mqdscli.dll - 2007-07-06 12:49:58 16,896 ----a-w C:\WINDOWS\system32\mqise.dll + 2008-04-14 02:22:15 16,896 ----a-w C:\WINDOWS\system32\mqise.dll - 2006-02-28 12:00:00 89,088 ----a-w C:\WINDOWS\system32\mqlogmgr.dll + 2008-04-14 02:22:15 89,088 ----a-w C:\WINDOWS\system32\mqlogmgr.dll - 2006-02-28 12:00:00 225,280 ----a-w C:\WINDOWS\system32\mqoa.dll + 2008-04-14 02:22:15 225,280 ----a-w C:\WINDOWS\system32\mqoa.dll - 2007-07-06 12:49:58 660,992 ----a-w C:\WINDOWS\system32\mqqm.dll + 2008-04-14 02:22:15 663,040 ----a-w C:\WINDOWS\system32\mqqm.dll - 2007-07-06 12:49:58 177,152 ----a-w C:\WINDOWS\system32\mqrt.dll + 2008-04-14 02:22:15 177,152 ----a-w C:\WINDOWS\system32\mqrt.dll - 2006-02-28 12:00:00 123,392 ----a-w C:\WINDOWS\system32\mqrtdep.dll + 2008-04-14 02:22:15 123,904 ----a-w C:\WINDOWS\system32\mqrtdep.dll - 2007-07-06 12:49:58 95,744 ----a-w C:\WINDOWS\system32\mqsec.dll + 2008-04-14 02:22:15 95,744 ----a-w C:\WINDOWS\system32\mqsec.dll - 2006-02-28 12:00:00 517,632 ----a-w C:\WINDOWS\system32\mqsnap.dll + 2008-04-14 02:22:15 517,632 ----a-w C:\WINDOWS\system32\mqsnap.dll - 2006-02-28 12:00:00 4,608 ----a-w C:\WINDOWS\system32\mqsvc.exe + 2008-04-14 02:22:53 4,608 ----a-w C:\WINDOWS\system32\mqsvc.exe - 2006-02-28 12:00:00 117,248 ----a-w C:\WINDOWS\system32\mqtgsvc.exe + 2008-04-14 02:22:53 117,248 ----a-w C:\WINDOWS\system32\mqtgsvc.exe - 2006-02-28 12:00:00 186,880 ----a-w C:\WINDOWS\system32\mqtrig.dll + 2008-04-14 02:22:15 187,392 ----a-w C:\WINDOWS\system32\mqtrig.dll - 2007-07-06 12:49:58 48,640 ----a-w C:\WINDOWS\system32\mqupgrd.dll + 2008-04-14 02:22:15 49,152 ----a-w C:\WINDOWS\system32\mqupgrd.dll - 2007-07-06 12:49:58 533,504 ----a-w C:\WINDOWS\system32\mqutil.dll + 2008-04-14 02:22:15 533,504 ----a-w C:\WINDOWS\system32\mqutil.dll - 2006-02-28 12:00:00 72,192 ----a-w C:\WINDOWS\system32\msacm32.dll + 2008-04-14 02:22:15 72,192 ----a-w C:\WINDOWS\system32\msacm32.dll - 2006-02-28 12:00:00 3,584 ----a-w C:\WINDOWS\system32\msafd.dll + 2008-04-14 02:20:57 3,584 ----a-w C:\WINDOWS\system32\msafd.dll - 2006-02-28 12:00:00 86,016 ----a-w C:\WINDOWS\system32\msapsspc.dll + 2008-04-14 02:22:16 86,016 ----a-w C:\WINDOWS\system32\msapsspc.dll - 2006-02-28 12:00:00 57,344 ----a-w C:\WINDOWS\system32\msasn1.dll + 2008-04-14 02:22:16 57,344 ----a-w C:\WINDOWS\system32\msasn1.dll - 2008-06-24 16:22:31 74,240 ----a-w C:\WINDOWS\system32\mscms.dll + 2008-06-24 16:42:48 74,240 ----a-w C:\WINDOWS\system32\mscms.dll - 2006-02-28 12:00:00 69,632 ----a-w C:\WINDOWS\system32\msconf.dll + 2008-04-14 02:22:16 69,632 ----a-w C:\WINDOWS\system32\msconf.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dLL + 2008-04-13 17:26:07 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll - 2006-02-28 12:00:00 36,864 ----a-w C:\WINDOWS\system32\mscpxl32.dLL + 2008-04-14 02:22:16 36,864 ----a-w C:\WINDOWS\system32\mscpxl32.dll - 2008-02-26 11:59:49 294,912 ----a-w C:\WINDOWS\system32\msctf.dll + 2008-04-14 02:22:16 297,984 ----a-w C:\WINDOWS\system32\msctf.dll - 2006-02-28 12:00:00 69,120 ----a-w C:\WINDOWS\system32\MSCTFP.dll + 2008-04-14 02:22:16 68,608 ----a-w C:\WINDOWS\system32\msctfp.dll - 2006-02-28 12:00:00 118,784 ----a-w C:\WINDOWS\system32\msdadiag.dll + 2008-04-14 02:22:16 118,784 ----a-w C:\WINDOWS\system32\msdadiag.dll - 2006-02-28 12:00:00 151,552 ----a-w C:\WINDOWS\system32\msdart.dll + 2008-04-14 02:22:16 151,552 ----a-w C:\WINDOWS\system32\msdart.dll - 2006-02-28 12:00:00 14,336 ----a-w C:\WINDOWS\system32\msdmo.dll + 2008-04-14 02:22:16 14,336 ----a-w C:\WINDOWS\system32\msdmo.dll - 2006-02-28 12:00:00 6,144 ----a-w C:\WINDOWS\system32\msdtc.exe + 2008-04-14 02:22:53 6,144 ----a-w C:\WINDOWS\system32\msdtc.exe - 2006-02-28 12:00:00 58,880 ----a-w C:\WINDOWS\system32\msdtclog.dll + 2008-04-14 02:22:16 58,880 ----a-w C:\WINDOWS\system32\msdtclog.dll - 2006-03-01 19:43:33 426,496 ----a-w C:\WINDOWS\system32\msdtcprx.dll + 2008-04-14 02:22:16 427,008 ----a-w C:\WINDOWS\system32\msdtcprx.dll - 2006-03-01 19:43:33 956,416 ----a-w C:\WINDOWS\system32\msdtctm.dll + 2008-04-14 02:22:16 956,928 ----a-w C:\WINDOWS\system32\msdtctm.dll - 2006-03-01 19:43:33 161,280 ----a-w C:\WINDOWS\system32\msdtcuiu.dll + 2008-04-14 02:22:16 161,792 ----a-w C:\WINDOWS\system32\msdtcuiu.dll - 2006-02-28 12:00:00 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll + 2008-04-14 02:20:58 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll - 2006-11-27 14:54:15 539,136 ----a-w C:\WINDOWS\system32\msftedit.dll + 2008-04-14 02:22:16 539,136 ----a-w C:\WINDOWS\system32\msftedit.dll - 2006-02-28 12:00:00 1,002,496 ----a-w C:\WINDOWS\system32\msgina.dll + 2008-04-14 02:22:16 1,005,568 ----a-w C:\WINDOWS\system32\msgina.dll - 2006-02-28 12:00:00 33,792 ----a-w C:\WINDOWS\system32\msgsvc.dll + 2008-04-14 02:22:16 33,792 ----a-w C:\WINDOWS\system32\msgsvc.dll - 2006-02-28 12:00:00 192,512 ----a-w C:\WINDOWS\system32\msh261.drv + 2008-04-14 02:23:08 192,512 ----a-w C:\WINDOWS\system32\msh261.drv - 2006-02-28 12:00:00 299,008 ----a-w C:\WINDOWS\system32\msh263.drv + 2008-04-14 02:23:08 299,008 ----a-w C:\WINDOWS\system32\msh263.drv - 2007-04-18 16:13:24 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll + 2008-04-14 02:22:17 2,843,136 ----a-w C:\WINDOWS\system32\msi.dll - 2006-02-28 12:00:00 51,712 ----a-w C:\WINDOWS\system32\msident.dll + 2008-04-14 02:22:17 51,712 ----a-w C:\WINDOWS\system32\msident.dll - 2006-02-28 12:00:00 6,656 ----a-w C:\WINDOWS\system32\msidle.dll + 2008-04-14 02:22:17 6,656 ----a-w C:\WINDOWS\system32\msidle.dll - 2006-02-28 12:00:00 252,928 ----a-w C:\WINDOWS\system32\msieftp.dll + 2008-04-14 02:22:17 252,928 ----a-w C:\WINDOWS\system32\msieftp.dll - 2005-05-04 12:45:36 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe + 2008-04-14 02:22:53 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe - 2005-05-04 12:45:36 271,360 ----a-w C:\WINDOWS\system32\msihnd.dll + 2008-04-14 02:22:17 271,360 ----a-w C:\WINDOWS\system32\msihnd.dll - 2006-02-28 12:00:00 4,608 ----a-w C:\WINDOWS\system32\msimg32.dll + 2008-04-14 02:22:17 4,608 ----a-w C:\WINDOWS\system32\msimg32.dll - 2005-05-04 12:45:36 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll + 2008-04-13 15:39:43 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll - 2006-02-28 12:00:00 159,232 ----a-w C:\WINDOWS\system32\MSIMTF.dll + 2008-04-14 02:22:17 159,232 ----a-w C:\WINDOWS\system32\msimtf.dll - 2005-05-04 12:45:36 15,360 ----a-w C:\WINDOWS\system32\msisip.dll + 2008-04-14 02:22:17 15,360 ----a-w C:\WINDOWS\system32\msisip.dll - 2006-02-28 12:00:00 25,600 ----a-w C:\WINDOWS\system32\mslbui.dll + 2008-04-14 02:22:17 25,600 ----a-w C:\WINDOWS\system32\mslbui.dll - 2006-02-28 12:00:00 290,816 ----a-w C:\WINDOWS\system32\msnsspc.dll + 2008-04-14 02:22:17 290,816 ----a-w C:\WINDOWS\system32\msnsspc.dll - 2006-02-28 12:00:00 252,928 ----a-w C:\WINDOWS\system32\msoeacct.dll + 2008-04-14 02:22:17 252,928 ----a-w C:\WINDOWS\system32\msoeacct.dll - 2006-02-28 12:00:00 105,984 ----a-w C:\WINDOWS\system32\msoert2.dll + 2008-04-14 02:22:18 105,984 ----a-w C:\WINDOWS\system32\msoert2.dll - 2006-02-28 12:00:00 24,576 ----a-w C:\WINDOWS\system32\msorc32r.dll + 2007-03-28 12:51:49 24,576 ----a-w C:\WINDOWS\system32\msorc32r.dll - 2006-02-28 12:00:00 143,360 ----a-w C:\WINDOWS\system32\msorcl32.dll + 2008-04-14 02:22:18 143,360 ----a-w C:\WINDOWS\system32\msorcl32.dll - 2006-02-28 12:00:00 346,624 ----a-w C:\WINDOWS\system32\mspaint.exe + 2008-04-14 02:22:54 346,624 ----a-w C:\WINDOWS\system32\mspaint.exe - 2006-02-28 12:00:00 30,208 ----a-w C:\WINDOWS\system32\mspatcha.dll + 2008-04-14 02:22:18 29,696 ----a-w C:\WINDOWS\system32\mspatcha.dll - 2006-02-28 12:00:00 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll + 2008-04-13 16:23:31 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll - 2006-02-28 12:00:00 11,264 ----a-w C:\WINDOWS\system32\msrle32.dll + 2008-04-14 02:22:18 11,264 ----a-w C:\WINDOWS\system32\msrle32.dll - 2006-02-28 12:00:00 134,656 ----a-w C:\WINDOWS\system32\mssap.dll + 2008-04-14 02:22:18 134,656 ----a-w C:\WINDOWS\system32\mssap.dll + 2008-04-14 02:22:18 155,136 ------w C:\WINDOWS\system32\mssha.dll + 2008-04-14 01:56:52 81,408 ------w C:\WINDOWS\system32\msshavmsg.dll - 2006-02-28 12:00:00 280,064 ----a-w C:\WINDOWS\system32\mstask.dll + 2008-04-14 02:22:18 280,064 ----a-w C:\WINDOWS\system32\mstask.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\mstinit.exe + 2008-04-14 02:22:54 12,288 ----a-w C:\WINDOWS\system32\mstinit.exe - 2006-02-28 12:00:00 115,712 ----a-w C:\WINDOWS\system32\mstlsapi.dll + 2008-04-14 02:22:18 116,224 ----a-w C:\WINDOWS\system32\mstlsapi.dll - 2006-02-28 12:00:00 412,672 ----a-w C:\WINDOWS\system32\mstsc.exe + 2008-04-14 02:22:50 677,888 ----a-w C:\WINDOWS\system32\mstsc.exe - 2006-02-28 12:00:00 655,360 ----a-w C:\WINDOWS\system32\mstscax.dll + 2008-04-14 02:22:13 2,061,824 ----a-w C:\WINDOWS\system32\mstscax.dll - 2006-02-28 12:00:00 196,096 ----a-w C:\WINDOWS\system32\msutb.dll + 2008-04-14 02:22:18 196,096 ----a-w C:\WINDOWS\system32\msutb.dll - 2006-02-28 12:00:00 129,536 ----a-w C:\WINDOWS\system32\msv1_0.dll + 2008-04-14 02:22:18 132,608 ----a-w C:\WINDOWS\system32\msv1_0.dll - 2006-02-28 12:00:00 1,392,671 ----a-w C:\WINDOWS\system32\msvbvm60.dll + 2008-04-14 02:22:18 1,384,479 ----a-w C:\WINDOWS\system32\msvbvm60.dll - 2006-02-28 12:00:00 54,784 ----a-w C:\WINDOWS\system32\msvcirt.dll + 2008-04-14 02:22:18 57,344 ----a-w C:\WINDOWS\system32\msvcirt.dll - 2006-02-28 12:00:00 413,696 ----a-w C:\WINDOWS\system32\msvcp60.dll + 2008-04-14 02:22:18 413,696 ----a-w C:\WINDOWS\system32\msvcp60.dll - 2006-02-28 12:00:00 343,040 ----a-w C:\WINDOWS\system32\msvcrt.dll + 2008-04-14 02:22:18 343,040 ----a-w C:\WINDOWS\system32\msvcrt.dll - 2006-02-28 12:00:00 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll + 2008-04-13 18:30:46 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll - 2006-02-28 12:00:00 121,856 ----a-w C:\WINDOWS\system32\msvfw32.dll + 2008-04-14 02:22:18 122,368 ----a-w C:\WINDOWS\system32\msvfw32.dll - 2006-02-28 12:00:00 1,432,576 ----a-w C:\WINDOWS\system32\msvidctl.dll + 2008-04-14 02:22:18 1,433,088 ----a-w C:\WINDOWS\system32\msvidctl.dll - 2006-02-28 12:00:00 72,704 ----a-w C:\WINDOWS\system32\msw3prt.dll + 2008-04-14 02:22:18 72,704 ----a-w C:\WINDOWS\system32\msw3prt.dll - 2006-02-28 12:00:00 205,312 ----a-w C:\WINDOWS\system32\mswebdvd.dll + 2008-04-14 02:22:18 205,312 ----a-w C:\WINDOWS\system32\mswebdvd.dll - 2008-06-20 17:39:48 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll + 2008-06-20 17:46:10 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll - 2006-02-28 12:00:00 506,368 ----a-w C:\WINDOWS\system32\msxml.dll + 2008-04-14 02:22:18 506,368 ----a-w C:\WINDOWS\system32\msxml.dll - 2006-02-28 12:00:00 701,440 ----a-w C:\WINDOWS\system32\msxml2.dll + 2008-04-14 02:22:18 701,440 ----a-w C:\WINDOWS\system32\msxml2.dll - 2007-06-26 06:08:37 1,104,896 ----a-w C:\WINDOWS\system32\msxml3.dll + 2008-04-14 02:22:18 1,104,896 ----a-w C:\WINDOWS\system32\msxml3.dll + 2008-04-14 02:22:18 1,306,624 ------w C:\WINDOWS\system32\msxml6.dll + 2008-04-14 01:57:41 93,184 ------w C:\WINDOWS\system32\msxml6r.dll - 2006-02-28 12:00:00 17,408 ----a-w C:\WINDOWS\system32\msyuv.dll + 2008-04-14 02:22:18 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll - 2006-03-01 19:43:33 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll + 2008-04-14 02:22:18 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll - 2006-02-28 12:00:00 20,480 ----a-w C:\WINDOWS\system32\mtxdm.dll + 2008-04-14 02:22:18 30,720 ----a-w C:\WINDOWS\system32\mtxdm.dll - 2006-02-28 12:00:00 4,096 ----a-w C:\WINDOWS\system32\mtxex.dll + 2008-04-14 02:22:18 4,096 ----a-w C:\WINDOWS\system32\mtxex.dll - 2006-02-28 12:00:00 25,088 ----a-w C:\WINDOWS\system32\mtxlegih.dll + 2008-04-14 02:22:18 34,304 ----a-w C:\WINDOWS\system32\mtxlegih.dll - 2006-03-01 19:43:33 91,136 ----a-w C:\WINDOWS\system32\mtxoci.dll + 2008-04-14 02:22:18 91,648 ----a-w C:\WINDOWS\system32\mtxoci.dll + 2008-04-14 02:22:18 1,737,856 ------w C:\WINDOWS\system32\mtxparhd.dll - 2006-02-28 12:00:00 91,136 ----a-w C:\WINDOWS\system32\mydocs.dll + 2008-04-14 02:22:19 91,136 ----a-w C:\WINDOWS\system32\mydocs.dll + 2008-04-14 02:22:19 30,208 ------w C:\WINDOWS\system32\napipsec.dll + 2008-04-14 02:22:19 198,656 ------w C:\WINDOWS\system32\napmontr.dll + 2008-04-14 02:22:54 177,664 ------w C:\WINDOWS\system32\napstat.exe - 2006-02-28 12:00:00 55,296 ----a-w