|
Plagegeister aller Art und deren Bekämpfung: AKM 50€ virusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.03.2012, 21:32 | #1 |
| AKM 50€ virus hallo habe diesen akm virus auf meinem Computer wo verlangt das ich 50€ zahle. Ich könnte den PC auch einfach neu aufsetzen (glaube ich zumindest ^^) aber habe sehr viele (für mich) wichtige Dateien auf dem PC (eigene Musik, usw.) Habe das mit OTL gelesen und soweit durchgeführt hier die OTL.txt datei: OTL logfile created on: 3/14/2012 9:36:12 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 100.00 Mb Total Space | 75.86 Mb Free Space | 75.87% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 182.13 Gb Free Space | 39.10% Space Free | Partition Type: NTFS Drive E: | 465.66 Gb Total Space | 258.45 Gb Free Space | 55.50% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011/07/13 05:17:14 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) [Auto] -- E:\Windows\System32\ViakaraokeSrv.exe -- (VIAKaraokeService) SRV:64bit: - [2011/04/27 11:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv) SRV:64bit: - [2011/04/27 11:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2011/09/28 15:19:37 | 000,215,128 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB) SRV - [2011/07/30 10:09:23 | 000,075,136 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/05/21 00:01:00 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/19 07:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2010/01/29 19:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto] -- E:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC) SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/07/28 01:54:18 | 000,183,168 | ---- | M] (Hauppauge, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\hcwhdpvr.sys -- (hcwhdpvr) DRV:64bit: - [2011/07/13 05:17:13 | 002,157,680 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV:64bit: - [2011/06/10 01:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011/04/27 09:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2009/09/03 11:30:20 | 000,128,512 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tiehdusb.sys -- (TIEHDUSB) DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\serscan.sys -- (StillCam) DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 16:35:36 | 000,867,328 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\netr28ux.sys -- (netr28ux) DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/03/18 11:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV:64bit: - [2005/03/28 19:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.vol.at/ IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8B 25 E1 4E 3C 41 CC 01 [binary data] IE - HKU\Felix_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.facebook.com/home.php" FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/03/09 08:38:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/12 07:52:19 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/03/09 08:38:22 | 000,000,000 | ---D | M] [2011/07/15 16:23:53 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Felix\AppData\Roaming\Mozilla\Extensions [2012/02/07 10:14:29 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\8g09duiv.default\extensions [2012/02/07 10:14:29 | 000,000,000 | ---D | M] (DealPly) -- E:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\8g09duiv.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2011/07/15 16:23:30 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions File not found (No name found) -- [2012/03/12 07:52:19 | 000,134,104 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/02/09 08:47:02 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/02/09 08:47:02 | 000,002,252 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/02/09 08:47:02 | 000,001,153 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/02/09 08:47:02 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/02/09 08:47:02 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/02/09 08:47:02 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - E:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] E:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [MSC] E:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found O4 - HKLM..\Run: [AdobeCS5ServiceManager] E:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] E:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [ArcSoft Connection Service] File not found O4 - HKLM..\Run: [HDAudDeck] E:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [SwitchBoard] E:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\Felix_ON_E..\Run: [AdobeBridge] E:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe (Adobe Systems, Inc.) O4 - HKU\Felix_ON_E..\Run: [K3aRyluP6SiCkoR] E:\Users\Felix\AppData\Roaming\flint4ytw.exe (All Alex,Inc) O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\UpdatusUser_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] File not found O4 - HKU\UpdatusUser_ON_E..\RunOnce: [mctadmin] File not found O4 - Startup: E:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.7.254 O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKU\Felix_ON_E Winlogon: Shell - (C:\Users\Felix\AppData\Roaming\flint4ytw.exe) - E:\Users\Felix\AppData\Roaming\flint4ytw.exe (All Alex,Inc) O20 - HKU\Felix_ON_E Winlogon: UserInit - (C:\Users\Felix\AppData\Roaming\flint4ytw.exe) - E:\Users\Felix\AppData\Roaming\flint4ytw.exe (All Alex,Inc) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{323f50de-e469-11e0-bab3-20cf30b0a057}\Shell - "" = AutoRun O33 - MountPoints2\{323f50de-e469-11e0-bab3-20cf30b0a057}\Shell\AutoRun\command - "" = G:\start.