TrojanDownloader:Win32/Wintrim.BX (Microsoft); Skintrim.gen.f (McAfee); Trojan Horse (Symantec); PAK:PE_Patch (Kaspersky); Trojan-Downloader.Win32.Wintrim.bxa (v) (Sunbelt); Trojan.Generic.5601586 (FSecure)

 Plataforma:

Windows 2000, Windows XP, Windows Server 2003

 Classificao do risco total:
 Potencial de dano:
 Potencial de distribuição:
 infecção relatada:
Baixo
Medium
Alto
Crítico

  • Tipo de grayware:
    Trojan

  • Destrutivo:
    Não

  • Criptografado:
     

  • In the Wild:
    Sim

  Visão geral

Löscht Dateien, so dass Programme und Anwendungen nicht ordnungsgemäß ausgeführt werden.

  Detalhes técnicos

Tipo de compactação: 922,724 bytes
Tipo de arquivo: EXE
Residente na memória: Sim
Data de recebimento das amostras iniciais: 26 setembro 2012

Installation

Erstellt die folgenden Ordner:

  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Temp%\nsa3.tmp
  • %Program Files%\InternetGameBox
  • %Program Files%\InternetGameBox\ressources
  • %Program Files%\InternetGameBox\skins
  • %Start Menu%\Programs\InternetGameBox
  • ressources
  • ressources\favoris
  • %Program Files%\InternetGameBox\ressources\favoris

(Hinweis: %System Root% ist der Stammordner, normalerweise C:\. Dort befindet sich auch das Betriebssystem.. %User Profile% ist der Ordner für Benutzerprofile des aktuellen Benutzers, normalerweise C:\Windows\Profile\{Benutzername} unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername} unter Windows NT und C:\Dokumente und Einstellungen\{Benutzername} unter Windows 2000, XP und Server 2003.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.. %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %Start Menu% ist der Ordner 'Startmenü' des aktuellen Benutzers, normalerweise C:\Windows\Profile\{Benutzername}\Startmenü unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Startmenü unter Windows NT und C:\Windows\Startmenü oder C:\Dokumente und Einstellungen\{Benutzername}\Startmenü unter Windows 2000, XP und Server 2003.)

Autostart-Technik

Fügt folgende Registrierungseinträge hinzu, um bei jedem Systemstart automatisch ausgeführt zu werden.

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
owfefn = "%Application Data%\owfefn.exe owfefn"

Andere Systemänderungen

Löscht die folgenden Dateien:

  • %User Temp%\nsk1.tmp
  • %User Temp%\nsa3.tmp
  • %User Temp%\wbk4.tmp
  • %Windows%\SoftwareDistribution\DataStore\Logs\edbtmp.log

(Hinweis: %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.. %Windows% ist der Windows Ordner, normalerweise C:\Windows oder C:\WINNT.)

Fügt die folgenden Registrierungsschlüssel hinzu:

HKEY_CURRENT_USER\Software\IGB

HKEY_LOCAL_MACHINE\Software\IGB

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox

HKEY_CURRENT_USER\Software\fcn

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn

HKEY_CURRENT_USER\Software\LanConfig

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\
FLAGS

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\
0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\
0\win32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\
HELPDIR

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}\TypeLib

HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\
Software\Microsoft\Outlook Express\
5.0\signatures

Fügt die folgenden Registrierungseinträge hinzu:

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
nums = "FCu_SSmAAA-FB0rWl0AAA"

HKEY_CURRENT_USER\Software\IGB
nums = "FCu_SSmAAA-FB0rWl0AAA"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
grpid = "875"

HKEY_CURRENT_USER\Software\IGB
grpid = "875"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
InstallOpt1 = "1"

HKEY_CURRENT_USER\Software\IGB
InstallOpt1 = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
installdt = "20081206"

HKEY_CURRENT_USER\Software\IGB
installdt = "20081206"

HKEY_CURRENT_USER\Software\IGB
uai = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
dl_lg = "IT"

HKEY_CURRENT_USER\Software\IGB
dl_lg = "IT"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
DisplayName = "InternetGameBox "

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
UninstallString = "%Program Files%\InternetGameBox\uninst.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
UninstallString2 = "%Program Files%\InternetGameBox\uninst.exe /S"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
DisplayIcon = "%Program Files%\InternetGameBox\InternetGameBox.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
URLInfoAbout = "http://www.{BLOCKED}etgamebox.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
InternetGameBox
Publisher = "OOO «Favorit»"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
Installer Language = "1033"

