Hier der dritte und letzte Teil:
Zitat:
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\002243c94b41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\002243c94b41@0023f189f435 0x63 0x70 0xAA 0x43 ...
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x93 0xB5 0x46 0xBE ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x42 0x68 0x80 0x81 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x1E 0xAB 0x03 0xB4 ...
---- Files - GMER 1.0.15 ----
File C:\Users\***\AppData\Local\Temp\Low\kbiwkmkiwnedvxsx.tmp 196 bytes
File C:\Windows\System32\drivers\kbiwkmiffydpby.sys 69632 bytes <-- ROOTKIT !!!
File C:\Windows\System32\drivers\kbiwkmyvovtcrb.sys 69632 bytes executable <-- ROOTKIT !!!
File C:\Windows\System32\kbiwkmdhxeflfh.dat 1024 bytes
File C:\Windows\System32\kbiwkmexqbnnhk.dll 43520 bytes executable
File C:\Windows\System32\kbiwkmfkwcbvpe.dat 91 bytes
File C:\Windows\System32\kbiwkmnyxmrlqo.dll 20992 bytes executable
File C:\Windows\System32\kbiwkmphxgbexs.dat 91 bytes
File C:\Windows\System32\kbiwkmqorimaeg.dll 20480 bytes executable
File C:\Windows\System32\kbiwkmtjuynfnt.dat 22035 bytes
File C:\Windows\System32\kbiwkmvtbktqpp.dll 43520 bytes executable
---- EOF - GMER 1.0.15 ----
|
PS: Antivir zeigt ständig Trojaner an (meistens im system)
Hoffe du kannst mir helfen! Danke schonmal!
Weil ich glaube es spinnt nicht nur der Browser sondern auch noch die Videowiedergabe manchmal.
Gruß
__________________