Faaabiiio | 10.06.2014 22:42 | worm.Zhelatin in C:\Windows\System32\fsvk.exe.exe Guten Abend,
Ich habe heute mit Hilfe eines Freundes festgestellt (über Malwarebytes), dass ich einen
worm.Zhelatin in C:\Windows\System32\fsvk.exe.exe
auf meinem System mit Windows 7 Home Premium 64bit habe.
:headbang:
In einem anderen Thread habe ich bereits etwas darüber gelesen, jedoch bin ich daraus auch nicht wirklich schlauer geworden. Dort stand nur, dass man den PC neu aufsetzen soll, was ich aber, sofern dies möglich ist verhindern möchte, da ich erstens sehr viele Dateien habe, die dadurch verloren gehen würden und zweitens beim Kauf des PCs keine Windows CD erhalten habe, sondern nur einen Key (falls Neuinstallation nicht zu verhindern wäre ich froh, wenn mir jemand erklären kann, wie das ohne eine CD funktioniert).
Hier noch das Log: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10.06.2014
Scan Time: 13:51:01
Logfile: worm_zhelatin_test.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.10.04
Rootkit Database: v2014.06.02.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Fabio
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 286029
Time Elapsed: 7 min, 43 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 2
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, 4644, Delete-on-Reboot, [04c83f37adce5adc86146fbbb34e1ae6]
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, 4656, Delete-on-Reboot, [705ce294354641f5465258d2956c7f81]
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.OptimizerPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\70e6ca8c, Quarantined, [ddef3c3a6318f3430fdbd365e61e17e9],
Registry Values: 0
(No malicious items detected)
Registry Data: 10
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Replaced,[1eaebbbbf6850d29e22986e140c458a8]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[428a6e087506e4528589b4b39371e31d]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[686444323546d46237c07cf4c4409f61]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[2f9dc9ad2952b284f31a9bccf50fcf31]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[08c45521a2d99a9c9e588fe19b6951af]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[f2da294d6c0f122468a87deaaf55f20e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[ab21aacc75060f276d8c9ed2f21212ee]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[dcf0344279021125c64bf0779470728e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (hxxp://www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[b616e88ee19ae84e04f6610f7490c53b]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1135877238-1570040499-2305132942-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fd6126cd-f1c2-e4e3-1556-2aff212d63b5&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=10/02/2014&type=hp1000),Delete-on-Reboot,[616b591ded8e191db9530067be46867a]
Folders: 3
PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy, Quarantined, [b3194e28334853e351346223a55df40c],
PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\EEB2EBA2411B4197833F9FAA22CB5138, Quarantined, [b3194e28334853e351346223a55df40c],
PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\F74DD1FA2D9C4A6D82AE42E0BF7B59AC, Quarantined, [b3194e28334853e351346223a55df40c],
Files: 6
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProCrash.exe, Delete-on-Reboot, [ddef3c3a6318f3430fdbd365e61e17e9],
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Delete-on-Reboot, [04c83f37adce5adc86146fbbb34e1ae6],
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, Delete-on-Reboot, [705ce294354641f5465258d2956c7f81],
PUP.Optional.Linkury.A, C:\Users\Fabio\AppData\Roaming\OpenCandy\EEB2EBA2411B4197833F9FAA22CB5138\Installer.exe, Quarantined, [547883f39be07cba3e24f446828212ee],
Worm.Zhelatin, C:\Windows\System32\fsvk.exe.exe, Quarantined, [ebe16c0ae19aac8a0517dc2733d044bc],
PUP.Optional.OpenCandy, C:\Users\Fabio\AppData\Roaming\OpenCandy\F74DD1FA2D9C4A6D82AE42E0BF7B59AC\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, Quarantined, [b3194e28334853e351346223a55df40c],
Physical Sectors: 0
(No malicious items detected)
(end) Ich bin leider nicht sehr erfahren was solche Dinge betrifft und hoffe, dass ihr mir dabei helfen könnt. Dies ist mein erster Beitrag hier ;)
Vielen Dank im Voraus,
Fabio |