![]() |
|
Plagegeister aller Art und deren Bekämpfung: worm.Zhelatin in C:\Windows\System32\fsvk.exe.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() worm.Zhelatin in C:\Windows\System32\fsvk.exe.exe Guten Abend, Ich habe heute mit Hilfe eines Freundes festgestellt (über Malwarebytes), dass ich einen worm.Zhelatin in C:\Windows\System32\fsvk.exe.exe auf meinem System mit Windows 7 Home Premium 64bit habe. ![]() In einem anderen Thread habe ich bereits etwas darüber gelesen, jedoch bin ich daraus auch nicht wirklich schlauer geworden. Dort stand nur, dass man den PC neu aufsetzen soll, was ich aber, sofern dies möglich ist verhindern möchte, da ich erstens sehr viele Dateien habe, die dadurch verloren gehen würden und zweitens beim Kauf des PCs keine Windows CD erhalten habe, sondern nur einen Key (falls Neuinstallation nicht zu verhindern wäre ich froh, wenn mir jemand erklären kann, wie das ohne eine CD funktioniert). Hier noch das Log: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 10.06.2014 Scan Time: 13:51:01 Logfile: worm_zhelatin_test.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.10.04 Rootkit Database: v2014.06.02.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Fabio Scan Type: Threat Scan Result: Completed Objects Scanned: 286029 Time Elapsed: 7 min, 43 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 2 PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, 4644, Delete-on-Reboot, [04c83f37adce5adc86146fbbb34e1ae6] PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, 4656, Delete-on-Reboot, [705ce294354641f5465258d2956c7f81] Modules: 0 (No malicious items detected) Registry Keys: 1 PUP.Optional.OptimizerPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\70e6ca8c, Quarantined, [ddef3c3a6318f3430fdbd365e61e17e9], Registry Values: 0 (No malicious items detected) Registry Data: 10 PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Replaced,[1eaebbbbf6850d29e22986e140c458a8] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[428a6e087506e4528589b4b39371e31d] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[686444323546d46237c07cf4c4409f61] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[2f9dc9ad2952b284f31a9bccf50fcf31] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[08c45521a2d99a9c9e588fe19b6951af] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[f2da294d6c0f122468a87deaaf55f20e] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[ab21aacc75060f276d8c9ed2f21212ee] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[dcf0344279021125c64bf0779470728e] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[b616e88ee19ae84e04f6610f7490c53b] PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[616b591ded8e191db9530067be46867a] Folders: 3 PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy, Quarantined, [b3194e28334853e351346223a55df40c], PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\EEB2EBA2411B4197833F9FAA22CB5138, Quarantined, [b3194e28334853e351346223a55df40c], PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\F74DD1FA2D9C4A6D82AE42E0BF7B59AC, Quarantined, [b3194e28334853e351346223a55df40c], Files: 6 PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProCrash.exe, Delete-on-Reboot, [ddef3c3a6318f3430fdbd365e61e17e9], PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Delete-on-Reboot, [04c83f37adce5adc86146fbbb34e1ae6], PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, Delete-on-Reboot, [705ce294354641f5465258d2956c7f81], PUP.Optional.Linkury.A, C:\Users\Fabio\AppData\Roaming\OpenCandy\EEB2EBA2411B4197833F9FAA22CB5138\Installer.exe, Quarantined, [547883f39be07cba3e24f446828212ee], Worm.Zhelatin, C:\Windows\System32\fsvk.exe.exe, Quarantined, [ebe16c0ae19aac8a0517dc2733d044bc], PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\F74DD1FA2D9C4A6D82AE42E0BF7B59AC\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, Quarantined, [b3194e28334853e351346223a55df40c], Physical Sectors: 0 (No malicious items detected) (end) ![]() Vielen Dank im Voraus, Fabio |
Themen zu worm.Zhelatin in C:\Windows\System32\fsvk.exe.exe |
c:\windows, detected, explorer, funktioniert, internet, internet explorer, malwarebytes, microsoft, neuinstallation, pup.optional.helperbar.a, pup.optional.linkury.a, pup.optional.opencandy, pup.optional.optimizerpro, roaming, services, software, spyhunter, spyhunter entfernen, system, system32, windows, worm.zhelatin |