So, ich brauche wieder Hilfe. Also ich habe mir jetzt vor paar Minuten eine Datei geladen - sie erschien mir schon ein wenig komisch, aber ich war mal frohen Mutes und hab sie gestartet (Keine Random Datei, kenne das Teil, nur leider nicht von der Seite).
Naja, nichts kam - wurde also nichts ausgeführt. Nun durch zufall hab ich gerade meine msconfig gecheckt und habe dies hier gefunden:
apocalyps32 | donfelipe + FileDescription | "C:\Windows\apocalyps32.exe"
Hab den Eintrag jetzt sofort rausgenommen und bisher noch nicht neu gestartet. Tuneup-Startup Manager sieht diesen Eintrag auch und er hat das gleiche Icon wie meine "mysteriöse" Datei.
Nun denn, ich lösche die Datei gleich erstmal und schau dann weiter. Vorher einmal hier sämtliche Logs:
Hijackthis:
Zitat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:02:15, on 07.02.2010
Platform: Unknown Windows (WinNT 6.01.3504) (Windows7 Home Prem. x86)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Creative\Volume Panel\VolPanlu.exe
C:\Windows\System32\Ctxfihlp.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\Steam\Steam.exe
D:\Program Files\Xfire\Xfire.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\ICQ7.0\ICQ.exe
C:\Program Files\Java\jre6\bin\javaw.exe
D:\Program Files\foobar2000\foobar2000.exe
D:\Program Files\CD Art Display\CAD.exe
C:\Windows\system32\taskhost.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
D:\Program Files\TuneUp Utilities 2010\Integrator.exe
D:\Program Files\TuneUp Utilities 2010\StartUpManager.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Windows\system32\msconfig.exe
C:\Windows\system32\notepad.exe
G:\Sonstiges\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\apocalyps32.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [VirtualCloneDrive] "d:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s O4 - HKLM\..\Run: [apocalyps32] C:\Windows\apocalyps32.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "D:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\Xfire.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: HP Intelligente Auswahl - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Dolby Digital Live Pack Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\DDLLicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dragon Age: Origins - Inhaltsupdater (DAUpdaterSvc) - BioWare - D:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @D:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - D:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 7085 bytes
|
AntiVir:
Zitat:
Avira AntiVir Personal
Report file date: Sonntag, 7. Februar 2010 21:47
Scanning for 1731055 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows Vista
Windows version : (plain) [6.1.7600]
Boot mode : Normally booted
Username : Jinjael
Computer name : JINJAELSPC
Version information:
BUILD.DAT : 9.0.0.419 21701 Bytes 22.01.2010 18:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 13.10.2009 10:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27.02.2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20.02.2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27.02.2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 06:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19.11.2009 16:29:56
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20.01.2010 15:39:18
VBASE003.VDF : 7.10.3.75 996864 Bytes 26.01.2010 17:07:33
VBASE004.VDF : 7.10.3.76 2048 Bytes 26.01.2010 17:07:33
VBASE005.VDF : 7.10.3.77 2048 Bytes 26.01.2010 17:07:33
VBASE006.VDF : 7.10.3.78 2048 Bytes 26.01.2010 17:07:33
VBASE007.VDF : 7.10.3.79 2048 Bytes 26.01.2010 17:07:33
VBASE008.VDF : 7.10.3.80 2048 Bytes 26.01.2010 17:07:34
VBASE009.VDF : 7.10.3.81 2048 Bytes 26.01.2010 17:07:36
VBASE010.VDF : 7.10.3.82 2048 Bytes 26.01.2010 17:07:36
VBASE011.VDF : 7.10.3.83 2048 Bytes 26.01.2010 17:07:37
VBASE012.VDF : 7.10.3.84 2048 Bytes 26.01.2010 17:07:37
VBASE013.VDF : 7.10.3.85 2048 Bytes 26.01.2010 17:07:37
VBASE014.VDF : 7.10.3.122 172544 Bytes 29.01.2010 16:41:06
VBASE015.VDF : 7.10.3.149 79872 Bytes 01.02.2010 17:15:10