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/03/13 16:31:39 | 000,308,224 | ---- | C] (All Alex,Inc) -- E:\Users\Felix\AppData\Roaming\flint4ytw.exe [2012/03/12 14:46:17 | 000,000,000 | ---D | C] -- E:\Users\Felix\Desktop\Videos [2012/03/10 08:52:37 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\MSXML 4.0 [2012/03/09 10:49:09 | 000,000,000 | ---D | C] -- E:\Users\Felix\Desktop\YOUTUBE [2012/03/09 10:01:55 | 000,000,000 | ---D | C] -- E:\Users\Felix\Desktop\16er [2012/03/09 08:40:42 | 000,000,000 | ---D | C] -- E:\ProgramData\WEBREG [2012/03/09 08:40:42 | 000,000,000 | ---D | C] -- E:\Users\Felix\AppData\Roaming\HP [2012/03/09 08:38:33 | 000,000,000 | ---D | C] -- E:\Users\Felix\AppData\Roaming\HpUpdate [2012/03/09 08:37:32 | 000,000,000 | ---D | C] -- E:\ProgramData\HP Product Assistant [2012/03/09 08:35:47 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Common Files\HP [2012/03/09 08:35:41 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Common Files\Hewlett-Packard [2012/03/09 08:35:23 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [2012/03/09 08:34:13 | 000,642,360 | ---- | C] (Hewlett-Packard) -- E:\Windows\System32\hpzids40.dll [2012/03/09 08:34:09 | 000,136,704 | ---- | C] (Hewlett-Packard Company) -- E:\Windows\System32\hpf3l70w.dll [2012/03/09 08:34:05 | 000,881,664 | ---- | C] (Hewlett-Packard) -- E:\Windows\System32\hposwia_d02d.dll [2012/03/09 08:34:05 | 000,749,056 | ---- | C] (Hewlett-Packard Co.) -- E:\Windows\System32\hpost_d02d.dll [2012/03/09 08:34:05 | 000,551,424 | ---- | C] (Hewlett-Packard) -- E:\Windows\System32\hppldcoi.dll [2012/03/09 08:34:05 | 000,516,096 | ---- | C] (Hewlett-Packard Co.) -- E:\Windows\System32\hposc_d02a.dll [2012/03/09 08:33:18 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\HP [2012/03/09 08:32:19 | 000,000,000 | ---D | C] -- E:\ProgramData\HP [2012/02/15 14:47:28 | 000,096,256 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtmled.dll [2012/02/15 14:47:27 | 000,072,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\mshtmled.dll [2012/02/15 14:47:26 | 002,308,096 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll [2012/02/15 14:47:26 | 000,237,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll [2012/02/15 14:47:26 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\url.dll [2012/02/15 14:47:25 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\ieui.dll [2012/02/15 14:47:24 | 001,798,656 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\jscript9.dll [2012/02/15 14:47:24 | 000,248,320 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll [2012/02/15 14:47:23 | 001,427,456 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\inetcpl.cpl [2012/02/15 14:47:23 | 000,818,688 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript.dll [2012/02/15 14:47:23 | 000,716,800 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\jscript.dll [2012/02/15 14:47:22 | 001,493,504 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl [2012/02/15 07:24:16 | 000,509,952 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntshrui.dll [2012/02/15 07:24:14 | 000,515,584 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\timedate.cpl [2012/02/15 07:24:14 | 000,478,720 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\timedate.cpl [2012/02/15 07:24:10 | 000,634,880 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msvcrt.dll [2011/08/20 13:43:49 | 000,695,296 | ---- | C] (AnjoCaido) -- E:\Users\Felix\AppData\Roaming\MinecraftSP.exe [1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/03/14 15:01:17 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat [2012/03/14 14:59:42 | 3220,480,000 | -HS- | M] () -- E:\hiberfil.sys [2012/03/13 16:31:38 | 000,308,224 | ---- | M] (All Alex,Inc) -- E:\Users\Felix\AppData\Roaming\flint4ytw.exe [2012/03/13 15:19:27 | 000,014,832 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/03/13 15:19:27 | 000,014,832 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/03/13 08:27:18 | 004,101,774 | ---- | M] () -- E:\Windows\System32\perfh007.dat [2012/03/13 08:27:18 | 001,680,984 | ---- | M] () -- E:\Windows\System32\perfh009.dat [2012/03/13 08:27:18 | 001,211,926 | ---- | M] () -- E:\Windows\System32\perfc007.dat [2012/03/13 08:27:18 | 001,074,770 | ---- | M] () -- E:\Windows\System32\perfc009.dat [2012/03/11 09:02:16 | 000,127,504 | ---- | M] () -- E:\Users\Felix\Desktop\#1.mp3.sfk [2012/03/11 09:02:13 | 002,388,953 | ---- | M] () -- E:\Users\Felix\Desktop\#1.1.mp3 [2012/03/09 13:25:29 | 004,860,496 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT [2012/03/09 08:40:35 | 000,230,191 | ---- | M] () -- E:\Windows\hpoins46.dat [2012/03/09 08:40:18 | 000,000,000 | R--D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [2012/03/09 08:38:35 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [2012/03/09 08:38:11 | 000,001,189 | ---- | M] () -- E:\Users\Public\Desktop\Shop für HP Zubehör.lnk [2012/03/09 08:37:25 | 000,001,351 | ---- | M] () -- E:\Users\Public\Desktop\HP Solution Center.lnk [2012/03/09 08:36:39 | 000,002,099 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012/03/08 16:09:15 | 003,799,698 | ---- | M] () -- E:\Users\Felix\Desktop\Avicii - Levels (Radio