![]() |
|
Log-Analyse und Auswertung: WINDOWS gefährdet - muss 50 Euro zahlen !Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() WINDOWS gefährdet - muss 50 Euro zahlen ! Hey, also ich habe auch das Problem dass wenn ich meinen Laptop mit Internetverbindung starte, kommt direkt ein schwarzer Bildschirm mit einer Meldung mein Pc sei "besonders gefährdet" und es müsste gesperrt werden. Um dies zu beheben soll ich mir irgendwas runterladen und dafür bezahlen. Ich geh mal davon aus, dass es dasselbe ist was sich hier schon mehrere eingefangen haben. Zumindest hab ich von ähnlichen Fällen gelesen. Ich hab mir bereits die srep.exe runtergeladen und sie durchlaufen lassen. Bitte um Hilfe... Hier ist meine Shell.txt datei: WIN_7 X64 Service Pack 1 Running from F:\ HKLM\..\Winlogon; Shell = explorer.exe [ Microsoft Corporation ] . . . HKCU\..\Winlogon; Shell not found . [System Process] System smss.exe csrss.exe wininit.exe csrss.exe services.exe lsass.exe lsm.exe winlogon.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe cmd.exe conhost.exe ctfmon.exe srep.exe svchost.exe WmiPrvSE.exe HKLM\..\Run [UpdateLBPShortCut] = "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" HKLM\..\Run [UpdateP2GoShortCut] = "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" HKLM\..\Run [ATKOSD2] = C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe HKLM\..\Run [ATKMEDIA] = C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe HKLM\..\Run [HControlUser] = C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe HKLM\..\Run [avgnt] = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM\..\Run [PDFPrint] = C:\Program Files (x86)\PDF24\pdf24.exe HKLM\..\Run [Adobe ARM] = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" HKCU\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKCU\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKCU\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKCU\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKCU\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe HKU\.DEFAULT\..\Winlogon; Shell = HKU\S-1-5-19\..\Winlogon; Shell = HKU\S-1-5-20\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001_Classes\..\Winlogon; Shell = HKU\S-1-5-18\..\Winlogon; Shell = HKU\S-1-5-19\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe x64 HKLMx64\..\Winlogon; Shell = explorer.exe [ 2871808- ] No action taken HKCUx6464\..\Winlogon; Shell = No action taken HKLMx64\..\Winlogon, Shell = explorer.exe HKCUx64\..\Winlogon, Shell = ==== FINISH 04.02-13.23 ==== WIN_7 X64 Service Pack 1 Running from F:\ HKLM\..\Winlogon; Shell = explorer.exe [ Microsoft Corporation ] . . . HKCU\..\Winlogon; Shell not found . [System Process] System smss.exe csrss.exe wininit.exe csrss.exe services.exe lsass.exe lsm.exe winlogon.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe cmd.exe conhost.exe ctfmon.exe srep.exe svchost.exe HKLM\..\Run [UpdateLBPShortCut] = "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" HKLM\..\Run [UpdateP2GoShortCut] = "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" HKLM\..\Run [ATKOSD2] = C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe HKLM\..\Run [ATKMEDIA] = C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe HKLM\..\Run [HControlUser] = C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe HKLM\..\Run [avgnt] = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM\..\Run [PDFPrint] = C:\Program Files (x86)\PDF24\pdf24.exe HKLM\..\Run [Adobe ARM] = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" HKCU\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKCU\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKCU\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKCU\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKCU\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe HKU\.DEFAULT\..\Winlogon; Shell = HKU\S-1-5-19\..\Winlogon; Shell = HKU\S-1-5-20\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001_Classes\..\Winlogon; Shell = HKU\S-1-5-18\..\Winlogon; Shell = HKU\S-1-5-19\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe x64 HKLMx64\..\Winlogon; Shell = explorer.exe [ 2871808- ] No action taken HKCUx6464\..\Winlogon; Shell = No action taken HKLMx64\..\Winlogon, Shell = explorer.exe HKCUx64\..\Winlogon, Shell = ==== FINISH 04.02-13.34 ==== WIN_7 X64 Service Pack 1 Running from F:\ HKLM\..\Winlogon; Shell = explorer.exe [ Microsoft Corporation ] . . . HKCU\..\Winlogon; Shell not found . [System Process] System smss.exe csrss.exe wininit.exe csrss.exe services.exe lsass.exe lsm.exe winlogon.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe cmd.exe conhost.exe ctfmon.exe svchost.exe WmiPrvSE.exe srep.exe HKLM\..\Run [UpdateLBPShortCut] = "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" HKLM\..\Run [UpdateP2GoShortCut] = "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" HKLM\..\Run [ATKOSD2] = C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe HKLM\..\Run [ATKMEDIA] = C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe HKLM\..\Run [HControlUser] = C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe HKLM\..\Run [avgnt] = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM\..\Run [PDFPrint] = C:\Program Files (x86)\PDF24\pdf24.exe HKLM\..\Run [Adobe ARM] = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" HKCU\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKCU\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKCU\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKCU\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKCU\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe HKU\.DEFAULT\..\Winlogon; Shell = HKU\S-1-5-19\..\Winlogon; Shell = HKU\S-1-5-20\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Winlogon; Shell = HKU\S-1-5-21-3204032702-2654643515-1623689083-1001_Classes\..\Winlogon; Shell = HKU\S-1-5-18\..\Winlogon; Shell = HKU\S-1-5-19\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Syncables] = C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Raptr] = C:\PROGRA~2\Raptr\raptrstub.exe --startup HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Push Client] = C:\Users\Mamoris\AppData\Local\ATT Connect\Participant\pull.exe HKU\S-1-5-21-3204032702-2654643515-1623689083-1001\..\Run [Mozilla client] = C:\Users\Mamoris\AppData\Local\Mozilla\Firefox\firefox.exe x64 HKLMx64\..\Winlogon; Shell = explorer.exe [ 2871808- ] No action taken HKCUx6464\..\Winlogon; Shell = No action taken HKLMx64\..\Winlogon, Shell = explorer.exe HKCUx64\..\Winlogon, Shell = ==== FINISH 04.02-13.48 ==== |
Themen zu WINDOWS gefährdet - muss 50 Euro zahlen ! |
adobe, antivir, appdata, asus, avg, avgnt, avira, bildschirm, datei, desktop, euro, explorer.exe, firefox, gesperrt, hotkey, internetverbindung, laptop, microsoft, mozilla, problem, schwarzer bildschirm, software, system, verbindung, windows, windows gefährdet, winlogon |