VBASE016.VDF : 7.10.3.174 68608 Bytes 03.02.2010 17:17:10
VBASE017.VDF : 7.10.3.199 76800 Bytes 04.02.2010 17:15:16
VBASE018.VDF : 7.10.3.200 2048 Bytes 04.02.2010 17:15:16
VBASE019.VDF : 7.10.3.201 2048 Bytes 04.02.2010 17:15:16
VBASE020.VDF : 7.10.3.202 2048 Bytes 04.02.2010 17:15:16
VBASE021.VDF : 7.10.3.203 2048 Bytes 04.02.2010 17:15:16
VBASE022.VDF : 7.10.3.204 2048 Bytes 04.02.2010 17:15:16
VBASE023.VDF : 7.10.3.205 2048 Bytes 04.02.2010 17:15:17
VBASE024.VDF : 7.10.3.206 2048 Bytes 04.02.2010 17:15:17
VBASE025.VDF : 7.10.3.207 2048 Bytes 04.02.2010 17:15:17
VBASE026.VDF : 7.10.3.208 2048 Bytes 04.02.2010 17:15:17
VBASE027.VDF : 7.10.3.209 2048 Bytes 04.02.2010 17:15:17
VBASE028.VDF : 7.10.3.210 2048 Bytes 04.02.2010 17:15:17
VBASE029.VDF : 7.10.3.211 2048 Bytes 04.02.2010 17:15:17
VBASE030.VDF : 7.10.3.212 2048 Bytes 04.02.2010 17:15:17
VBASE031.VDF : 7.10.3.219 64512 Bytes 05.02.2010 17:15:19
Engineversion : 8.2.1.160
AEVDF.DLL : 8.1.1.3 106868 Bytes 23.01.2010 15:40:17
AESCRIPT.DLL : 8.1.3.13 823674 Bytes 01.02.2010 17:15:10
AESCN.DLL : 8.1.4.0 127348 Bytes 27.01.2010 17:21:28
AESBX.DLL : 8.1.1.1 246132 Bytes 08.11.2009 06:38:44
AERDL.DLL : 8.1.3.4 479605 Bytes 29.12.2009 16:30:07
AEPACK.DLL : 8.2.0.5 422262 Bytes 14.01.2010 18:57:21
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 08.11.2009 06:38:38
AEHEUR.DLL : 8.1.1.5 2326901 Bytes 06.02.2010 17:15:39
AEHELP.DLL : 8.1.10.0 237942 Bytes 14.01.2010 18:56:40
AEGEN.DLL : 8.1.1.86 369012 Bytes 01.02.2010 17:15:09
AEEMU.DLL : 8.1.1.0 393587 Bytes 08.11.2009 06:38:26
AECORE.DLL : 8.1.11.1 184694 Bytes 01.02.2010 17:15:08
AEBB.DLL : 8.1.0.3 53618 Bytes 08.11.2009 06:38:20
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12.12.2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 26.08.2009 14:14:02
AVREP.DLL : 8.0.0.3 155905 Bytes 20.01.2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 05.12.2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24.03.2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30.01.2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28.01.2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02.02.2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05.12.2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15.05.2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 13.10.2009 11:25:47
Configuration settings for the scan:
Jobname.............................: ShlExt
Configuration file..................: C:\Users\Jinjael\AppData\Local\Temp\250cd180.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: off
Scan registry.......................: off
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Start of the scan: Sonntag, 7. Februar 2010 21:47
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Users\Jinjael\Documents\ICQ\******1\ReceivedFiles\*******3 J***\***.exe bekannt, kein Virus!
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
C:\Windows\System32\drivers\sptd.sys
[WARNING] The file could not be opened!
Beginning disinfection:
C:\Users\Jinjael\Documents\ICQ\******1\ReceivedFiles\*******3 J***\***.exe
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[WARNING] The file was ignored!
End of the scan: Sonntag, 7. Februar 2010 22:01
Used time: 12:52 Minute(s)
The scan has been done completely.
13081 Scanned directories
179317 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
3 Files cannot be scanned
179313 Files not concerned
1109 Archives were scanned
4 Warnings
2 Notes
|
_______________
Zitat:
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\apocalyps32.exe
|
Das macht mir sorgen - :O
Edit:
Wollte mit Virustotal alles irgendwie bei denn Reports erwähnte mal durchscannen lassen, stoße ich im Windows Ordner auf folgenden Ordner:
ap0calypse_B0CC6428
5,17MB, ich lösche vollständig.
Edit²:
Löschen nicht möglich, der Ordner kommt in Bruchteilen von Sekunden direkt wieder.
... gleiches mit der exe
Edit³:
Arghz, PC bis jetzt nicht neu gestartet, aber Programm schreibt sich immer wieder in den Systemstart rein :O