Warum wird hier soviel Panik gemacht. Das sind doch keine Viren. Kann mich mal jemand aufklären? Was können die anrichten? Wie sind die rein gekommen?
Diese Datei „C:\Programme\Microsoft InfoChecker\ff.exe“ ist OK. Ist ein ENCARTA Projekt.
Code:
File: mssupdate.exe Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
Packers detected:
PE_PATCH.MORPHINE, MORPHINE, PE_PATCH, MEWBUNDLE, MEW
AntiVir
No viruses found (0.18 seconds taken)
Avast
No viruses found (1.51 seconds taken)
BitDefender
No viruses found (0.92 seconds taken)
ClamAV
Trojan.Mybot-581 (0.41 seconds taken)
Dr.Web
Win32.HLLW.MyBot (0.53 seconds taken)
F-Prot Antivirus
No viruses found (0.23 seconds taken)
Kaspersky Anti-Virus
Backdoor.Win32.Rbot.gen (1.45 seconds taken)
mks_vir
Trojan.Rbot.Gen (0.20 seconds taken)
NOD32
probably unknown NewHeur_PE (probable variant) (1.44 seconds taken)
Norman Virus Control
No viruses found (5.01 seconds taken)
Code:
File: winU32L.exe Status:
INFECTED/MALWARE
Packers detected:
FSG
AntiVir
No viruses found (0.64 seconds taken)
Avast
Win32:SpyBot-A1175 (3.01 seconds taken)
BitDefender
No viruses found (0.80 seconds taken)
ClamAV
Trojan.Mybot.gen-171 (0.40 seconds taken)
Dr.Web
Win32.HLLW.MyBot.based (0.68 seconds taken)
F-Prot Antivirus
W32/Spybot.CUE (0.06 seconds taken)
Kaspersky Anti-Virus
Backdoor.Win32.Rbot.gen (1.59 seconds taken)
mks_vir
Win32 (probable variant) (0.78 seconds taken)
NOD32
Win32/Rbot.BLE (1.35 seconds taken)
Norman Virus Control
Sandbox: W32/Backdoor; [ General information ]
* File might be compressed.
* **Locates window "NULL [class mIRC]" on desktop.
* File length: 109568 bytes.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\SYSTEM\winU32L.exe.
* Deletes file 1.
[ Changes to registry ]
* Creates value "Win Update 32"="winU32L.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
* Creates value "Win Update 32"="winU32L.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices".
* Creates key "HKCU\Software\Microsoft\OLE".
* Sets value "Win Update 32"="winU32L.exe" in key "HKCU\Software\Microsoft\OLE".
[ Network services ]
* Looks for an Internet connection.
* Connects to "g0tg4m3.game2max.net" on port 6667 (TCP).
* Connects to IRC server.
* IRC: Uses nickname NOR, 80340.
* IRC: Uses username ezkieya.
* IRC: Joins channel #fcuk with password fcukd.
* IRC: Sets the usermode for user NOR, 80340 to +x.
[ Process/window information ]
* Creates a mutex fcuk.
* Will automatically restart after boot (I'll be back...). (11.22 seconds taken)
Code:
File: nvsc32.exe Status:
INFECTED/MALWARE
Packers detected:
PE_PATCH, MEWBUNDLE, MEW
AntiVir
No viruses found (0.15 seconds taken)
Avast
No viruses found (1.51 seconds taken)
BitDefender
No viruses found (0.94 seconds taken)
ClamAV
Trojan.Wootbot-137 (0.41 seconds taken)
Dr.Web
Win32.HLLW.ForBot (0.54 seconds taken)
F-Prot Antivirus
No viruses found (0.14 seconds taken)
Kaspersky Anti-Virus
Backdoor.Win32.Wootbot.am (0.71 seconds taken)
mks_vir
No viruses found (0.22 seconds taken)
NOD32
Win32/Wootbot.NEX (1.44 seconds taken)
Norman Virus Control
No viruses found (5.49 seconds taken)