C:\WINDOWS\system32\narrator.exe + 2008-04-14 02:22:54 55,296 ----a-w C:\WINDOWS\system32\narrator.exe - 2006-02-28 12:00:00 36,352 ----a-w C:\WINDOWS\system32\ncobjapi.dll + 2008-04-14 02:22:19 36,352 ----a-w C:\WINDOWS\system32\ncobjapi.dll - 2006-02-28 12:00:00 18,432 ----a-w C:\WINDOWS\system32\nddeapi.dll + 2008-04-14 02:22:19 18,432 ----a-w C:\WINDOWS\system32\nddeapi.dll - 2006-02-28 12:00:00 4,096 ----a-w C:\WINDOWS\system32\nddeapir.exe + 2008-04-14 02:22:54 4,096 ----a-w C:\WINDOWS\system32\nddeapir.exe - 2006-02-28 12:00:00 19,456 ----a-w C:\WINDOWS\system32\nddenb32.dll + 2008-04-14 02:22:19 19,456 ----a-w C:\WINDOWS\system32\nddenb32.dll - 2006-02-28 12:00:00 42,496 ----a-w C:\WINDOWS\system32\net.exe + 2008-04-14 02:22:55 42,496 ----a-w C:\WINDOWS\system32\net.exe - 2006-02-28 12:00:00 124,928 ----a-w C:\WINDOWS\system32\net1.exe + 2008-04-14 02:22:55 124,928 ----a-w C:\WINDOWS\system32\net1.exe - 2006-08-17 12:28:44 332,288 ----a-w C:\WINDOWS\system32\netapi32.dll + 2008-04-14 02:22:19 337,408 ----a-w C:\WINDOWS\system32\netapi32.dll - 2006-02-28 12:00:00 633,344 ----a-w C:\WINDOWS\system32\netcfgx.dll + 2008-04-14 02:22:19 633,856 ----a-w C:\WINDOWS\system32\netcfgx.dll - 2006-02-28 12:00:00 114,176 ----a-w C:\WINDOWS\system32\netdde.exe + 2008-04-14 02:22:55 114,176 ----a-w C:\WINDOWS\system32\netdde.exe - 2006-02-28 12:00:00 144,896 ----a-w C:\WINDOWS\system32\netid.dll + 2008-04-14 02:22:19 144,896 ----a-w C:\WINDOWS\system32\netid.dll - 2006-02-28 12:00:00 407,040 ----a-w C:\WINDOWS\system32\netlogon.dll + 2008-04-14 02:22:19 407,040 ----a-w C:\WINDOWS\system32\netlogon.dll - 2005-08-22 18:31:48 197,632 ----a-w C:\WINDOWS\system32\netman.dll + 2008-04-14 02:22:19 198,144 ----a-w C:\WINDOWS\system32\netman.dll |
![]() | #6 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2006-02-28 12:00:00 883,712 ----a-w C:\WINDOWS\system32\netplwiz.dll + 2008-04-14 02:22:19 883,712 ----a-w C:\WINDOWS\system32\netplwiz.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\netrap.dll + 2008-04-14 02:22:19 11,776 ----a-w C:\WINDOWS\system32\netrap.dll - 2006-02-28 12:00:00 333,312 ----a-w C:\WINDOWS\system32\netsetup.exe + 2008-04-14 02:25:38 333,312 ----a-w C:\WINDOWS\system32\netsetup.exe - 2006-02-28 12:00:00 88,064 ----a-w C:\WINDOWS\system32\netsh.exe + 2008-04-14 02:22:55 88,064 ----a-w C:\WINDOWS\system32\netsh.exe - 2006-02-28 12:00:00 1,726,976 ----a-w C:\WINDOWS\system32\netshell.dll + 2008-04-14 02:22:20 1,722,880 ----a-w C:\WINDOWS\system32\netshell.dll - 2006-02-28 12:00:00 37,376 ----a-w C:\WINDOWS\system32\netstat.exe + 2008-04-14 02:22:55 37,376 ----a-w C:\WINDOWS\system32\netstat.exe - 2006-02-28 12:00:00 81,920 ----a-w C:\WINDOWS\system32\netui0.dll + 2008-04-14 02:22:20 81,920 ----a-w C:\WINDOWS\system32\netui0.dll - 2006-02-28 12:00:00 245,760 ----a-w C:\WINDOWS\system32\netui1.dll + 2008-04-14 02:22:20 245,760 ----a-w C:\WINDOWS\system32\netui1.dll - 2006-02-28 12:00:00 251,392 ----a-w C:\WINDOWS\system32\newdev.dll + 2008-04-14 02:22:20 250,880 ----a-w C:\WINDOWS\system32\newdev.dll - 2006-02-28 12:00:00 103,936 ----a-w C:\WINDOWS\system32\nlhtml.dll + 2008-04-14 02:22:20 98,304 ----a-w C:\WINDOWS\system32\nlhtml.dll - 2006-02-28 12:00:00 28,672 ----a-w C:\WINDOWS\system32\nmmkcert.dll + 2008-04-14 02:22:20 28,672 ----a-w C:\WINDOWS\system32\nmmkcert.dll - 2006-02-28 12:00:00 70,144 ----a-w C:\WINDOWS\system32\notepad.exe + 2008-04-14 02:22:55 70,144 ----a-w C:\WINDOWS\system32\notepad.exe - 2006-02-28 12:00:00 57,344 ----a-w C:\WINDOWS\system32\npp\ndisnpp.dll + 2008-04-14 02:22:19 57,344 ----a-w C:\WINDOWS\system32\npp\ndisnpp.dll - 2006-02-28 12:00:00 15,360 ----a-w C:\WINDOWS\system32\npp\nppagent.exe + 2008-04-14 02:22:55 15,360 ----a-w C:\WINDOWS\system32\npp\nppagent.exe - 2006-02-28 12:00:00 55,296 ----a-w C:\WINDOWS\system32\npptools.dll + 2008-04-14 02:22:20 55,296 ----a-w C:\WINDOWS\system32\npptools.dll - 2006-02-28 12:00:00 80,896 ----a-w C:\WINDOWS\system32\nslookup.exe + 2008-04-14 02:22:55 80,896 ----a-w C:\WINDOWS\system32\nslookup.exe - 2006-02-28 12:00:00 1,228,800 ----a-w C:\WINDOWS\system32\ntbackup.exe + 2008-04-14 02:22:56 1,229,312 ----a-w C:\WINDOWS\system32\ntbackup.exe - 2006-02-28 12:00:00 733,696 ----a-w C:\WINDOWS\system32\ntdll.dll + 2008-04-14 02:21:52 731,648 ----a-w C:\WINDOWS\system32\ntdll.dll - 2006-02-28 12:00:00 67,072 ----a-w C:\WINDOWS\system32\ntdsapi.dll + 2008-04-14 02:22:20 67,072 ----a-w C:\WINDOWS\system32\ntdsapi.dll - 2007-02-28 16:02:05 2,018,304 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe + 2008-04-14 02:00:05 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe - 2006-02-28 12:00:00 43,520 ----a-w C:\WINDOWS\system32\ntlanman.dll + 2008-04-14 02:22:20 44,032 ----a-w C:\WINDOWS\system32\ntlanman.dll - 2006-02-28 12:00:00 8,192 ----a-w C:\WINDOWS\system32\ntlsapi.dll + 2008-04-14 02:22:20 8,192 ----a-w C:\WINDOWS\system32\ntlsapi.dll - 2006-02-28 12:00:00 119,296 ----a-w C:\WINDOWS\system32\ntmarta.dll + 2008-04-14 02:22:20 119,296 ----a-w C:\WINDOWS\system32\ntmarta.dll - 2006-02-28 12:00:00 40,960 ----a-w C:\WINDOWS\system32\ntmsapi.dll + 2008-04-14 02:22:20 40,960 ----a-w C:\WINDOWS\system32\ntmsapi.dll - 2006-02-28 12:00:00 180,224 ----a-w C:\WINDOWS\system32\ntmsdba.dll + 2008-04-14 02:22:20 180,224 ----a-w C:\WINDOWS\system32\ntmsdba.dll - 2006-02-28 12:00:00 497,664 ----a-w C:\WINDOWS\system32\ntmsmgr.dll + 2008-04-14 02:22:20 497,664 ----a-w C:\WINDOWS\system32\ntmsmgr.dll - 2006-02-28 12:00:00 438,272 ----a-w C:\WINDOWS\system32\ntmssvc.dll + 2008-04-14 02:22:20 438,272 ----a-w C:\WINDOWS\system32\ntmssvc.dll - 2007-02-28 16:02:08 2,138,624 ----a-w C:\WINDOWS\system32\ntoskrnl.exe + 2008-04-14 01:59:55 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe - 2006-02-28 12:00:00 92,160 ----a-w C:\WINDOWS\system32\ntprint.dll + 2008-04-14 02:22:21 92,160 ----a-w C:\WINDOWS\system32\ntprint.dll - 2006-02-28 12:00:00 145,920 ----a-w C:\WINDOWS\system32\ntshrui.dll + 2008-04-14 02:22:21 145,920 ----a-w C:\WINDOWS\system32\ntshrui.dll - 2006-02-28 12:00:00 421,376 ----a-w C:\WINDOWS\system32\ntvdm.exe + 2008-04-14 02:22:56 422,400 ----a-w C:\WINDOWS\system32\ntvdm.exe - 2006-02-28 12:00:00 13,312 ----a-w C:\WINDOWS\system32\ntvdmd.dll + 2008-04-14 02:22:21 15,360 ----a-w C:\WINDOWS\system32\ntvdmd.dll - 2006-10-13 12:35:14 64,000 ----a-w C:\WINDOWS\system32\nwapi32.dll + 2008-04-14 02:22:21 64,000 ----a-w C:\WINDOWS\system32\nwapi32.dll - 2006-10-13 12:35:14 146,432 ----a-w C:\WINDOWS\system32\nwprovau.dll + 2008-04-14 02:22:21 146,432 ----a-w C:\WINDOWS\system32\nwprovau.dll - 2006-10-13 12:35:14 65,536 ----a-w C:\WINDOWS\system32\nwwks.dll + 2008-04-14 02:22:21 65,536 ----a-w C:\WINDOWS\system32\nwwks.dll - 2006-02-28 12:00:00 267,776 ----a-w C:\WINDOWS\system32\oakley.dll + 2008-04-14 02:22:21 271,360 ----a-w C:\WINDOWS\system32\oakley.dll - 2006-02-28 12:00:00 288,768 ----a-w C:\WINDOWS\system32\objsel.dll + 2008-04-14 02:22:21 289,280 ----a-w C:\WINDOWS\system32\objsel.dll - 2006-02-28 12:00:00 62,976 ----a-w C:\WINDOWS\system32\ocmanage.dll + 2008-04-14 02:22:22 69,632 ----a-w C:\WINDOWS\system32\ocmanage.dll - 2006-02-28 12:00:00 249,856 ----a-w C:\WINDOWS\system32\odbc32.dll + 2008-04-14 02:22:22 249,856 ----a-w C:\WINDOWS\system32\odbc32.dll - 2006-02-28 12:00:00 16,384 ----a-w C:\WINDOWS\system32\odbc32gt.dll + 2008-04-14 02:22:22 16,384 ----a-w C:\WINDOWS\system32\odbc32gt.dll - 2006-02-28 12:00:00 32,768 ----a-w C:\WINDOWS\system32\odbcad32.exe + 2008-04-14 02:22:56 32,768 ----a-w C:\WINDOWS\system32\odbcad32.exe - 2006-02-28 12:00:00 24,576 ----a-w C:\WINDOWS\system32\odbcbcp.dll + 2008-04-14 02:22:22 24,576 ----a-w C:\WINDOWS\system32\odbcbcp.dll - 2006-02-28 12:00:00 135,168 ----a-w C:\WINDOWS\system32\odbcconf.dll + 2008-04-14 02:22:22 135,168 ----a-w C:\WINDOWS\system32\odbcconf.dll - 2006-02-28 12:00:00 69,632 ----a-w C:\WINDOWS\system32\odbcconf.exe + 2008-04-14 02:22:56 69,632 ----a-w C:\WINDOWS\system32\odbcconf.exe - 2006-02-28 12:00:00 106,496 ----a-w C:\WINDOWS\system32\odbccp32.dll + 2008-04-14 02:22:22 106,496 ----a-w C:\WINDOWS\system32\odbccp32.dll - 2006-02-28 12:00:00 65,536 ----a-w C:\WINDOWS\system32\odbccr32.dll + 2008-04-14 02:22:22 65,536 ----a-w C:\WINDOWS\system32\odbccr32.dll - 2006-02-28 12:00:00 65,536 ----a-w C:\WINDOWS\system32\odbccu32.dll + 2008-04-14 02:22:22 65,536 ----a-w C:\WINDOWS\system32\odbccu32.dll - 2006-02-28 12:00:00 102,400 ----a-w C:\WINDOWS\system32\odbcint.dll + 2007-03-28 12:51:52 102,400 ----a-w C:\WINDOWS\system32\odbcint.dll - 2006-02-28 12:00:00 57,616 ----a-w C:\WINDOWS\system32\odbcji32.dll + 2008-04-14 02:21:15 57,375 ----a-w C:\WINDOWS\system32\odbcji32.dll - 2006-02-28 12:00:00 278,559 ----a-w C:\WINDOWS\system32\odbcjt32.dll + 2008-04-14 02:22:23 278,559 ----a-w C:\WINDOWS\system32\odbcjt32.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll + 2008-04-13 17:26:05 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll - 2006-02-28 12:00:00 147,456 ----a-w C:\WINDOWS\system32\odbctrac.dll + 2008-04-14 02:22:23 147,456 ----a-w C:\WINDOWS\system32\odbctrac.dll - 2006-02-28 12:00:00 20,511 ----a-w C:\WINDOWS\system32\oddbse32.dll + 2008-04-14 02:22:23 20,511 ----a-w C:\WINDOWS\system32\oddbse32.dll - 2006-02-28 12:00:00 20,510 ----a-w C:\WINDOWS\system32\odexl32.dll + 2008-04-14 02:22:23 20,510 ----a-w C:\WINDOWS\system32\odexl32.dll - 2006-02-28 12:00:00 20,510 ----a-w C:\WINDOWS\system32\odfox32.dll + 2008-04-14 02:22:23 20,510 ----a-w C:\WINDOWS\system32\odfox32.dll - 2006-02-28 12:00:00 20,510 ----a-w C:\WINDOWS\system32\odpdx32.dll + 2008-04-14 02:22:23 20,510 ----a-w C:\WINDOWS\system32\odpdx32.dll - 2006-02-28 12:00:00 20,511 ----a-w C:\WINDOWS\system32\odtext32.dll + 2008-04-14 02:22:23 20,511 ----a-w C:\WINDOWS\system32\odtext32.dll - 2006-02-28 12:00:00 120,832 ----a-w C:\WINDOWS\system32\offfilt.dll + 2008-04-14 02:22:23 192,000 ----a-w C:\WINDOWS\system32\offfilt.dll - 2005-07-26 04:39:49 1,285,120 ----a-w C:\WINDOWS\system32\ole32.dll + 2008-04-14 02:22:23 1,287,680 ----a-w C:\WINDOWS\system32\ole32.dll - 2007-12-04 18:40:03 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll + 2008-04-14 02:22:23 551,936 ----a-w C:\WINDOWS\system32\oleaut32.dll - 2005-07-26 04:39:50 74,752 ----a-w C:\WINDOWS\system32\olecli32.dll + 2008-04-14 02:22:23 74,752 ----a-w C:\WINDOWS\system32\olecli32.dll - 2005-07-26 04:39:50 37,888 ----a-w C:\WINDOWS\system32\olecnv32.dll + 2008-04-14 02:22:23 37,376 ----a-w C:\WINDOWS\system32\olecnv32.dll - 2006-10-16 16:15:58 126,976 ----a-w C:\WINDOWS\system32\oledlg.dll + 2008-04-14 02:22:23 126,976 ----a-w C:\WINDOWS\system32\oledlg.dll - 2006-02-28 12:00:00 108,544 ----a-w C:\WINDOWS\system32\oleprn.dll + 2008-04-14 02:22:23 108,544 ----a-w C:\WINDOWS\system32\oleprn.dll - 2006-02-28 12:00:00 83,456 ----a-w C:\WINDOWS\system32\olepro32.dll + 2008-04-14 02:22:23 84,992 ----a-w C:\WINDOWS\system32\olepro32.dll + 2008-04-14 02:22:23 145,408 ------w C:\WINDOWS\system32\onex.dll - 2006-02-28 12:00:00 122,368 ----a-w C:\WINDOWS\system32\oobe\msobcomm.dll + 2008-04-14 02:22:17 122,368 ----a-w C:\WINDOWS\system32\oobe\msobcomm.dll - 2006-02-28 12:00:00 16,384 ----a-w C:\WINDOWS\system32\oobe\msobdl.dll + 2008-04-14 02:22:17 16,384 ----a-w C:\WINDOWS\system32\oobe\msobdl.dll - 2006-02-28 12:00:00 562,688 ----a-w C:\WINDOWS\system32\oobe\msobmain.dll + 2008-04-14 02:22:17 565,760 ----a-w C:\WINDOWS\system32\oobe\msobmain.dll - 2006-02-28 12:00:00 30,720 ----a-w C:\WINDOWS\system32\oobe\msobshel.dll + 2008-04-14 02:22:17 30,720 ----a-w C:\WINDOWS\system32\oobe\msobshel.dll - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\oobe\msobweb.dll + 2008-04-14 02:22:17 19,456 ----a-w C:\WINDOWS\system32\oobe\msobweb.dll - 2006-02-28 12:00:00 28,160 ----a-w C:\WINDOWS\system32\oobe\msoobe.exe + 2008-04-14 02:22:54 29,184 ----a-w C:\WINDOWS\system32\oobe\msoobe.exe - 2006-02-28 12:00:00 51,712 ----a-w C:\WINDOWS\system32\oobe\oobebaln.exe + 2008-04-14 02:22:56 51,712 ----a-w C:\WINDOWS\system32\oobe\oobebaln.exe - 2006-02-28 12:00:00 70,656 ----a-w C:\WINDOWS\system32\openfiles.exe + 2008-04-14 02:22:56 70,656 ----a-w C:\WINDOWS\system32\openfiles.exe - 2006-02-28 12:00:00 713,728 ----a-w C:\WINDOWS\system32\opengl32.dll + 2008-04-14 02:22:23 713,728 ----a-w C:\WINDOWS\system32\opengl32.dll - 2006-02-28 12:00:00 216,576 ----a-w C:\WINDOWS\system32\osk.exe + 2008-04-14 02:22:57 216,576 ----a-w C:\WINDOWS\system32\osk.exe - 2006-02-28 12:00:00 68,096 ----a-w C:\WINDOWS\system32\osuninst.dll + 2008-04-14 02:22:23 68,096 ----a-w C:\WINDOWS\system32\osuninst.dll - 2006-02-28 12:00:00 116,224 ----a-w C:\WINDOWS\system32\p2p.dll + 2008-04-14 02:22:23 153,600 ----a-w C:\WINDOWS\system32\p2p.dll - 2006-02-28 12:00:00 86,016 ----a-w C:\WINDOWS\system32\p2pgasvc.dll + 2008-04-14 02:22:23 105,472 ----a-w C:\WINDOWS\system32\p2pgasvc.dll - 2006-02-28 12:00:00 312,320 ----a-w C:\WINDOWS\system32\p2pgraph.dll + 2008-04-14 02:22:23 313,856 ----a-w C:\WINDOWS\system32\p2pgraph.dll - 2006-02-28 12:00:00 88,064 ----a-w C:\WINDOWS\system32\p2pnetsh.dll + 2008-04-14 02:22:23 115,712 ----a-w C:\WINDOWS\system32\p2pnetsh.dll - 2006-02-28 12:00:00 526,848 ----a-w C:\WINDOWS\system32\p2psvc.dll + 2008-04-14 02:22:23 554,496 ----a-w C:\WINDOWS\system32\p2psvc.dll - 2006-02-28 12:00:00 59,904 ----a-w C:\WINDOWS\system32\packager.exe + 2008-04-14 02:22:57 59,904 ----a-w C:\WINDOWS\system32\packager.exe - 2006-02-28 12:00:00 65,536 ----a-w C:\WINDOWS\system32\pautoenr.dll + 2008-04-14 02:22:23 70,144 ----a-w C:\WINDOWS\system32\pautoenr.dll - 2006-02-28 12:00:00 286,208 ----a-w C:\WINDOWS\system32\pdh.dll + 2008-04-14 02:22:23 286,720 ----a-w C:\WINDOWS\system32\pdh.dll - 2008-10-10 00:04:47 48,276 ----a-w C:\WINDOWS\system32\perfc007.dat + 2008-10-13 12:09:14 48,276 ----a-w C:\WINDOWS\system32\perfc007.dat - 2008-10-10 00:04:47 40,108 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-10-13 12:09:14 40,108 ----a-w C:\WINDOWS\system32\perfc009.dat - 2006-02-28 12:00:00 41,984 ----a-w C:\WINDOWS\system32\perfctrs.dll + 2008-04-14 02:22:23 41,984 ----a-w C:\WINDOWS\system32\perfctrs.dll - 2006-02-28 12:00:00 27,136 ----a-w C:\WINDOWS\system32\perfdisk.dll + 2008-04-14 02:22:23 27,136 ----a-w C:\WINDOWS\system32\perfdisk.dll - 2008-10-10 00:04:47 316,942 ----a-w C:\WINDOWS\system32\perfh007.dat + 2008-10-13 12:09:14 316,942 ----a-w C:\WINDOWS\system32\perfh007.dat - 2008-10-10 00:04:47 311,912 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-10-13 12:09:14 311,912 ----a-w C:\WINDOWS\system32\perfh009.dat - 2006-02-28 12:00:00 15,872 ----a-w C:\WINDOWS\system32\perfmon.exe + 2008-04-14 02:22:57 15,872 ----a-w C:\WINDOWS\system32\perfmon.exe - 2006-02-28 12:00:00 17,408 ----a-w C:\WINDOWS\system32\perfnet.dll + 2008-04-14 02:22:23 18,432 ----a-w C:\WINDOWS\system32\perfnet.dll - 2006-02-28 12:00:00 26,112 ----a-w C:\WINDOWS\system32\perfos.dll + 2008-04-14 02:22:23 26,112 ----a-w C:\WINDOWS\system32\perfos.dll - 2006-02-28 12:00:00 35,328 ----a-w C:\WINDOWS\system32\perfproc.dll + 2008-04-14 02:22:23 35,328 ----a-w C:\WINDOWS\system32\perfproc.dll + 2008-04-14 02:22:23 412,160 ------w C:\WINDOWS\system32\photometadatahandler.dll - 2006-02-28 12:00:00 172,032 ----a-w C:\WINDOWS\system32\photowiz.dll + 2008-04-14 02:22:23 172,032 ----a-w C:\WINDOWS\system32\photowiz.dll - 2006-02-28 12:00:00 35,328 ----a-w C:\WINDOWS\system32\pid.dll + 2008-04-14 02:22:23 35,328 ----a-w C:\WINDOWS\system32\pid.dll - 2006-02-28 12:00:00 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll + 2008-04-14 02:21:42 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\ping.exe + 2008-04-14 02:22:57 18,944 ----a-w C:\WINDOWS\system32\ping.exe - 2006-02-28 12:00:00 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll + 2008-04-14 02:22:23 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll - 2006-02-28 12:00:00 48,640 ----a-w C:\WINDOWS\system32\pnrpnsp.dll + 2008-04-14 02:22:23 58,880 ----a-w C:\WINDOWS\system32\pnrpnsp.dll - 2006-02-28 12:00:00 105,984 ----a-w C:\WINDOWS\system32\polstore.dll + 2008-04-14 02:22:23 105,984 ----a-w C:\WINDOWS\system32\polstore.dll |
![]() | #7 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen"....Code:
ATTFilter - 2006-02-28 12:00:00 49,152 ----a-w C:\WINDOWS\system32\powercfg.exe + 2008-04-14 02:22:57 49,152 ----a-w C:\WINDOWS\system32\powercfg.exe - 2006-02-28 12:00:00 17,408 ----a-w C:\WINDOWS\system32\powrprof.dll + 2008-04-14 02:22:23 17,408 ----a-w C:\WINDOWS\system32\powrprof.dll - 2006-02-28 12:00:00 577,024 ----a-w C:\WINDOWS\system32\printui.dll + 2008-04-14 02:22:23 576,512 ----a-w C:\WINDOWS\system32\printui.dll - 2006-02-28 12:00:00 27,648 ----a-w C:\WINDOWS\system32\profmap.dll + 2008-04-14 02:22:23 27,648 ----a-w C:\WINDOWS\system32\profmap.dll - 2006-02-28 12:00:00 109,568 ----a-w C:\WINDOWS\system32\progman.exe + 2008-04-14 02:22:57 109,568 ----a-w C:\WINDOWS\system32\progman.exe - 2006-02-28 12:00:00 50,688 ----a-w C:\WINDOWS\system32\proquota.exe + 2008-04-14 02:22:57 50,688 ----a-w C:\WINDOWS\system32\proquota.exe - 2006-02-28 12:00:00 9,728 ----a-w C:\WINDOWS\system32\proxycfg.exe + 2008-04-14 02:22:57 9,728 ----a-w C:\WINDOWS\system32\proxycfg.exe - 2006-02-28 12:00:00 23,040 ----a-w C:\WINDOWS\system32\psapi.dll + 2008-04-14 02:22:23 23,040 ----a-w C:\WINDOWS\system32\psapi.dll - 2006-02-28 12:00:00 99,328 ----a-w C:\WINDOWS\system32\psbase.dll + 2008-04-14 02:22:23 99,328 ----a-w C:\WINDOWS\system32\psbase.dll - 2006-02-28 12:00:00 43,520 ----a-w C:\WINDOWS\system32\pstorec.dll + 2008-04-14 02:22:23 43,520 ----a-w C:\WINDOWS\system32\pstorec.dll - 2006-02-28 12:00:00 34,816 ----a-w C:\WINDOWS\system32\pstorsvc.dll + 2008-04-14 02:22:23 34,816 ----a-w C:\WINDOWS\system32\pstorsvc.dll + 2008-04-14 02:22:23 151,040 ------w C:\WINDOWS\system32\qagent.dll + 2008-04-14 02:22:23 294,400 ------w C:\WINDOWS\system32\qagentrt.dll - 2006-02-28 12:00:00 192,512 ----a-w C:\WINDOWS\system32\qcap.dll + 2008-04-14 02:22:23 192,512 ----a-w C:\WINDOWS\system32\qcap.dll + 2008-04-14 02:22:23 62,464 ------w C:\WINDOWS\system32\qcliprov.dll - 2006-02-28 12:00:00 279,040 ----a-w C:\WINDOWS\system32\qdv.dll + 2008-04-14 02:22:23 279,040 ----a-w C:\WINDOWS\system32\qdv.dll - 2006-02-28 12:00:00 386,048 ----a-w C:\WINDOWS\system32\qdvd.dll + 2008-04-14 02:22:23 387,072 ----a-w C:\WINDOWS\system32\qdvd.dll - 2006-02-28 12:00:00 563,200 ----a-w C:\WINDOWS\system32\qedit.dll + 2008-04-14 02:22:23 563,200 ----a-w C:\WINDOWS\system32\qedit.dll - 2006-02-28 12:00:00 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll + 2008-04-13 17:21:32 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll - 2006-02-28 12:00:00 382,464 ----a-w C:\WINDOWS\system32\qmgr.dll + 