ibm00001
|
ibm00001.exe, ibm00007, ibm00001.dll, ibm00008, ibm00002, ibm00013- zur Startseite- Sicherheitsforum: http://board.protecus.de
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKLM\..\Run: [msresearch] C:\windows\msresearch.exe O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sysvcs.exe O4 - HKCU\..\Run: [klop] C:\WINDOWS\16.tmp O20 - Winlogon Notify: OfficeUpdate - C:\WINDOWS\system32\l6p20g7oe6.dll - l2mfix anwenden Troj/Torpig-BC:\WINDOWS\system32\service\dll.dllC:\WINDOWS\system32\service\dllp.txt C:\WINDOWS\system32\service\explorer.exe HKCU\Software\Microsoft\Windows\CurrentVersion\pwd HKCU\Software\Microsoft\Windows\CurrentVersion\gnum HKCU\Software\Microsoft\Windows\CurrentVersion\myID2 HKCU\Software\Microsoft\Windows\CurrentVersion\Run explorer "System\service\explorer.exe" Troj/Torpig-Dibm00000.exe ibm00001.dll ibm00001.exe ibm00002.dll tmp.tmp Common Files\Microsoft Shared\Web Folders\ibm00001.dll (detected as Troj/Torpig-J) Common Files\Microsoft Shared\Web Folders\ibm00001.exe (detected as Troj/Torpig-J) Common Files\Microsoft Shared\Web Folders\ibm00002.dll (detected as Troj/Torpig-J) Common Files\Microsoft Shared\Web Folders\tmp.tmp C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll -> Trojan.Sinowal.a : Cleaned with backup C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe -> Logger.Small.dg : Cleaned with backup C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Logger.Small.dg : Cleaned with backup anderer PC R3 - Default URLSearchHook is missing O4 - HKCU\..\Run: [Shell] "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.exe" Verzeichnis von C:\WINDOWS\system32 24.12.2005 17:11 36.864 intercept.dll 24.12.2005 15:22 6.652 scmt16.exe Verzeichnis von C:\WINDOWS 24.12.2005 17:11 36.864 intercept.dll 24.12.2005 15:23 3.087 secure32.html 24.12.2005 15:22 61.726 kl.exe 24.12.2005 15:22 0 uniq C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00000.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00002.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00002.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\tmp.tmp C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00003.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00004.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00003.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00004.exe C:\WINDOWS\system32\service\dll.dll C:\WINDOWS\system32\service\dllp.txt C:\WINDOWS\system32\service\explorer.exe C:\WINDOWS\system32\nvapps.xml C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00000.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00002.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\tmp.tmp C:\WINDOWS\system32\intercept.dll C:\WINDOWS\system32\scmt16.exe C:\WINDOWS\intercept.dll C:\WINDOWS\secure32.html C:\WINDOWS\kl.exe C:\WINDOWS\uniq anderer PC F2 - REG:system.ini: Shell=explorer.exe "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00003.exe" O4 - HKCU\..\Run: [Shell] "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00003.exe" * Trojan-Dropper.Win32.Small.aek * Trojan-PSW.Win32.Small.ak * Trojan-PSW.Win32.Agent.bu ibm00000.exe ibm00001.dll ibm00001.exe ibm00002.dll tmp.tmp Common Files>\Microsoft Shared\Web Folders\ibm00001.dll (detected as Troj/Torpig-J) Common Files>\Microsoft Shared\Web Folders\ibm00001.exe (detected as Troj/Torpig-J) Common Files>\Microsoft Shared\Web Folders\ibm00002.dll (detected as Troj/Torpig-J) The following registry entry is created to run ibm00001.exe on startup: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Shell path to ibm00001.exe * The following registry entry is changed to run ibm00001.exe on startup: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell explorer.exe "path to ibm00001.exe"
ibm00001.dll ibm00001.exe ibm00002.dll [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Old value: "Shell"="Explorer.exe" New value: "Shell"="explorer.exe%empty spaces%\"%PROGRAM FILES%\Common Files\\Microsoft Shared\\Web Folders\\ibm00001.exe\"" ibm00001.exe und die ibm0000(1)/(2).dllPROGRAM FILES%\Common Files\Microsoft Shared\Web Folders\ibm00001.dllPROGRAM FILES%\Common Files\Microsoft Shared\Web Folders\ibm00002.dll PROGRAM FILES%\Common Files\Microsoft Shared\Web Folders\ibm00001.exe anderer PC
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00010.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00013.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00014.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00015.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00015.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00016.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00017.exe F2 - REG:system.ini: Shell=explorer.exe "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00015.exe" anderer PC F2 - REG:system.ini: Shell=explorer.exe "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00007.exe" O4 - HKCU\..\Run: [shell] "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00007.exe"
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00006.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00007.dll C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00007.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00008.dll |