- #21
A
andemande
Guest
man liest, und liest und überliest....
eine HPFS Partition würde alles erklären
eine HPFS Partition würde alles erklären
Follow along with the video below to see how to install our site as a web app on your home screen.
Anmerkung: This feature currently requires accessing the site using the built-in Safari browser.
DRV - [2006/09/28 12:55:50 | 000,077,568 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\system32\drivers\WudfPf.sys.XXX -- (WudfPf)
:OTL
DRV - [2010/05/19 02:40:04 | 000,000,000 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\system32\drivers\ojupk.sys -- (ojupk)
IE - HKU\Hannes_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultenginename: Yahoo! Search
FF - prefs.js..browser.search.defaultthis.engineName: Softonic Deutsch Customized Web Search
FF - prefs.js..browser.search.defaulturl: http://search.conduit.com/ResultsExt.aspx?ctid=CT1351351&SearchSource=3&q={searchTerms}
FF - prefs.js..browser.search.selectedEngine: Yahoo! Search
FF - prefs.js..keyword.URL: [url]http://de.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_de&p=[/url]
O2 - BHO: (C:\WINDOWS\system32\p7gic.dll) - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\System32\p7gic.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKU\Hannes_ON_C..\Run: [{814D6C00-7A2C-4C33-DD30-951CCDBCD568}] C:\Dokumente und Einstellungen\Hannes\Anwendungsdaten\Akweap\tiop.exe File not found
O4 - HKU\Hannes_ON_C..\Run: [hsf87efjhdsf87f3jfsdi7fhsujfd] C:\DOKUME~1\Hannes\LOKALE~1\Temp\user.exe File not found
O4 - HKU\Hannes_ON_C..\Run: [hsf87sdhfush87fsufhuie3fddf] C:\DOKUME~1\Hannes\LOKALE~1\Temp\i2w6s.exe File not found
O4 - HKU\Hannes_ON_C..\Run: [mcexecwin] C:\DOKUME~1\Hannes\LOKALE~1\Temp\wlxzi.DLL File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [url]http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[/url] (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} [url]http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[/url] (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [url]http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[/url] (Java Plug-in 1.5.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [url]http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[/url] (Shockwave Flash Object)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\System32\sdra64.exe File not found
O22 - SharedTaskScheduler: {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - kjsfi8sjefiuoshiefyhiusdhfdf - C:\WINDOWS\System32\p7gic.dll File not found
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[2010/05/05 02:24:04 | 000,000,008 | ---- | M] () -- C:\WINDOWS\sdfinacs.dll
[2010/05/05 02:24:01 | 000,000,168 | ---- | M] () -- C:\WINDOWS\wuasirvy.dll
[2010/05/03 02:12:17 | 000,000,005 | ---- | M] () -- C:\WINDOWS\sdfixwcs.dll
:Commands
[emptytemp]
[resethosts]
File WudfPf.sys.XXX.zip received on 2010.06.04 17:34:43 (UTC)
Antivirus Version Last Update Result
a-squared 5.0.0.26 2010.06.04 Rootkit.Win32.TDSS!IK
AhnLab-V3 2010.06.04.02 2010.06.04 -
AntiVir 8.2.2.6 2010.06.04 TR/Patched.Gen
Antiy-AVL 2.0.3.7 2010.06.04 -
Authentium 5.2.0.5 2010.06.04 W32/SYStroj.AB.gen!Eldorado
Avast 4.8.1351.0 2010.06.04 Win32:Alureon-FZ
Avast5 5.0.332.0 2010.06.04 Win32:Alureon-FZ
AVG 9.0.0.787 2010.06.04 Win32/Patched.DP