2008-04-14 02:22:23 409,088 ----a-w C:\WINDOWS\system32\qmgr.dll - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\qmgrprxy.dll + 2008-04-14 02:22:23 18,944 ----a-w C:\WINDOWS\system32\qmgrprxy.dll - 2006-02-28 12:00:00 20,480 ----a-w C:\WINDOWS\system32\qprocess.exe + 2008-04-14 02:22:57 20,480 ----a-w C:\WINDOWS\system32\qprocess.exe - 2008-05-07 05:14:45 1,293,312 ----a-w C:\WINDOWS\system32\quartz.dll + 2008-05-07 05:10:35 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll - 2006-06-22 05:06:24 1,441,792 ----a-w C:\WINDOWS\system32\query.dll + 2008-04-14 02:22:23 1,441,792 ----a-w C:\WINDOWS\system32\query.dll + 2008-04-14 02:22:23 76,800 ------w C:\WINDOWS\system32\qutil.dll - 2006-02-28 12:00:00 44,032 ----a-w C:\WINDOWS\system32\racpldlg.dll + 2008-04-14 02:22:23 43,520 ----a-w C:\WINDOWS\system32\racpldlg.dll - 2006-06-26 17:40:34 8,192 ----a-w C:\WINDOWS\system32\rasadhlp.dll + 2008-04-14 02:22:23 7,680 ----a-w C:\WINDOWS\system32\rasadhlp.dll - 2006-02-28 12:00:00 236,544 ----a-w C:\WINDOWS\system32\rasapi32.dll + 2008-04-14 02:22:23 237,056 ----a-w C:\WINDOWS\system32\rasapi32.dll - 2006-02-28 12:00:00 89,088 ----a-w C:\WINDOWS\system32\rasauto.dll + 2008-04-14 02:22:23 88,576 ----a-w C:\WINDOWS\system32\rasauto.dll - 2006-02-28 12:00:00 69,632 ----a-w C:\WINDOWS\system32\raschap.dll + 2008-04-14 02:22:23 79,872 ----a-w C:\WINDOWS\system32\raschap.dll - 2006-02-28 12:00:00 686,592 ----a-w C:\WINDOWS\system32\rasdlg.dll + 2008-04-14 02:22:23 687,104 ----a-w C:\WINDOWS\system32\rasdlg.dll - 2006-02-28 12:00:00 61,440 ----a-w C:\WINDOWS\system32\rasman.dll + 2008-04-14 02:22:23 61,440 ----a-w C:\WINDOWS\system32\rasman.dll - 2006-06-22 10:47:23 181,248 ----a-w C:\WINDOWS\system32\rasmans.dll + 2008-04-14 02:22:23 186,368 ----a-w C:\WINDOWS\system32\rasmans.dll - 2006-02-28 12:00:00 57,344 ----a-w C:\WINDOWS\system32\rasphone.exe + 2008-04-14 02:22:57 57,344 ----a-w C:\WINDOWS\system32\rasphone.exe - 2006-02-28 12:00:00 206,336 ----a-w C:\WINDOWS\system32\rasppp.dll + 2008-04-14 02:22:23 210,944 ----a-w C:\WINDOWS\system32\rasppp.dll + 2008-04-14 02:22:23 61,952 ------w C:\WINDOWS\system32\rasqec.dll - 2006-02-28 12:00:00 16,896 ----a-w C:\WINDOWS\system32\rassapi.dll + 2008-04-14 02:22:23 16,384 ----a-w C:\WINDOWS\system32\rassapi.dll - 2006-02-28 12:00:00 58,880 ----a-w C:\WINDOWS\system32\rastapi.dll + 2008-04-14 02:22:23 58,368 ----a-w C:\WINDOWS\system32\rastapi.dll - 2006-02-28 12:00:00 113,152 ----a-w C:\WINDOWS\system32\rastls.dll + 2008-04-14 02:22:23 151,040 ----a-w C:\WINDOWS\system32\rastls.dll - 2006-02-28 12:00:00 102,912 ----a-w C:\WINDOWS\system32\rcbdyctl.dll + 2008-04-14 02:22:23 102,912 ----a-w C:\WINDOWS\system32\rcbdyctl.dll - 2006-02-28 12:00:00 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe + 2008-04-14 02:22:57 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe - 2006-02-28 12:00:00 22,528 ----a-w C:\WINDOWS\system32\rcp.exe + 2008-04-14 02:22:58 22,528 ----a-w C:\WINDOWS\system32\rcp.exe - 2006-02-28 12:00:00 147,968 ----a-w C:\WINDOWS\system32\rdchost.dll + 2008-04-14 02:22:23 147,968 ----a-w C:\WINDOWS\system32\rdchost.dll - 2006-02-28 12:00:00 62,464 ----a-w C:\WINDOWS\system32\rdpclip.exe + 2008-04-14 02:22:58 62,976 ----a-w C:\WINDOWS\system32\rdpclip.exe - 2006-02-28 12:00:00 92,168 ----a-w C:\WINDOWS\system32\rdpdd.dll + 2008-04-14 02:23:27 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll - 2006-02-28 12:00:00 19,968 ----a-w C:\WINDOWS\system32\rdpsnd.dll + 2008-04-14 02:22:23 19,968 ----a-w C:\WINDOWS\system32\rdpsnd.dll - 2006-02-28 12:00:00 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll + 2008-04-14 02:23:27 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll - 2006-02-28 12:00:00 13,824 ----a-w C:\WINDOWS\system32\rdsaddin.exe + 2008-04-14 02:22:58 13,824 ----a-w C:\WINDOWS\system32\rdsaddin.exe - 2006-02-28 12:00:00 67,072 ----a-w C:\WINDOWS\system32\rdshost.exe + 2008-04-14 02:22:58 67,072 ----a-w C:\WINDOWS\system32\rdshost.exe - 2006-02-28 12:00:00 53,248 ----a-w C:\WINDOWS\system32\reg.exe + 2008-04-14 02:22:58 53,248 ----a-w C:\WINDOWS\system32\reg.exe - 2006-02-28 12:00:00 49,664 ----a-w C:\WINDOWS\system32\regapi.dll + 2008-04-14 02:22:23 49,664 ----a-w C:\WINDOWS\system32\regapi.dll - 2006-02-28 12:00:00 59,904 ----a-w C:\WINDOWS\system32\regsvc.dll + 2008-04-14 02:22:23 59,904 ----a-w C:\WINDOWS\system32\regsvc.dll - 2006-02-28 12:00:00 12,288 ----a-w C:\WINDOWS\system32\regsvr32.exe + 2008-04-14 02:22:58 12,288 ----a-w C:\WINDOWS\system32\regsvr32.exe - 2006-02-28 12:00:00 399,872 ----a-w C:\WINDOWS\system32\regwizc.dll + 2008-04-14 02:22:23 399,872 ----a-w C:\WINDOWS\system32\regwizc.dll + 2006-02-28 12:00:00 39,424 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\processr.sys + 2006-02-28 12:00:00 39,424 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\processr.sys - 2006-02-28 12:00:00 61,440 ----a-w C:\WINDOWS\system32\remotepg.dll + 2008-04-14 02:22:23 61,440 ----a-w C:\WINDOWS\system32\remotepg.dll - 2006-02-28 12:00:00 385,536 ----a-w C:\WINDOWS\system32\Restore\rstrui.exe + 2008-04-14 02:22:59 385,536 ----a-w C:\WINDOWS\system32\Restore\rstrui.exe - 2006-02-28 12:00:00 58,880 ----a-w C:\WINDOWS\system32\resutils.dll + 2008-04-14 02:22:23 58,880 ----a-w C:\WINDOWS\system32\resutils.dll - 2006-02-28 12:00:00 14,848 ----a-w C:\WINDOWS\system32\rexec.exe + 2008-04-14 02:22:58 14,848 ----a-w C:\WINDOWS\system32\rexec.exe + 2008-04-14 02:22:23 290,304 ------w C:\WINDOWS\system32\rhttpaa.dll - 2006-11-27 14:54:15 433,152 ----a-w C:\WINDOWS\system32\riched20.dll + 2008-04-14 02:22:23 433,664 ----a-w C:\WINDOWS\system32\riched20.dll - 2007-07-09 13:11:35 584,192 ----a-w C:\WINDOWS\system32\rpcrt4.dll + 2008-04-14 02:22:23 584,704 ----a-w C:\WINDOWS\system32\rpcrt4.dll - 2005-07-26 04:39:50 397,824 ----a-w C:\WINDOWS\system32\rpcss.dll + 2008-04-14 02:22:23 399,360 ----a-w C:\WINDOWS\system32\rpcss.dll - 2006-02-28 12:00:00 152,576 ----a-w C:\WINDOWS\system32\rsaenh.dll + 2008-04-13 17:37:57 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll - 2006-02-28 12:00:00 15,360 ----a-w C:\WINDOWS\system32\rsh.exe + 2008-04-14 02:22:58 15,360 ----a-w C:\WINDOWS\system32\rsh.exe - 2006-02-28 12:00:00 40,448 ----a-w