habe hier noch was möglicherweise hilfreiches (nicht für mich) danke!!!
der virus heisst übrigens Trojan.Vundo (bin nicht 100% sicher ob es der richtige ist) tut mir leid
Verarbeiten:
C:\Programme\Internet Explorer\iexplore.exe
Infektion:
c:\windows\system32\awttstq.dll
Registrierung:
HKEY_CLASSES_ROOT\CLSID\{0612F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_CLASSES_ROOT\CLSID\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_CLASSES_ROOT\CLSID\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_CLASSES_ROOT\CLSID\{83A5F7B7-DC75-44CE-9195-264F41709FA9}
HKEY_CLASSES_ROOT\CLSID\{CE70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_CLASSES_ROOT\CLSID\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_CLASSES_ROOT\CLSID\{79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A}
HKEY_CLASSES_ROOT\CLSID\{DAD9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_CLASSES_ROOT\CLSID\{DE8BDE42-16D9-4CCC-9F4F-1C3167B82F60}
HKEY_CLASSES_ROOT\CLSID\{18898424-E3AB-4BA9-8E8D-5434B1CECA75}
HKEY_CLASSES_ROOT\CLSID\{BAD263C7-B253-43D9-A1F7-25A1010E24E2}
HKEY_CLASSES_ROOT\MSEvents.MSEvents
HKEY_CLASSES_ROOT\MSEvents.MSEvents.1
HKEY_CLASSES_ROOT\IEpl.IEpl
HKEY_CLASSES_ROOT\IEpl.IEPl.1
HKEY_CLASSES_ROOT\DPCUpdater.DPCUpdater
HKEY_CLASSES_ROOT\DPCUpdater.DPCUpdater.1
HKEY_CLASSES_ROOT\ATLDistrib.ATLDistrib
HKEY_CLASSES_ROOT\ATLDistrib.ATLDistrib.1
HKEY_CLASSES_ROOT\RawExecAction.RawExecAction
HKEY_CLASSES_ROOT\RawExecAction.RawExecAction.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{0612F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{CE70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{18898424-E3AB-4BA9-8E8D-5434B1CECA75}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{83A5F7B7-DC75-44CE-9195-264F41709FA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{DAD9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{DE8BDE42-16D9-4CCC-9F4F-1C3167B82F60}
HKEY_CLASSES_ROOT\CLSID\{827DC836-DD9F-A602-5812EB50A834}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{827DC836-DD9F-A602-5812EB50A834}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows
er Helper Objects\{BAD263C7-B253-43D9-A1F7-25A1010E24E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell
ExecuteHooks->{BAD263C7-B253-43D9-A1F7-25A1010E24E2}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{0612F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{0612F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06
12F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06
12F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06
12F71E-934B-4D92-B8E8-2E29EA78EB03}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23
53FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23
53FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23
53FCBC-012D-487B-8BF3-865C0929FBEB}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3F
E36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3F
E36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3F
E36807-69ED-45D1-B9BE-85C0E3F75B6A}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-A602-5812EB50A834}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-A602-5812EB50A834}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82
7DC836-DD9F-A602-5812EB50A834}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82
7DC836-DD9F-A602-5812EB50A834}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82
7DC836-DD9F-A602-5812EB50A834}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{CE70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{CE70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE
70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE
70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE
70731D-F28D-4D81-9D61-C8EE60378401}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{DAD9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{DAD9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA
D9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA
D9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA
D9C3A5-FB4E-45CD-93EB-2059F4EEF4D1}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-500\Software\Microsoft
\Windows\CurrentVersion\Ext\Stats\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_USERS\S-1-5-21-1005119527-3313978143-2467614560-1006\Software\Microsof
t\Windows\CurrentVersion\Ext\Stats\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC
148228-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC
148228-87E1-4D00-AC06-58DCAA52A4D1}