Tachauch
Auch ich hatte das zweifelhafte Vergnügen mit diesem Virus. Hier mal mein Bericht.
-------------------------------------
Scanning Report
Thursday, May 03, 2007 19:05:20 - 20:28:59
Computer name: WINDOWSPC
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\
--------------------------------------------------------------------------------
Result: 64 malware found
Virus.Win32.Sality.k (virus)
C:\WINDOWS\SYSTEM32\WMIMGR32.DLL (Submitted)
Virus.Win32.Sality.l (virus)
C:\DRIVERS\G\NIVIDA_DETONATOR\NVUDISP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\NIVIDA_DETONATOR\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\MATROX\2\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\MATROX\1\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\ATICIMUN.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\CHECKVER.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\ISSETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\WDM\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\DRIVER\SETUP.EXE (Disinfected & Submitted)
C:\DRIVERS\G\ATI_CATALYST\CPANEL\SETUP.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000395.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000396.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000403.EXE (Disinfected)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000404.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000405.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000407.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000410.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000411.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000425.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000426.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000427.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000428.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000430.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000431.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000432.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000434.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000435.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000436.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000437.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000438.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000439.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000440.EXE (Disinfected)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000441.EXE (Disinfected)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000442.EXE (Disinfected & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{A77F6C39-79E0-47CA-BA8E-8C682C0E49CD}\RP10\A0000443.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\CLOKSPL.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\DPLAY61A.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\EMPIRES2.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\UNINSTAL.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\UNINSTALX.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\DATA\CLOSEDPW.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\AGE2_X1\AGE2_X1.EXE (Disinfected & Submitted)
D:\PROGRAMME\MICROSOFT GAMES\AGE OF EMPIRES II\AGE2_X1\CLOKSPL.EXE (Disinfected & Submitted)
D:\PROGRAMME\KICKER MANAGER 2004\KM2004 EDITOR.EXE (Disinfected & Submitted)
D:\PROGRAMME\KICKER MANAGER 2004\KM2004.EXE (Disinfected & Submitted)
D:\PROGRAMME\DIABLO II\BNUPDATE.EXE (Disinfected & Submitted)
D:\PROGRAMME\DIABLO II\D2VIDTST.EXE (Disinfected & Submitted)
D:\PROGRAMME\DIABLO II\DIABLO II.EXE (Disinfected & Submitted)
D:\PROGRAMME\COOLEDIT\COOLPRO.EXE (Disinfected & Submitted)
D:\PROGRAMME\COOLEDIT\COOLTIPS.EXE (Disinfected & Submitted)
D:\PROGRAMME\COOLEDIT\AMOVIE\AMOVIE.EXE (Disinfected & Submitted)
D:\DOWNLOADS\TREIBER\USB STICK\V2.35R004 - RITEK\SETUP.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\HIJACKTHIS\HJT\HIJACKTHIS.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\HIJACKTHIS\HIJACKTHIS\HIJACKTHIS.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\DLL UNINSTALLER\REMOVE.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ANTIVIR\AVWINSFX.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ADAWARE\AAWSEPERSONAL.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ADAWARE\PLUGINS\ARIESREMOVERINST.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ADAWARE\PLUGINS\LOOK2ME_REMOVER.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ADAWARE\PLUGINS\VIRTUMONDE_REMOVER.EXE (Disinfected & Submitted)
D:\DOWNLOADS\ANTIVIRENPROGRAMME\ADAWARE\PLUGINS\WIN32_PIPELINE_REMOVER.EXE (Disinfected & Submitted)
Win32.Mydoom.A (spyware)
System (Disinfected)
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 14494
System: 3036
Not scanned: 4
Actions:
Disinfected: 63
Renamed: 0
Deleted: 0
None: 1
Submitted: 60
Files not scanned:
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
D:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure AVP: 7.0.171, 2007-05-03
F-Secure Blacklight: 1.0.53, 0000-00-00
F-Secure Draco: 1.0.35, 0260-23-12
F-Secure Libra: 2.4.2, 2007-05-03
F-Secure Orion: 1.2.37, 2007-05-03
F-Secure Pegasus: 1.19.0, 2007-04-02
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2006 Product support |Send virus sample to F-Secure