C:\WINDOWS\system32\rshx32.dll + 2008-04-14 02:22:23 40,448 ----a-w C:\WINDOWS\system32\rshx32.dll - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\rsmps.dll + 2008-04-14 02:22:23 18,944 ----a-w C:\WINDOWS\system32\rsmps.dll - 2006-02-28 12:00:00 107,520 ----a-w C:\WINDOWS\system32\rsnotify.exe + 2008-04-14 02:22:58 107,520 ----a-w C:\WINDOWS\system32\rsnotify.exe - 2006-02-28 12:00:00 90,112 ----a-w C:\WINDOWS\system32\rsvpsp.dll + 2008-04-14 02:22:23 92,672 ----a-w C:\WINDOWS\system32\rsvpsp.dll - 2006-02-28 12:00:00 78,848 ----a-w C:\WINDOWS\system32\rtcshare.exe + 2008-04-14 02:22:59 78,848 ----a-w C:\WINDOWS\system32\rtcshare.exe - 2006-02-28 12:00:00 31,744 ----a-w C:\WINDOWS\system32\rtipxmib.dll + 2008-04-14 02:22:23 31,744 ----a-w C:\WINDOWS\system32\rtipxmib.dll - 2006-02-28 12:00:00 44,032 ----a-w C:\WINDOWS\system32\rtutils.dll + 2008-04-14 02:22:23 44,032 ----a-w C:\WINDOWS\system32\rtutils.dll - 2006-02-28 12:00:00 33,792 ----a-w C:\WINDOWS\system32\rundll32.exe + 2008-04-14 02:22:59 33,792 ----a-w C:\WINDOWS\system32\rundll32.exe - 2006-02-28 12:00:00 14,336 ----a-w C:\WINDOWS\system32\runonce.exe + 2008-04-14 02:22:59 14,336 ----a-w C:\WINDOWS\system32\runonce.exe + 2008-04-14 02:22:23 9,728 ------w C:\WINDOWS\system32\rwnh.dll + 2008-04-14 02:22:23 397,056 ------w C:\WINDOWS\system32\s3gnb.dll - 2006-02-28 12:00:00 43,520 ----a-w C:\WINDOWS\system32\safrcdlg.dll + 2008-04-14 02:22:23 43,520 ----a-w C:\WINDOWS\system32\safrcdlg.dll - 2006-02-28 12:00:00 29,696 ----a-w C:\WINDOWS\system32\safrdm.dll + 2008-04-14 02:22:23 29,696 ----a-w C:\WINDOWS\system32\safrdm.dll - 2006-02-28 12:00:00 45,568 ----a-w C:\WINDOWS\system32\safrslv.dll + 2008-04-14 02:22:23 45,568 ----a-w C:\WINDOWS\system32\safrslv.dll - 2006-02-28 12:00:00 64,000 ----a-w C:\WINDOWS\system32\samlib.dll + 2008-04-14 02:22:23 64,000 ----a-w C:\WINDOWS\system32\samlib.dll - 2006-02-28 12:00:00 429,568 ----a-w C:\WINDOWS\system32\samsrv.dll + 2008-04-14 02:22:23 429,568 ----a-w C:\WINDOWS\system32\samsrv.dll - 2006-02-28 12:00:00 13,312 ----a-w C:\WINDOWS\system32\savedump.exe + 2008-04-14 02:22:59 13,312 ----a-w C:\WINDOWS\system32\savedump.exe - 2006-02-28 12:00:00 270,848 ----a-w C:\WINDOWS\system32\sbe.dll + 2008-04-14 02:22:23 270,848 ----a-w C:\WINDOWS\system32\sbe.dll - 2006-02-28 12:00:00 159,232 ----a-w C:\WINDOWS\system32\sbeio.dll + 2008-04-14 02:22:23 159,232 ----a-w C:\WINDOWS\system32\sbeio.dll - 2006-02-28 12:00:00 70,656 ----a-w C:\WINDOWS\system32\scarddlg.dll + 2008-04-14 02:22:23 70,656 ----a-w C:\WINDOWS\system32\scarddlg.dll - 2006-02-28 12:00:00 99,840 ----a-w C:\WINDOWS\system32\scardsvr.exe + 2008-04-14 02:22:59 99,840 ----a-w C:\WINDOWS\system32\scardsvr.exe - 2006-02-28 12:00:00 171,520 ----a-w C:\WINDOWS\system32\sccsccp.dll + 2008-04-14 02:22:23 171,520 ----a-w C:\WINDOWS\system32\sccsccp.dll - 2006-02-28 12:00:00 186,880 ----a-w C:\WINDOWS\system32\scecli.dll + 2008-04-14 02:22:23 187,904 ----a-w C:\WINDOWS\system32\scecli.dll - 2006-02-28 12:00:00 327,168 ----a-w C:\WINDOWS\system32\scesrv.dll + 2008-04-14 02:22:23 328,192 ----a-w C:\WINDOWS\system32\scesrv.dll - 2007-04-25 14:22:27 144,896 ----a-w C:\WINDOWS\system32\schannel.dll + 2008-04-14 02:22:23 144,384 ----a-w C:\WINDOWS\system32\schannel.dll - 2006-02-28 12:00:00 192,000 ----a-w C:\WINDOWS\system32\schedsvc.dll + 2008-04-14 02:22:23 193,536 ----a-w C:\WINDOWS\system32\schedsvc.dll - 2006-02-28 12:00:00 127,488 ----a-w C:\WINDOWS\system32\schtasks.exe + 2008-04-14 02:22:59 126,976 ----a-w C:\WINDOWS\system32\schtasks.exe - 2006-02-28 12:00:00 23,040 ----a-w C:\WINDOWS\system32\sclgntfy.dll + 2008-04-14 02:22:23 23,040 ----a-w C:\WINDOWS\system32\sclgntfy.dll - 2006-02-28 12:00:00 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr + 2008-04-14 02:23:08 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr - 2006-02-28 12:00:00 159,744 ----a-w C:\WINDOWS\system32\scrobj.dll + 2008-04-14 02:22:23 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll - 2006-02-28 12:00:00 151,552 ----a-w C:\WINDOWS\system32\scrrun.dll + 2008-04-14 02:22:24 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll - 2006-02-28 12:00:00 78,336 ----a-w C:\WINDOWS\system32\sdbinst.exe + 2008-04-14 02:22:59 78,336 ----a-w C:\WINDOWS\system32\sdbinst.exe - 2006-02-28 12:00:00 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll + 2008-04-14 02:22:24 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll - 2006-02-28 12:00:00 19,456 ----a-w C:\WINDOWS\system32\secedit.exe + 2008-04-14 02:22:59 19,968 ----a-w C:\WINDOWS\system32\secedit.exe - 2006-02-28 12:00:00 18,944 ----a-w C:\WINDOWS\system32\seclogon.dll + 2008-04-14 02:22:24 18,944 ----a-w C:\WINDOWS\system32\seclogon.dll - 2006-02-28 12:00:00 55,808 ----a-w C:\WINDOWS\system32\secur32.dll + 2008-04-14 02:22:24 56,320 ----a-w C:\WINDOWS\system32\secur32.dll - 2006-02-28 12:00:00 5,632 ----a-w C:\WINDOWS\system32\security.dll + 2008-04-14 02:22:24 5,632 ----a-w C:\WINDOWS\system32\security.dll - 2006-02-28 12:00:00 29,696 ----a-w C:\WINDOWS\system32\sendcmsg.dll + 2008-04-14 02:22:24 29,696 ----a-w C:\WINDOWS\system32\sendcmsg.dll - 2006-02-28 12:00:00 55,296 ----a-w C:\WINDOWS\system32\sendmail.dll + 2008-04-14 02:22:24 55,296 ----a-w C:\WINDOWS\system32\sendmail.dll - 2006-02-28 12:00:00 38,912 ----a-w C:\WINDOWS\system32\sens.dll + 2008-04-14 02:22:24 39,424 ----a-w C:\WINDOWS\system32\sens.dll - 2006-02-28 12:00:00 6,656 ----a-w C:\WINDOWS\system32\sensapi.dll + 2008-04-14 02:22:24 7,168 ----a-w C:\WINDOWS\system32\sensapi.dll - 2006-02-28 12:00:00 56,320 ----a-w C:\WINDOWS\system32\servdeps.dll + 2008-04-14 02:22:24 56,320 ----a-w C:\WINDOWS\system32\servdeps.dll - 2006-02-28 12:00:00 108,544 ----a-w C:\WINDOWS\system32\services.exe + 2008-04-14 02:22:59 109,056 ----a-w C:\WINDOWS\system32\services.exe - 2006-02-28 12:00:00 142,848 ----a-w C:\WINDOWS\system32\sessmgr.exe + 2008-04-14 02:23:00 143,360 ----a-w C:\WINDOWS\system32\sessmgr.exe - 2006-02-28 12:00:00 32,768 ----a-w C:\WINDOWS\system32\sethc.exe + 2008-04-14 02:23:00 32,768 ----a-w C:\WINDOWS\system32\sethc.exe - 2006-02-28 12:00:00 23,040 ----a-w C:\WINDOWS\system32\setup.exe + 2008-04-14 02:23:00 23,040 ----a-w C:\WINDOWS\system32\setup.exe - 2006-02-28 