Erst schonmal ein riesengroßes Dankeschön =) :daumenhoc Es funktioniert alles schon wieder viel besser, auch komme ich jetzt wieder ins Internet und muss nicht mehr alles über den andern PC jonglieren...
Virustotal.com:
xtick.exe Code:
Datei XTICK.exe empfangen 2009.01.17 00:02:04 (CET)
Status: Beendet
Ergebnis: 0/37 (0.00%)
weitere Informationen
File size: 311396 bytes
MD5...: 9c73142f9ef41b2f01590026b9eeb6a2
SHA1..: 5a7a6b807e948f668207ad176bb4e737966d200e
SHA256: 47ef2f2c179d495ccd3263cf36c1683f72dc383414609a802af4506dbe53448e SHA512: 65c42ebc91690f631c4a70997564659e847d27350fbc9b82e95a129321d49070
ae753eb343774c3eae38b1b6b4470dfc5672906848e208d2d8b8e6e344d56e50
ssdeep: 6144:Tow44INTqL9tn5ETrWOfjGuvA5T111J55Pxu3316Hx9f:Tow44INTqvnYr0
uvMuV6R1
PEiD..: Armadillo v1.71
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x41a2f4
timedatestamp.....: 0x40c7cd7f (Thu Jun 10 02:54:55 2004)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1b95e 0x1c000 6.29 8579ac2f399bb8b68e6de31052d80e72
.rdata 0x1d000 0x5b52 0x6000 4.64 bc2aa39c76c8c97aad4ef33c9b568129
.data 0x23000 0x2f48 0x3000 4.80 c3de6f9a1d25a70a14a0e8db54f78bc3
.rsrc 0x26000 0x254b8 0x26000 6.52 d8414dc98292d85ae81bf9496a980faa
( 14 imports )
> CFGMGR32.dll: CM_Get_DevNode_Status
> SETUPAPI.dll: SetupDiGetDeviceInterfaceDetailA, SetupDiEnumDeviceInterfaces, SetupDiEnumDeviceInfo, SetupDiGetClassDevsA, SetupDiDestroyDeviceInfoList, SetupDiSetClassInstallParamsA, SetupDiGetDeviceRegistryPropertyA, SetupDiSetDeviceRegistryPropertyA, SetupDiCallClassInstaller
> WINMM.dll: sndPlaySoundA
> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, _onexit, __dllonexit, strcat, _setmbcp, strcmp, __CxxFrameHandler, _EH_prolog, _mbscmp, _controlfp, memcpy, free, malloc, memset, strcpy, memcmp, rand, srand, time, calloc, strlen, _strupr, strtok, printf, _ftol, atof, memmove, _mbsnbcmp, sprintf, _beginthread, strncpy, _endthread
> KERNEL32.dll: CreateToolhelp32Snapshot, GetModuleFileNameA, GetCurrentDirectoryA, Process32Next, LocalFree, GetVersion, FormatMessageA, GlobalLock, GlobalUnlock, GlobalAlloc, LoadResource, LockResource, FindResourceA, MulDiv, GetFileSize, SizeofResource, GetFileAttributesA, GetSystemTime, ReadFile, Sleep, CreateFileA, CloseHandle, DeviceIoControl, GetVersionExA, GetLastError, lstrcpynA, SleepEx, CreateThread, GetVolumeInformationA, GetTempPathA, GetLogicalDrives, TerminateProcess, CreateProcessA, GetDriveTypeA, WriteFile, OpenFile, GetStartupInfoA, DeleteFileA, GetModuleHandleA, GetWindowsDirectoryA, WaitForSingleObject, Process32First
> USER32.dll: KillTimer, GetSystemMetrics, DrawIcon, GetSystemMenu, AppendMenuA, GetDC, MessageBoxA, LoadBitmapA, MessageBoxExA, EqualRect, LoadIconA, MessageBeep, ClientToScreen, FillRect, OffsetRect, RedrawWindow, InvalidateRect, UpdateWindow, GetSysColor, IsIconic, GetDesktopWindow, GetWindowRect, SetTimer, GetParent, PostMessageA, SendMessageA, EnableWindow, GetNextDlgGroupItem, SetWindowRgn, WindowFromPoint, DrawEdge, SetCapture, GetWindowLongA, IsWindow, GetCursorPos, SetForegroundWindow, GetSubMenu, ReleaseCapture, GetCapture, SetCursor, GetClientRect, LoadMenuA, EnumWindows, DrawFocusRect
> GDI32.dll: BitBlt, CreateSolidBrush, DeleteObject, GetStockObject, CreateFontA, CreateFontIndirectA, GetViewportOrgEx, GetObjectA, CreateCompatibleBitmap, CreateCompatibleDC, Rectangle, DeleteDC, SelectObject, CreateBitmap, SetTextColor, SetBkColor, GetDeviceCaps, GetTextExtentPoint32A, StretchBlt, SelectClipRgn, CombineRgn, CreateRectRgn, GetPixel, SetViewportOrgEx