HKEY_CURRENT_USER\Software\fcn
gid = "875"

HKEY_CURRENT_USER\Software\fcn
cnid = "V4Nb4bUgSie8y5MG1mwFnw"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn
DisplayName = "Favorit"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn
UninstallString = "%Application Data%\owfefn.exe -uninstall"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn
NoRemove = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn
NoModify = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
owfefn
NoRepair = "1"

HKEY_CURRENT_USER\Software\fcn
idt = "201209260834"

HKEY_CURRENT_USER\Software\LanConfig
LAN = "UP"

HKEY_LOCAL_MACHINE\SOFTWARE\IGB
bnrid = "672125"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Account Manager\Accounts
ConnectionSettingsMigrated = "1"

HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\
Software\Microsoft\Outlook Express\
5.0
StoreMigratedV5 = "1"

HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\
Software\Microsoft\Outlook Express\
5.0
Settings Upgraded = "7"

HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\
Software\Microsoft\Outlook Express\
5.0
Running = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Account Manager\Accounts
AssociatedID = "{random values}"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Account Manager
Server ID = "4"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4
FirstRun = "1"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4
OlkContactRefresh = "0"

HKEY_CURRENT_USER\Software\Microsoft\
WAB\WAB4
OlkFolderRefresh = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
Version = "1.0"

HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\
Software\Microsoft\Outlook Express\
5.0\Mail
Attach VCard = "0"

Ändert die folgenden Registrierungseinträge:

HKEY_CURRENT_USER\SessionInformation
ProgramCount = "2"

(Note: The default value data of the said registry entry is 2.)

HKEY_CURRENT_USER\SessionInformation
ProgramCount = "1"

(Note: The default value data of the said registry entry is 2.)

HKEY_CURRENT_USER\SessionInformation
ProgramCount = "3"

(Note: The default value data of the said registry entry is 2.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4C95A9902ABE0777CED18D6ACCC3372D2748381E
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4BA7B9DDD68788E12FF852E1A024204BF286A8F6
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4B421F7515F6AE8A6ECEF97F6982A400A4D9224E
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
47AFB915CDA26D82467B97FA42914468726138DD
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4463C531D7CCC1006794612BB656D3BF8257846F
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
43F9B110D5BAFD48225231B0D0082B372FEF9A54
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
43DDB1FFF3B49B73831407F6BC8B975023D07C50
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
4072BA31FEC351438480F62E6CB95508461EAB2F
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
394FF6850B06BE52E51856CC10E180E882B385CC
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
SystemCertificates\AuthRoot\Certificates\
36863563FD5128C7BEA6F005CFE9B43668086CCE
Blob = "{random values}"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
Name = "iexplore.exe"

(Note: The default value data of the said registry entry is iexplore.exe.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
ID = "4117b81"

(Note: The default value data of the said registry entry is 41107b81.)

HKEY_CURRENT_USER\Identities
Last Username = "Main Identity"

(Note: The default value data of the said registry entry is Main Identity.)

HKEY_CURRENT_USER\Identities
Last User ID = "{341F68BA-C841-4200-A7B4-3D5CFF202166}"

(Note: The default value data of the said registry entry is {C0FE0177-5693-4537-9331-A7402AD82D40}.)

HKEY_CURRENT_USER\Identities
Identity Login = "9853"

(Note: The default value data of the said registry entry is 98053.)

HKEY_CURRENT_USER\Identities
Identity Ordinal = "2"

(Note: The default value data of the said registry entry is 1.)

Einschleusungsroutine

Schleust die folgenden Dateien ein:

