![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: system32/vinomisu.dll/dapotado.dll/kuvimulo.dllWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #16 |
![]() ![]() | system32/vinomisu.dll/dapotado.dll/kuvimulo.dll Ok,Combofix ist durch,hier das Ergebnis! Also sind die 90 Euro im Jahr für Usenext fürn Mülleimer? Wie kann ein Anbieter,der so viel Geld nimmt,so unseriös sein? ![]() ![]() ![]() ![]() Combofix-Log: ComboFix 09-05-22.05 - Master 23.05.2009 0:23.1 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.49.1031.18.255.133 [GMT 2:00] ausgeführt von:: c:\dokumente und einstellungen\Master\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\abimurog.ini c:\windows\system32\ekuzuloy.ini c:\windows\system32\hufowebi.dll c:\windows\system32\oguwator.ini c:\windows\system32\sysinfo.exe c:\windows\system32\takihiru.dll c:\windows\system32\urihikat.ini c:\windows\system32\usimoniv.ini . ((((((((((((((((((((((( Dateien erstellt von 2009-04-22 bis 2009-05-22 )))))))))))))))))))))))))))))) . 2009-05-22 22:27 . 2009-05-22 22:27 -------- d-----w c:\windows\system32\xircom 2009-05-22 22:27 . 2009-05-22 22:27 -------- d-----w c:\programme\microsoft frontpage 2009-05-22 20:59 . 2009-05-22 20:59 -------- d-----w c:\dokumente und einstellungen\Master\Anwendungsdaten\Malwarebytes 2009-05-22 20:58 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-22 20:58 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-22 20:58 . 2009-05-22 20:58 -------- d-----w c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-05-22 18:43 . 2009-03-30 08:33 96104 ----a-w c:\windows\system32\drivers\avipbb.sys 2009-05-22 18:43 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys 2009-05-22 18:43 . 2009-02-13 10:29 22360 ----a-w c:\windows\system32\drivers\avgntmgr.sys 2009-05-22 18:43 . 2009-02-13 10:17 45416 ----a-w c:\windows\system32\drivers\avgntdd.sys 2009-05-22 18:43 . 2009-05-22 18:43 -------- d-----w c:\dokumente und einstellungen\All Users\Anwendungsdaten\Avira 2009-05-17 10:28 . 2001-08-17 12:02 8576 ----a-w c:\windows\system32\drivers\hidgame.sys 2009-04-22 22:48 . 2009-04-22 22:48 -------- d-----w c:\dokumente und einstellungen\Master\.surfbar 2009-04-22 22:47 . 2009-04-22 22:47 -------- d-----w c:\windows\Sun 2009-04-22 22:44 . 2009-04-22 22:44 410984 ----a-w c:\windows\system32\deploytk.dll 2009-04-22 22:43 . 2009-04-22 22:43 -------- d-----w c:\programme\Java 2009-04-22 22:39 . 2009-04-22 22:39 152576 ----a-w c:\dokumente und einstellungen\Master\Anwendungsdaten\Sun\Java\jre1.6.0_13\lzma.dll . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-21 21:38 . 2008-10-01 03:18 1632 ----a-w c:\windows\system32\d3d8caps.dat 2009-05-20 11:59 . 2008-10-01 01:15 1744 ----a-w c:\windows\system32\d3d9caps.dat 2009-04-09 15:03 . 2009-04-09 14:49 120 ----a-w C:\drmHeader.bin 2009-03-15 04:01 . 2008-01-08 16:37 360832 ----a-w c:\windows\system32\drivers\TCPIP.SYS 2009-03-13 22:02 . 2008-10-01 01:13 17112 ----a-w c:\dokumente und einstellungen\Master\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 2009-03-13 21:48 . 2009-03-13 21:48 827368 ----a-w c:\dokumente und einstellungen\Master\Anwendungsdaten\MSNInstaller\msnauins.exe . ------- Sigcheck ------- [-] 2007-10-09 11:20 1548288 6D60483EBCF29203C9B3B453471D3706 c:\windows\system32\sfcfiles.dll . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GLDStart"="c:\programme\GLDirect\gldirect.exe" [2004-07-20 241664] "avgnt"="d:\programme\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "RoboForm"="c:\programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-01-06 160592] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2007-12-11 124928] c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\ Microsoft Office.lnk - d:\programme\Word2000\Office\OSA9.EXE [2000-1-21 65588] Dienst-Manager.lnk - c:\programme\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\hufowebi.dll,c:\windows\system32\vihokaso.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\79e4bfb050e66daf] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "d:\\Programme\\ICQ6.5\\ICQ.exe"= "d:\\Spiele\\MOHAA\\MOHAA.exe"= "c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programme\\Messenger\\msmsgs.exe"= "d:\\Programme\\M-Firefox\\firefox.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6346:TCP"= 6346:TCP:192.168.220.100/255.255.255.255:Enabled:Sharezza "6346:UDP"= 6346:UDP:192.168.220.100/255.255.255.255:Enabled:Sharezza R0 pmfilt;pmfilt;c:\windows\system32\drivers\pmfilt.sys [15.01.2009 01:13 10112] R0 pmhelp;pmhelp;c:\windows\system32\drivers\pmhelp.sys [15.01.2009 01:13 50464] R2 AntiVirSchedulerService;Avira AntiVir Planer;d:\programme\Avira\AntiVir Desktop\sched.exe [22.05.2009 20:43 108289] S2 79e4bfb050e66daf;Microsoft DDE+ server;c:\windows\system32\.79e4bfb050e66daf\79e4bfb050e66daf.exe --> c:\windows\system32\.79e4bfb050e66daf\79e4bfb050e66daf.exe [?] . - - - - Entfernte verwaiste Registrierungseinträge - - - - HKLM-Run-CPM6fd8b5b4 - c:\windows\system32\hufowebi.dll HKLM-Run-6ceb8628 - c:\windows\system32\takihiru.dll HKLM-Run-sopitafepi - c:\windows\system32\kuvimulo.dll SafeBoot-procexp90.Sys . ------- Zusätzlicher Suchlauf ------- . IE: RF - Formular ausfüllen - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RF - Formular speichern - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html IE: RF - Menü anpassen - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: RF - RoboForm-Leiste ein/aus - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html FF - ProfilePath - c:\dokumente und einstellungen\Master\Anwendungsdaten\Mozilla\Firefox\Profiles\jso3djcv.default\ FF - plugin: d:\programme\DivX\DivX Content Uploader\npUpload.dll FF - plugin: d:\programme\DivX\DivX Player\npDivxPlayerPlugin.dll FF - plugin: d:\programme\DivX\DivX Web Player\npdivx32.dll FF - plugin: d:\programme\M-Firefox\plugins\np-mswmp.dll FF - plugin: d:\programme\opera\program\plugins\npdsplay.dll FF - plugin: d:\programme\opera\program\plugins\npwmsdrm.dll FF - plugin: d:\programme\Reader 8.0\Reader\browser\nppdf32.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-23 00:29 Windows 5.1.2600 Service Pack 2 FAT NTAPI Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . ------------------------ Weitere laufende Prozesse ------------------------ . d:\programme\Avira\AntiVir Desktop\avguard.exe c:\programme\JAVA\JRE6\BIN\JQS.EXE c:\windows\system32\wbem\wmiapsrv.exe . ************************************************************************** . Zeit der Fertigstellung: 2009-05-22 0:32 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2009-05-22 22:31 Vor Suchlauf: 1.264.414.720 Bytes frei Nach Suchlauf: 1.444.622.336 Bytes frei WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect multi(0)disk(0)rdisk(0)partition(1)\WINXP="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 140 |
| Themen zu system32/vinomisu.dll/dapotado.dll/kuvimulo.dll |
| autostart, einfach, festplatte, folge, infiziert, kleines, lahm, lahmt, neuste, nicht mehr, nichts, pc lahm, pc lahmt, platte, popups, problem, prozesse, rechner, regcleaner, scan, system, taskmanager, virus, vundo, öffnen |