> ADVAPI32.dll: DeleteService, RegQueryValueExA, CreateServiceA, CloseServiceHandle, RegOpenKeyExA, OpenServiceA, RegCreateKeyExA, RegSetValueExA, RegCloseKey, OpenSCManagerA
> SHELL32.dll: ShellExecuteA, Shell_NotifyIconA
> COMCTL32.dll: _TrackMouseEvent
> ole32.dll: CreateStreamOnHGlobal, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal
> OLEPRO32.DLL: -
> SHLWAPI.dll: PathFindFileNameA
( 0 exports ) kdxgthkaab.exe Code:
Datei kdxgthkaab.exe empfangen 2009.01.17 00:09:29 (CET)
Status: Beendet
Ergebnis: 0/39 (0.00%)
weitere Informationen
File size: 405504 bytes
MD5...: a722119e50752bab5bda996994449c6a
SHA1..: ca1e1c5606333d49a40850948be6409eea0ba306
SHA256: ab24d4f68fb80e778e362d92a185d5eee0c6783893a8920768357a1caab7a19f SHA512: 1ff9a39dadd82b62a913398efd1d410b86b25feba9be17fd83cfc7d8e2e3ff86
234b8cb5ce71f63c30aa01eb9ab52f773636fd556cc6239b8096bae51e44e664
ssdeep: 6144:xz8O6haek5aqd6XjVMVuZYXKGNxVVJKcQy5XU818tfOvqNZT6:Z16haeCaq
MXjOcZY9PJKiOSmtT6
PEiD..: InstallShield 2000
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%) PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x40bab0
timedatestamp.....: 0x42c2ccbc (Wed Jun 29 16:30:52 2005)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x43b7e 0x44000 6.16 7b5608073bf78d9d0ba8c4faf5b99da7
.rdata 0x45000 0x81d4 0x9000 5.08 014fcb5456ef835b880305bc7d243eda
.data 0x4e000 0x13098 0x11000 5.46 ee31de3c10ac6ecd6168a4cee7bac3b4
.reloc 0x62000 0x3408 0x4000 5.74 8bfe625933eb0300e2850a9a44fa6b36
( 3 imports )
> KERNEL32.dll: WriteFile, DeleteFileA, GetLastError, Sleep, GetProcAddress, GetStartupInfoA, GetCommandLineA, GetVersionExA, RtlUnwind, IsBadWritePtr, IsBadReadPtr, HeapValidate, RaiseException, TerminateProcess, GetCurrentProcess, ExitProcess, UnhandledExceptionFilter, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, DeleteCriticalSection, TlsAlloc, GetCurrentThreadId, TlsFree, TlsSetValue, TlsGetValue, SetLastError, GetCurrentThread, HeapDestroy, HeapCreate, HeapFree, VirtualFree, LCMapStringA, LCMapStringW, EnterCriticalSection, GetVolumeInformationA, DebugBreak, InterlockedDecrement, OutputDebugStringA, InterlockedIncrement, FatalAppExitA, HeapAlloc, HeapReAlloc, VirtualAlloc, SetUnhandledExceptionFilter, GetACP, GetOEMCP, GetCPInfo, InitializeCriticalSection, VirtualQuery, InterlockedExchange, GetTimeFormatA, GetDateFormatA, GetStringTypeA, GetStringTypeW, IsValidLocale, IsValidCodePage, GetLocaleInfoA, EnumSystemLocalesA, GetUserDefaultLCID, VirtualProtect, GetSystemInfo, SetConsoleCtrlHandler, SetStdHandle, FlushFileBuffers, SetFilePointer, IsBadCodePtr, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, GetTimeZoneInformation, SetEndOfFile, ReadFile, GetLocaleInfoW, CompareStringA, CompareStringW, SetEnvironmentVariableA, LoadLibraryA, GetModuleHandleA, DeviceIoControl, GetSystemDirectoryA, CreateFileA, SetFileTime, CloseHandle, FileTimeToSystemTime, SystemTimeToFileTime, GetWindowsDirectoryA, GetTempPathA, GetTickCount, FindFirstFileA, FindNextFileA, FindClose, LeaveCriticalSection, MultiByteToWideChar, FreeLibrary, WaitForSingleObject, CreateEventA
> ADVAPI32.dll: RegQueryValueExA, ControlService, QueryServiceConfigA, QueryServiceStatus, OpenSCManagerA, CreateServiceA, OpenServiceA, StartServiceA, DeleteService, CloseServiceHandle, RegEnumValueA, RegDeleteValueA, RegOpenKeyA, RegSetValueExA, RegCloseKey, RegOpenKeyExA
> USER32.dll: MessageBoxA
( 0 exports ) sfcont.dll konnte ich nichtmehr finden, es gibt in dem Ordner nur noch eine sfcont.bin-Datei.