  • %User Temp%\nsk2.tmp
  • %User Temp%\nsa3.tmp\LangDLL.dll
  • %User Temp%\nsa3.tmp\ioSpecial.ini
  • %User Temp%\nsa3.tmp\modern-wizard.bmp
  • %User Temp%\nsa3.tmp\modern-header.bmp
  • %User Temp%\nsa3.tmp\InstallOptions.dll
  • %Application Data%\owfefn.exe
  • %Program Files%\InternetGameBox\InternetGameBox.exe
  • %Program Files%\InternetGameBox\ressources\configv2_fr.xml
  • %Program Files%\InternetGameBox\ressources\configv2_en.xml
  • %Program Files%\InternetGameBox\ressources\configv2_es.xml
  • %Program Files%\InternetGameBox\skins\skinv2.skn
  • %Program Files%\InternetGameBox\language
  • %Start Menu%\Programs\InternetGameBox\InternetGameBox.lnk
  • %Start Menu%\Programs\InternetGameBox\Uninstall.lnk
  • %Desktop%\InternetGameBox.lnk
  • %Program Files%\InternetGameBox\uninst.exe
  • %Application Data%\owfefn.dat
  • %User Temp%\owfefnpi.tmp
  • %Application Data%\owfefn_m2s.xml
  • %Application Data%\owfefn_m2s.zl
  • %Application Data%\owfefn_s2m.zl
  • %Application Data%\owfefn_s2m.xml
  • %User Temp%\owfefnup.tmp
  • %User Temp%\owfefnpic.tmp
  • %Application Data%\owfefn_navps.dat
  • ressources\favoris\defaultv2.swf
  • %Program Files%\InternetGameBox\ressources\AttenteOn.html
  • %Program Files%\InternetGameBox\ressources\AttenteOff.html

(Hinweis: %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.. %Application Data% ist der Ordner 'Anwendungsdaten' für den aktuellen Benutzer, normalerweise C:\Windows\Profile\{Benutzername}\Anwendungsdaten unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Anwendungsdaten unter Windows NT und C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Anwendungsdaten unter Windows 2000, XP und Server 2003.. %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %Start Menu% ist der Ordner 'Startmenü' des aktuellen Benutzers, normalerweise C:\Windows\Profile\{Benutzername}\Startmenü unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Startmenü unter Windows NT und C:\Windows\Startmenü oder C:\Dokumente und Einstellungen\{Benutzername}\Startmenü unter Windows 2000, XP und Server 2003.. %Desktop% ist der Ordner 'Desktop' für den aktuellen Benutzer, normalerweise C:\Windows\Profile\{Benutzername}\Desktop unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Desktop unter Windows NT und C:\Dokumente und Einstellungen\{Benutzername}\Desktop unter Windows 2000, XP und Server 2003.)

  Solução

Mecanismo de varredura mínima: 9.200

Step 1

Für Windows ME und XP Benutzer: Stellen Sie vor einer Suche sicher, dass die Systemwiederherstellung deaktiviert ist, damit der gesamte Computer durchsucht werden kann.

Step 2

Im abgesicherten Modus neu starten

[ Saber mais ]

Step 3

Diesen Registrierungsschlüssel löschen

[ Saber mais ]

Wichtig: Eine nicht ordnungsgemäße Bearbeitung der Windows Registrierung kann zu einer dauerhaften Fehlfunktion des Systems führen. Führen Sie diesen Schritt nur durch, wenn Sie mit der Vorgehensweise vertraut sind oder wenn Sie Ihren Systemadministrator um Unterstützung bitten können. Lesen Sie ansonsten zuerst diesen Microsoft Artikel, bevor Sie die Registrierung Ihres Computers ändern.

  • In HKEY_CURRENT_USER\Software
    • IGB
  • In HKEY_LOCAL_MACHINE\Software
    • IGB
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • InternetGameBox
  • In HKEY_CURRENT_USER\Software
    • fcn
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • owfefn
  • In HKEY_CURRENT_USER\Software
    • LanConfig
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
    • {8CC497C9-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}
    • 1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0
    • FLAGS
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0
    • 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0\0
    • win32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8CC497C9-A1DF-11CE-8098-00AA0047BE5D}\1.0
    • HELPDIR
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C0-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C2-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C1-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C3-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C4-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8CC497C5-A1DF-11CE-8098-00AA0047BE5D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}
    • TypeLib
  • In HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\Software\Microsoft\Outlook Express\5.0
    • signatures

Step 4

Diesen Registrierungswert löschen

[ Saber mais ]

Wichtig: Eine nicht ordnungsgemäße Bearbeitung der Windows Registrierung kann zu einer dauerhaften Fehlfunktion des Systems führen. Führen Sie diesen Schritt nur durch, wenn Sie mit der Vorgehensweise vertraut sind oder wenn Sie Ihren Systemadministrator um Unterstützung bitten können. Lesen Sie ansonsten zuerst diesen Microsoft Artikel, bevor Sie die Registrierung Ihres Computers ändern.