Edit).mp3 [2012/02/15 14:49:46 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/03/11 09:02:05 | 002,388,953 | ---- | C] () -- E:\Users\Felix\Desktop\#1.1.mp3 [2012/03/11 08:49:53 | 000,127,504 | ---- | C] () -- E:\Users\Felix\Desktop\#1.mp3.sfk [2012/03/09 08:38:11 | 000,001,189 | ---- | C] () -- E:\Users\Public\Desktop\Shop für HP Zubehör.lnk [2012/03/09 08:37:25 | 000,001,351 | ---- | C] () -- E:\Users\Public\Desktop\HP Solution Center.lnk [2012/03/09 08:36:39 | 000,002,099 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012/03/09 08:32:33 | 000,230,191 | ---- | C] () -- E:\Windows\hpoins46.dat [2012/03/08 16:09:10 | 003,799,698 | ---- | C] () -- E:\Users\Felix\Desktop\Avicii - Levels (Radio Edit).mp3 [2011/10/20 11:24:34 | 000,065,536 | ---- | C] () -- E:\Windows\SysWow64\dmcrypto.dll [2011/10/20 11:23:35 | 000,002,384 | ---- | C] () -- E:\Windows\HCWPNP.INI [2011/08/25 06:52:29 | 000,016,896 | ---- | C] () -- E:\Users\Felix\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/08/20 19:03:40 | 000,000,192 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\vehicles.properties [2011/08/20 13:43:49 | 003,667,968 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\hamachi.msi [2011/08/20 13:43:49 | 000,290,797 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\minecraft_name.jar [2011/08/20 13:43:49 | 000,232,501 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\Minecraft.exe [2011/08/20 13:43:49 | 000,051,765 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\Minecraft.jar [2011/08/20 13:43:49 | 000,000,133 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\zan.settings [2011/08/20 13:43:49 | 000,000,070 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\mcpatcher.properties [2011/08/20 13:43:49 | 000,000,008 | ---- | C] () -- E:\Users\Felix\AppData\Roaming\lastlogin [2011/08/09 04:46:41 | 000,001,456 | ---- | C] () -- E:\Users\Felix\AppData\Local\Adobe Für Web speichern 12.0 Prefs [2011/07/29 18:28:01 | 000,215,128 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe [2011/07/29 18:28:00 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe [2011/07/29 18:28:00 | 000,075,136 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe [2011/07/27 11:31:22 | 000,017,408 | ---- | C] () -- E:\Users\Felix\AppData\Local\WebpageIcons.db [2011/07/13 05:18:39 | 000,001,769 | ---- | C] () -- E:\Windows\Language_trs.ini [2011/07/13 03:27:00 | 000,252,928 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll [2011/07/13 02:13:41 | 000,006,446 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI [2010/01/29 17:21:20 | 000,000,532 | ---- | C] () -- E:\Windows\hpomdl46.dat [2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2011/07/13 01:45:27 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2011/07/13 01:45:27 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente [2011/07/13 01:45:27 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/07/27 12:41:48 | 000,000,000 | ---D | M] -- E:\ProgramData\FXhome [2011/12/11 14:35:10 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files [2011/07/27 11:34:23 | 000,000,000 | ---D | M] -- E:\ProgramData\regid.1986-12.com.adobe [2012/02/07 09:26:27 | 000,000,000 | ---D | M] -- E:\ProgramData\Sony [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2011/07/13 01:45:27 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2011/07/13 01:45:27 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen [2012/01/05 06:38:55 | 000,032,640 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Bitte um eure Hilfe mfg Primax00 |
14.03.2012, 22:09 | #2 | |||||
/// Helfer-Team | AKM 50€ virus Hallo und Herzlich Willkommen!
__________________Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]: Zitat:
Zitat:
Für Vista und Win7: Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen! 1. Zitat:
Code:
ATTFilter :OTL IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vol.at/ IE - HKU\Felix_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://at.msn.com/?ocid=iehp FF - prefs.js..browser.startup.homepage: "hxxp://www.facebook.com/home.php" FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found O4 - HKU\Felix_ON_E..\Run: [K3aRyluP6SiCkoR] E:\Users\Felix\AppData\Roaming\flint4ytw.exe (All Alex,Inc) O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] File not found O4 - HKU\UpdatusUser_ON_E..\RunOnce: [mctadmin] File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{323f50de-e469-11e0-bab3-20cf30b0a057}\Shell - "" = AutoRun O33 - MountPoints2\{323f50de-e469-11e0-bab3-20cf30b0a057}\Shell\AutoRun\command - "" = G:\start.exe :Files E:\Users\Felix\AppData\Roaming\flint4ytw.exe ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyjava]
Zitat:
Lade Dir Malwarebytes Anti-Malware von→ malwarebytes.org
3. Um festzustellen, ob veraltete oder schädliche Software unter Programme installiert sind, ich würde gerne noch all deine installierten Programme sehen:
4. erneut einen Scan mit OTL:
Zitat:
** Möglichst nicht ins internet gehen, kein Online-Banking, File-sharing, Chatprogramme usw grußkira
__________________ |
Themen zu AKM 50€ virus |
adobe, akm 50 euro virus, aufsetzen, autorun, bho, cdrom, computer, dateien, dealply, defender, explorer, explorer.exe, firefox, format, home, langs, logfile, microsoft, microsoft security, musik, neu, neu aufsetzen, nvidia, plug-in, realtek, registry, scan, security, software, vdeck.exe, version=1.0, virus, winlogon |