12:00:00 259,584 ----a-w C:\WINDOWS\system32\Setup\comsetup.dll + 2008-04-14 02:22:08 274,944 ----a-w C:\WINDOWS\system32\Setup\comsetup.dll - 2006-02-28 12:00:00 32,828 ----a-w C:\WINDOWS\system32\Setup\fp40ext.dll + 2008-04-14 02:22:10 32,828 ----a-w C:\WINDOWS\system32\Setup\fp40ext.dll - 2006-02-28 12:00:00 132,608 ----a-w C:\WINDOWS\system32\Setup\fxsocm.dll + 2008-04-14 02:22:10 132,608 ----a-w C:\WINDOWS\system32\Setup\fxsocm.dll - 2006-02-28 12:00:00 508,416 ----a-w C:\WINDOWS\system32\Setup\iis.dll + 2008-04-14 02:22:12 508,416 ----a-w C:\WINDOWS\system32\Setup\iis.dll - 2006-02-28 12:00:00 118,784 ----a-w C:\WINDOWS\system32\Setup\imsinsnt.dll + 2008-04-14 02:22:12 126,464 ----a-w C:\WINDOWS\system32\Setup\imsinsnt.dll + 2008-04-14 02:22:13 8,192 ----a-w C:\WINDOWS\system32\Setup\koc.dll - 2006-02-28 12:00:00 16,896 ----a-w C:\WINDOWS\system32\Setup\medctroc.dll + 2008-04-14 02:22:14 16,896 ----a-w C:\WINDOWS\system32\Setup\medctroc.dll - 2006-02-28 12:00:00 82,432 ----a-w C:\WINDOWS\system32\Setup\msdtcstp.dll + 2008-04-14 02:22:16 90,112 ----a-w C:\WINDOWS\system32\Setup\msdtcstp.dll - 2006-02-28 12:00:00 15,360 ----a-w C:\WINDOWS\system32\Setup\msgrocm.dll + 2008-04-14 02:22:16 15,360 ----a-w C:\WINDOWS\system32\Setup\msgrocm.dll - 2006-02-28 12:00:00 169,984 ----a-w C:\WINDOWS\system32\Setup\msmqocm.dll + 2008-04-14 02:22:17 170,496 ----a-w C:\WINDOWS\system32\Setup\msmqocm.dll - 2006-02-28 12:00:00 78,336 ----a-w C:\WINDOWS\system32\Setup\netoc.dll + 2008-04-14 02:22:19 78,336 ----a-w C:\WINDOWS\system32\Setup\netoc.dll - 2006-02-28 12:00:00 63,488 ----a-w C:\WINDOWS\system32\Setup\ntoc.dll + 2008-04-14 02:22:20 63,488 ----a-w C:\WINDOWS\system32\Setup\ntoc.dll - 2006-02-28 12:00:00 15,872 ----a-w C:\WINDOWS\system32\Setup\ocgen.dll + 2008-04-14 02:22:22 15,360 ----a-w C:\WINDOWS\system32\Setup\ocgen.dll - 2006-02-28 12:00:00 17,408 ----a-w C:\WINDOWS\system32\Setup\ocmsn.dll + 2008-04-14 02:22:22 17,408 ----a-w C:\WINDOWS\system32\Setup\ocmsn.dll - 2006-02-28 12:00:00 101,888 ----a-w C:\WINDOWS\system32\Setup\setupqry.dll + 2008-04-14 02:22:24 101,888 ----a-w C:\WINDOWS\system32\Setup\setupqry.dll - 2006-02-28 12:00:00 34,304 ----a-w C:\WINDOWS\system32\Setup\tabletoc.dll + 2008-04-14 02:22:30 34,304 ----a-w C:\WINDOWS\system32\Setup\tabletoc.dll - 2006-02-28 12:00:00 123,392 ----a-w C:\WINDOWS\system32\Setup\tsoc.dll + 2008-04-14 02:22:30 131,584 ----a-w C:\WINDOWS\system32\Setup\tsoc.dll - 2006-02-28 12:00:00 988,672 ----a-w C:\WINDOWS\system32\setupapi.dll + 2008-04-14 05:52:26 989,696 ----a-w C:\WINDOWS\system32\setupapi.dll + 2008-04-14 02:23:00 32,768 ------w C:\WINDOWS\system32\setupn.exe - 2006-02-28 12:00:00 5,120 ----a-w C:\WINDOWS\system32\sfc.dll + 2008-04-14 02:22:24 5,120 ----a-w C:\WINDOWS\system32\sfc.dll - 2006-02-28 12:00:00 142,336 ----a-w C:\WINDOWS\system32\sfc_os.dll + 2008-04-14 02:22:24 142,336 ----a-w C:\WINDOWS\system32\sfc_os.dll - 2006-02-28 12:00:00 1,548,288 ----a-w C:\WINDOWS\system32\sfcfiles.dll + 2008-04-14 02:22:25 1,571,840 ----a-w C:\WINDOWS\system32\sfcfiles.dll - 2006-02-28 12:00:00 572,928 ----a-w C:\WINDOWS\system32\shdoclc.dll + 2008-04-14 01:55:38 572,928 ----a-w C:\WINDOWS\system32\shdoclc.dll - 2008-02-16 09:30:56 1,499,136 ----a-w C:\WINDOWS\system32\shdocvw.dll + 2008-04-14 02:22:25 1,499,136 ----a-w C:\WINDOWS\system32\shdocvw.dll - 2007-10-25 16:55:09 8,495,616 ----a-w C:\WINDOWS\system32\shell32.dll + 2008-04-14 02:22:25 8,502,272 ----a-w C:\WINDOWS\system32\shell32.dll - 2006-02-28 12:00:00 25,088 ----a-w C:\WINDOWS\system32\shfolder.dll + 2008-04-14 02:22:25 25,088 ----a-w C:\WINDOWS\system32\shfolder.dll - 2006-02-28 12:00:00 68,096 ----a-w C:\WINDOWS\system32\shgina.dll + 2008-04-14 02:22:25 68,096 ----a-w C:\WINDOWS\system32\shgina.dll - 2006-02-28 12:00:00 65,536 ----a-w C:\WINDOWS\system32\shimeng.dll + 2008-04-14 02:22:25 65,024 ----a-w C:\WINDOWS\system32\shimeng.dll - 2006-02-28 12:00:00 439,808 ----a-w C:\WINDOWS\system32\shimgvw.dll + 2008-04-14 02:22:25 439,808 ----a-w C:\WINDOWS\system32\shimgvw.dll - 2008-02-16 09:30:57 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll + 2008-04-14 02:22:25 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll - 2006-02-28 12:00:00 153,600 ----a-w C:\WINDOWS\system32\shmedia.dll + 2008-04-14 02:22:25 154,112 ----a-w C:\WINDOWS\system32\shmedia.dll - 2006-02-28 12:00:00 42,496 ----a-w C:\WINDOWS\system32\shmgrate.exe + 2008-04-14 02:23:00 45,056 ----a-w C:\WINDOWS\system32\shmgrate.exe - 2006-02-28 12:00:00 78,336 ----a-w C:\WINDOWS\system32\shrpubw.exe + 2008-04-14 02:23:00 78,336 ----a-w C:\WINDOWS\system32\shrpubw.exe - 2006-02-28 12:00:00 28,160 ----a-w C:\WINDOWS\system32\shscrap.dll + 2008-04-14 02:22:25 28,160 ----a-w C:\WINDOWS\system32\shscrap.dll - 2006-12-19 21:49:41 135,168 ----a-w C:\WINDOWS\system32\shsvcs.dll + 2008-04-14 02:22:25 135,168 ----a-w C:\WINDOWS\system32\shsvcs.dll - 2006-02-28 12:00:00 20,992 ----a-w C:\WINDOWS\system32\shutdown.exe + 2008-04-14 02:23:01 20,480 ----a-w C:\WINDOWS\system32\shutdown.exe - 2006-02-28 12:00:00 13,312 ----a-w C:\WINDOWS\system32\sigtab.dll + 2008-04-14 02:22:25 13,312 ----a-w C:\WINDOWS\system32\sigtab.dll - 2006-02-28 12:00:00 71,168 ----a-w C:\WINDOWS\system32\sigverif.exe + 2008-04-14 02:23:01 71,168 ----a-w C:\WINDOWS\system32\sigverif.exe - 2006-02-28 12:00:00 26,112 ----a-w C:\WINDOWS\system32\skeys.exe + 2008-04-14 02:23:01 26,112 ----a-w C:\WINDOWS\system32\skeys.exe - 2006-02-28 12:00:00 25,600 ----a-w C:\WINDOWS\system32\slayerxp.dll + 2008-04-14 02:22:25 25,600 ----a-w C:\WINDOWS\system32\slayerxp.dll - 2006-02-28 12:00:00 98,304 ----a-w C:\WINDOWS\system32\slbiop.dll |
![]() | #8 |
![]() ![]() | ![]() Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen".... Huhu, das Prog ist schon runtern! was heißt i.O?. LG |
![]() |
Themen zu Mehrere Trojaner gefunden "trojan-spy.win32.greenscreen".... |
ad-aware, antivir, antivirus, avira, computer, excel, firefox, google, google update, hijack, hijack this, hijackthis, hkus\s-1-5-18, internet, internet explorer, logfile, mehrere, mozilla, object, problem, rojaner gefunden, rundll, security, software, solution, spyware, system, trojaner, trojaner gefunden, urlsearchhook, windows, windows xp |