  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • owfefn = "%Application Data%\owfefn.exe owfefn"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • nums = "FCu_SSmAAA-FB0rWl0AAA"
  • In HKEY_CURRENT_USER\Software\IGB
    • nums = "FCu_SSmAAA-FB0rWl0AAA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • grpid = "875"
  • In HKEY_CURRENT_USER\Software\IGB
    • grpid = "875"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • InstallOpt1 = "1"
  • In HKEY_CURRENT_USER\Software\IGB
    • InstallOpt1 = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • installdt = "20081206"
  • In HKEY_CURRENT_USER\Software\IGB
    • installdt = "20081206"
  • In HKEY_CURRENT_USER\Software\IGB
    • uai = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • dl_lg = "IT"
  • In HKEY_CURRENT_USER\Software\IGB
    • dl_lg = "IT"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • DisplayName = "InternetGameBox "
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • UninstallString = "%Program Files%\InternetGameBox\uninst.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • UninstallString2 = "%Program Files%\InternetGameBox\uninst.exe /S"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • DisplayIcon = "%Program Files%\InternetGameBox\InternetGameBox.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • URLInfoAbout = "http://www.{BLOCKED}etgamebox.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetGameBox
    • Publisher = "OOO «Favorit»"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • Installer Language = "1033"
  • In HKEY_CURRENT_USER\Software\fcn
    • gid = "875"
  • In HKEY_CURRENT_USER\Software\fcn
    • cnid = "V4Nb4bUgSie8y5MG1mwFnw"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\owfefn
    • DisplayName = "Favorit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\owfefn
    • UninstallString = "%Application Data%\owfefn.exe -uninstall"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\owfefn
    • NoRemove = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\owfefn
    • NoModify = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\owfefn
    • NoRepair = "1"
  • In HKEY_CURRENT_USER\Software\fcn
    • idt = "201209260834"
  • In HKEY_CURRENT_USER\Software\LanConfig
    • LAN = "UP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\IGB
    • bnrid = "672125"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
    • ConnectionSettingsMigrated = "1"
  • In HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\Software\Microsoft\Outlook Express\5.0
    • StoreMigratedV5 = "1"
  • In HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\Software\Microsoft\Outlook Express\5.0
    • Settings Upgraded = "7"
  • In HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\Software\Microsoft\Outlook Express\5.0
    • Running = "1"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
    • AssociatedID = "{random values}"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager
    • Server ID = "4"
  • In HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4
    • FirstRun = "1"
  • In HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4
    • OlkContactRefresh = "0"
  • In HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4
    • OlkFolderRefresh = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C0-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C2-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C1-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C3-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C4-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CC497C5-A1DF-11CE-8098-00AA0047BE5D}\TypeLib
    • Version = "1.0"
  • In HKEY_CURRENT_USER\Identities\{341F68BA-C841-4200-A7B4-3D5CFF202166}\Software\Microsoft\Outlook Express\5.0\Mail
    • Attach VCard = "0"

Step 5

Diesen geänderten Registrierungswert wiederherstellen

[ Saber mais ]

Wichtig: Eine nicht ordnungsgemäße Bearbeitung der Windows Registrierung kann zu einer dauerhaften Fehlfunktion des Systems führen. Führen Sie diesen Schritt nur durch, wenn Sie mit der Vorgehensweise vertraut sind oder wenn Sie Ihren Systemadministrator um Unterstützung bitten können. Lesen Sie ansonsten zuerst diesen Microsoft Artikel, bevor Sie die Registrierung Ihres Computers ändern.

  • In HKEY_CURRENT_USER\SessionInformation
    • From: ProgramCount = "2"
      To: ProgramCount = ""2""
  • In HKEY_CURRENT_USER\SessionInformation
    • From: ProgramCount = "1"
      To: ProgramCount = ""2""
  • In HKEY_CURRENT_USER\SessionInformation
    • From: ProgramCount = "3"
      To: ProgramCount = ""2""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4C95A9902ABE0777CED18D6ACCC3372D2748381E
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4BA7B9DDD68788E12FF852E1A024204BF286A8F6
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4B421F7515F6AE8A6ECEF97F6982A400A4D9224E
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47AFB915CDA26D82467B97FA42914468726138DD
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4463C531D7CCC1006794612BB656D3BF8257846F
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\43F9B110D5BAFD48225231B0D0082B372FEF9A54
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\43DDB1FFF3B49B73831407F6BC8B975023D07C50
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4072BA31FEC351438480F62E6CB95508461EAB2F
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\394FF6850B06BE52E51856CC10E180E882B385CC
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36863563FD5128C7BEA6F005CFE9B43668086CCE
    • From: Blob = "{random values}"
      To: Blob = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    • From: Name = "iexplore.exe"
      To: Name = ""iexplore.exe""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    • From: ID = "4117b81"
      To: ID = ""41107b81""
  • In HKEY_CURRENT_USER\Identities
    • From: Last Username = "Main Identity"
      To: Last Username = ""Main Identity""
  • In HKEY_CURRENT_USER\Identities
    • From: Last User ID = "{341F68BA-C841-4200-A7B4-3D5CFF202166}"
      To: Last User ID = ""{C0FE0177-5693-4537-9331-A7402AD82D40}""
  • In HKEY_CURRENT_USER\Identities
    • From: Identity Login = "9853"
      To: Identity Login = ""98053""
  • In HKEY_CURRENT_USER\Identities
    • From: Identity Ordinal = "2"
      To: Identity Ordinal = ""1""