BitDefender 7.2 2010.06.04 Rootkit.Patched.TDSS.Gen
CAT-QuickHeal 10.00 2010.06.04 -
ClamAV 0.96.0.3-git 2010.06.04 -
Comodo 4985 2010.06.04 TrojWare.Win32.Rootkit.TDL3.gen
DrWeb 5.0.2.03300 2010.06.04 BackDoor.Tdss.2459
eSafe 7.0.17.0 2010.06.03 -
eTrust-Vet 35.2.7528 2010.06.04 Win32/Alureon.A!generic
F-Prot 4.6.0.103 2010.06.03 W32/SYStroj.AB.gen!Eldorado
F-Secure 9.0.15370.0 2010.06.04 Rootkit.Patched.TDSS.Gen
Fortinet 4.1.133.0 2010.06.04 -
GData 21 2010.06.04 Rootkit.Patched.TDSS.Gen
Ikarus T3.1.1.84.0 2010.06.04 Rootkit.Win32.TDSS
Jiangmin 13.0.900 2010.06.04 Rootkit.TDSS.dgu
Kaspersky 7.0.0.125 2010.06.04 Rootkit.Win32.TDSS.ap
McAfee 5.400.0.1158 2010.06.04 Patched-SYSFile.d
McAfee-GW-Edition 2010.1 2010.06.04 -
Microsoft 1.5802 2010.06.04 Virus:Win32/Alureon.H
NOD32 5173 2010.06.04 Win32/Olmarik.ZC
Norman 6.04.12 2010.06.04 W32/tdss.drv.gen8
nProtect 2010-06-04.01 2010.06.04 -
Panda 10.0.2.7 2010.06.04 -
PCTools 7.0.3.5 2010.06.04 Backdoor.Tidserv
Rising 22.50.04.04 2010.06.04 RootKit.Win32.TDSS.c
Sophos 4.53.0 2010.06.04 Mal/TDSSRt-A
Sunbelt 6405 2010.06.04 LooksLike.Win32.PatchedDriver!A (v)
Symantec 20101.1.0.89 2010.06.04 Backdoor.Tidserv!inf
TheHacker 6.5.2.0.292 2010.06.04 -
TrendMicro 9.120.0.1004 2010.06.04 Mal_TIDIES-12
TrendMicro-HouseCall 9.120.0.1004 2010.06.04 Mal_TIDIES-12
VBA32 3.12.12.5 2010.06.04 Rootkit.Win32.TDSL.b
ViRobot 2010.6.4.2337 2010.06.04 -
VirusBuster 5.0.27.0 2010.06.04 Rootkit.TDSS.Gen.3
Additional information
File size: 33939 bytes
MD5...: 68bc9209adeb1a885b8d254ba465ec90
SHA1..: eeb0dd07377ca1b54026118abd34870a48f2bbe2
SHA256: 12df0b74589c377651d2f0a0d87d2ecc182128dad53f88aabc3fcece8622628b
ssdeep: 768:2ONBnx6sCYeExEKI1/wO4x8rzxUONZBJjmBsICVRYoqANueL6:XNVx7Vvx83<br>xhN4SbYo7Nuj<br>
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
trid..: ZIP compressed archive (99.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:<br>publisher....: n/a<br>copyright....: n/a<br>product......: n/a<br>description..: n/a<br>original name: n/a<br>internal name: n/a<br>file version.: n/a<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
HKU\Hannes_ON_C..\Run: [{814D6C00-7A2C-4C33-DD30-951CCDBCD568}] C:\Dokumente und Einstellungen\Hannes\Anwendungsdaten\Akweap\tiop.exe
O4 - HKU\Hannes_ON_C..\Run: [{814D6C00-7A2C-4C33-DD30-951CCDBCD568}] C:\Dokumente und Einstellungen\Hannes\Anwendungsdaten\Akweap\tiop.exe
HKU\Hannes_ON_C..\Run: [hsf87efjhdsf87f3jfsdi7fhsujfd] C:\DOKUME~1\Hannes\LOKALE~1\Temp\user.exe
O4 - HKU\Hannes_ON_C..\Run: [hsf87efjhdsf87f3jfsdi7fhsujfd] C:\DOKUME~1\Hannes\LOKALE~1\Temp\user.exe
HKU\Hannes_ON_C..\Run: [hsf87sdhfush87fsufhuie3fddf] C:\DOKUME~1\Hannes\LOKALE~1\Temp\i2w6s.exe
O4 - HKU\Hannes_ON_C..\Run: [hsf87sdhfush87fsufhuie3fddf] C:\DOKUME~1\Hannes\LOKALE~1\Temp\i2w6s.exe
HKU\Hannes_ON_C..\Run: [mcexecwin] C:\DOKUME~1\Hannes\LOKALE~1\Temp\wlxzi.DLL
O4 - HKU\Hannes_ON_C..\Run: [mcexecwin] C:\DOKUME~1\Hannes\LOKALE~1\Temp\wlxzi.DLL
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\System32\sdra64.exe
O22 - SharedTaskScheduler: {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - kjsfi8sjefiuoshiefyhiusdhfdf - C:\WINDOWS\System32\p7gic.dll
O2 - BHO: (C:\WINDOWS\system32\p7gic.dll) - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\System32\p7gic.dll