Malwarebytes Scan Log: Code:
Malwarebytes' Anti-Malware 1.33
Datenbank Version: 1663
Windows 5.1.2600 Service Pack 3
17.01.2009 23:33:16
mbam-log-2009-01-17 (23-33-16).txt
Scan-Methode: Vollständiger Scan (C:\|D:\|E:\|)
Durchsuchte Objekte: 202750
Laufzeit: 1 hour(s), 2 minute(s), 7 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 11
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 5
Infizierte Dateien: 30
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\rxresult.rxresultfilter (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rxresult.rxresultfilter.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2ab289ae-4b90-4281-b2ae-1f4bb034b647} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d1c4e81-a32a-416b-bcdb-33b3ef3617d3} (Adware.Need2Find) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo (Adware.RXToolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo.1 (Adware.RXToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RXToolBar (Adware.RXToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RX ToolBar (Adware.RXToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Adware.BHO) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\p2p networking (Backdoor.Bot) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
C:\Programme\RXToolBar (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\HTML (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Icon (Adware.RXToolbar) -> Quarantined and deleted successfully.
Infizierte Dateien:
C:\Programme\RXToolBar\CacheCatalog.rx (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\rx.xml (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\rxtoolbar.cfg (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\rxwebsearches.xsl (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\sfcont.bin (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\yahoo.xsl (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CT (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CTwww_fanfiction_net_ (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CTwww_lycos_de (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CTwww_qklinkserver_com_activity_in_asp_bid=6900NC (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CTwww_srch-results_com_lm_imp_rxt_asp_si=19902&k=meet%20thereNC (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\CTwww_thalerwald_de_forum_NC (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\U953136 (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Cache\U953136_yahoo (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\additional.gif (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\additional_active.gif (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\background.jpg (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\blue_hr_horz.GIF (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\gray_hr_horz.GIF (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\thumbtack.gif (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\thumbtack_active.gif (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\graphics\thumbtack_click.gif (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\HTML\content.htm (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\HTML\main.htm (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\Programme\RXToolBar\Icon\blake_prohosting_com_favicon_ico.ico (Adware.RXToolbar) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Programme\ICQToolbar\toolbaru.dll (Adware.BHO) -> Quarantined and deleted successfully. |