Step 6

Diese Dateien suchen und löschen

[ Saber mais ]
Möglicherweise sind einige Komponentendateien verborgen. Aktivieren Sie unbedingt das Kontrollkästchen Versteckte Elemente durchsuchen unter "Weitere erweiterte Optionen", um alle verborgenen Dateien und Ordner in den Suchergebnissen zu berücksichtigen.
  • %User Temp%\nsk2.tmp
  • %User Temp%\nsa3.tmp\LangDLL.dll
  • %User Temp%\nsa3.tmp\ioSpecial.ini
  • %User Temp%\nsa3.tmp\modern-wizard.bmp
  • %User Temp%\nsa3.tmp\modern-header.bmp
  • %User Temp%\nsa3.tmp\InstallOptions.dll
  • %Application Data%\owfefn.exe
  • %Program Files%\InternetGameBox\InternetGameBox.exe
  • %Program Files%\InternetGameBox\ressources\configv2_fr.xml
  • %Program Files%\InternetGameBox\ressources\configv2_en.xml
  • %Program Files%\InternetGameBox\ressources\configv2_es.xml
  • %Program Files%\InternetGameBox\skins\skinv2.skn
  • %Program Files%\InternetGameBox\language
  • %Start Menu%\Programs\InternetGameBox\InternetGameBox.lnk
  • %Start Menu%\Programs\InternetGameBox\Uninstall.lnk
  • %Desktop%\InternetGameBox.lnk
  • %Program Files%\InternetGameBox\uninst.exe
  • %Application Data%\owfefn.dat
  • %User Temp%\owfefnpi.tmp
  • %Application Data%\owfefn_m2s.xml
  • %Application Data%\owfefn_m2s.zl
  • %Application Data%\owfefn_s2m.zl
  • %Application Data%\owfefn_s2m.xml
  • %User Temp%\owfefnup.tmp
  • %User Temp%\owfefnpic.tmp
  • %Application Data%\owfefn_navps.dat
  • ressources\favoris\defaultv2.swf
  • %Program Files%\InternetGameBox\ressources\AttenteOn.html
  • %Program Files%\InternetGameBox\ressources\AttenteOff.html

Step 7

Diese Ordner suchen und löschen

[ Saber mais ]
Aktivieren Sie unbedingt das Kontrollkästchen Versteckte Elemente durchsuchen unter Weitere erweiterte Optionen, um alle verborgenen Ordner in den Suchergebnissen zu berücksichtigen.
  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Temp%\nsa3.tmp
  • %Program Files%\InternetGameBox
  • %Program Files%\InternetGameBox\ressources
  • %Program Files%\InternetGameBox\skins
  • %Start Menu%\Programs\InternetGameBox
  • ressources
  • ressources\favoris
  • %Program Files%\InternetGameBox\ressources\favoris

Step 8

Führen Sie den Neustart im normalen Modus durch, und durchsuchen Sie Ihren Computer mit Ihrem Trend Micro Produkt nach Dateien, die als TROJ_PACKSKINTRIM_000002b.TOMA entdeckt werden. Falls die entdeckten Dateien bereits von Ihrem Trend Micro Produkt gesäubert, gelöscht oder in Quarantäne verschoben wurden, sind keine weiteren Schritte erforderlich. Dateien in Quarantäne können einfach gelöscht werden. Auf dieser Knowledge-Base-Seite finden Sie weitere Informationen.


Participe da nossa pesquisa!