Heurestics.Broken Executable

#0
28.01.2011, 21:04
Member

Beiträge: 180
#1 Spyware Terminator hat folgende Dateien als infiziert gemeldet:

Code

<Heuristics.Broken.Executable> : C:\OEM\Preload\Autorun\APP\MyWinLocker v3\program files\EgisTec\MyWinLocker 3\Shredder.exe
<Heuristics.Broken.Executable> : C:\OEM\Preload\Autorun\APP\MyWinLocker v3\program files\EgisTec\MyWinLocker 3\Shredder.exe
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\microsoft shared\Help 9\msenv.dll
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\microsoft shared\Help 9\msenv.dll
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\22c1aeb21cb9af304\WLXSuite.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\22c1aeb21cb9af304\WLXSuite.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\884afd8c1cb9af30b\crt90.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\884afd8c1cb9af30b\crt90.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\8ee9454b1cb9af30c\d3dx10-x86.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\8ee9454b1cb9af30c\d3dx10-x86.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\951fe9301cbb35201\WLRemoteService-i386.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\951fe9301cbb35201\WLRemoteService-i386.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\a22c471f1cb9af310\Contacts.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\a22c471f1cb9af310\Contacts.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\b776923d1cb9af312\pimt.msi
<Heuristics.Broken.Executable> : C:\Program Files\Common Files\Windows Live\.cache\b776923d1cb9af312\pimt.msi
<Heuristics.Broken.Executable> : C:\Program Files\EgisTec\MyWinLocker 3\Shredder.exe
<Heuristics.Broken.Executable> : C:\Program Files\EgisTec\MyWinLocker 3\Shredder.exe
<Heuristics.Broken.Executable> : C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\wpt_x64.msi
<Heuristics.Broken.Executable> : C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\wpt_x64.msi
<Heuristics.Broken.Executable> : C:\Program Files\Samsung\Samsung New PC Studio\RCX134.tmp
<Heuristics.Broken.Executable> : C:\Program Files\Samsung\Samsung New PC Studio\RCX134.tmp
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Packages\VC80_x86_v2\Setup\VC80_x86_v2.msi
<Heuristics.Broken.Executable> : C:\ProgramData\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Packages\VC80_x86_v2\Setup\VC80_x86_v2.msi
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Packages\VC80_x86_v2\Setup\VC80_x86_v2.msi
<Heuristics.Broken.Executable> : C:\Users\All Users\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Packages\VC80_x86_v2\Setup\VC80_x86_v2.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FL_HxRuntime_HxS________.3643236F_FC70_11D3_A536_0090278A1BB8
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FL_HxRuntime_HxS________.3643236F_FC70_11D3_A536_0090278A1BB8
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109610070400000000000F01FEC\12.0.4518\EXCEL.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109610070400000000000F01FEC\12.0.4518\EXCEL.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109610070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109610070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109810070400000000000F01FEC\12.0.4518\POWERPNT.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109810070400000000000F01FEC\12.0.4518\POWERPNT.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109810070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109810070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109910070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109910070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109A10070400000000000F01FEC\12.0.4518\OUTLOOK.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109A10070400000000000F01FEC\12.0.4518\OUTLOOK.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109A10070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109A10070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109B10070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109B10070400000000000F01FEC\12.0.4518\VBE.DEV.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109B10070400000000000F01FEC\12.0.4518\WINWORD.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\$PatchCache$\Managed\00002109B10070400000000000F01FEC\12.0.4518\WINWORD.HXS_1031
<Heuristics.Broken.Executable> : C:\Windows\Installer\14b7d6.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\14b7d6.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\9d3d34.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\9d3d34.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57f87.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57f87.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fb0.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fb0.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fb9.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fb9.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fd0.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fd0.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fea.msi
<Heuristics.Broken.Executable> : C:\Windows\Installer\d57fea.msi


Welches Vorgehen empfehlt ihr?
Seitenanfang Seitenende
29.01.2011, 10:19
Member
Avatar Xeper

Beiträge: 5285
#2 Gar keins... außer vielleicht die nerfige Heuristik einen Level runter schrauben.
__________
Email/XMPP: therion at ninth-art dot de
IRC: megatherion @ Freenode
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: