19.05.2011, 13:51
#11 Trojaner: PSW.Agent.AMDQ in C:\Dokumente und Einstellungen, und C:\Programme Zitat:
Zitat von
cosinus Code:
Alles auswählen Aufklappen ATTFilter
:OTL
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.01.01 16:38:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009.08.24 04:42:34 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.) - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.09.19 03:12:34 | 000,000,045 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{37792a50-e531-11df-8d5d-0013d4c23089}\Shell - "" = AutoRun
O33 - MountPoints2\{37792a50-e531-11df-8d5d-0013d4c23089}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37792a50-e531-11df-8d5d-0013d4c23089}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.24 04:42:34 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{37792a54-e531-11df-8d5d-0013d4c23089}\Shell - "" = AutoRun
O33 - MountPoints2\{37792a54-e531-11df-8d5d-0013d4c23089}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37792a54-e531-11df-8d5d-0013d4c23089}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.24 04:42:34 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{6c0e7110-1b34-11e0-8d9d-0013d4c23089}\Shell - "" = AutoRun
O33 - MountPoints2\{6c0e7110-1b34-11e0-8d9d-0013d4c23089}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6c0e7110-1b34-11e0-8d9d-0013d4c23089}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009.08.24 04:42:34 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{86fd968e-f6e3-11de-bd62-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{86fd968e-f6e3-11de-bd62-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{86fd968e-f6e3-11de-bd62-806d6172696f}\Shell\AutoRun\command - "" = F:\setup.exe
@Alternate Data Stream - 146 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:0908F1AC
:Commands
[purity]
[resethosts]
Das Programm des Surfssticks nennt sich Mobile Partner..