![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Mail mit Makro-Viren von "dirk schirakowski und uwe schütze" geöffnetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Mail mit Makro-Viren von "dirk schirakowski und uwe schütze" geöffnet Dann schauen wir mal genau: Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #2 |
![]() | Mail mit Makro-Viren von "dirk schirakowski und uwe schütze" geöffnet Hi,
__________________habe ich gemacht, unten das Ergebnis - Viele Grüße Jolande Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff
Log created at 19:48 on 28/01/2015 by Brigitte Atrops
Administrator - Elevation successful
========== regfind ==========
Searching for "Pokki"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"DisplayIcon"=""%LOCALAPPDATA%\Pokki\Engine\HostAppService.exe",6"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"Publisher"="Pokki"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"UninstallString"=""%LOCALAPPDATA%\Pokki\Engine\HostAppService.exe" /UNINSTALLMENU"
[HKEY_CURRENT_USER\Software\Pokki]
[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shell\pokki]
[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shell\pokki]
@="Add to Pokki Menu"
[HKEY_CURRENT_USER\Software\Classes\Directory\shell\pokki]
[HKEY_CURRENT_USER\Software\Classes\Directory\shell\pokki]
@="Add to Pokki Menu"
[HKEY_CURRENT_USER\Software\Classes\Drive\shell\pokki]
[HKEY_CURRENT_USER\Software\Classes\Drive\shell\pokki]
@="Add to Pokki Menu"
[HKEY_CURRENT_USER\Software\Classes\lnkfile\shell\pokki]
[HKEY_CURRENT_USER\Software\Classes\lnkfile\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"DisplayIcon"=""%LOCALAPPDATA%\Pokki\Engine\HostAppService.exe",6"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"Publisher"="Pokki"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu]
"UninstallString"=""%LOCALAPPDATA%\Pokki\Engine\HostAppService.exe" /UNINSTALLMENU"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\AllFileSystemObjects\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\AllFileSystemObjects\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\Directory\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\Directory\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\Drive\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\Drive\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\lnkfile\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001\Software\Classes\lnkfile\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\AllFileSystemObjects\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\AllFileSystemObjects\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\Directory\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\Directory\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\Drive\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\Drive\shell\pokki]
@="Add to Pokki Menu"
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\lnkfile\shell\pokki]
[HKEY_USERS\S-1-5-21-1639775452-4181559810-1420609367-1001_Classes\lnkfile\shell\pokki]
@="Add to Pokki Menu"
========== filefind ==========
Searching for "*Pokki*"
C:\SYSTEM.SAV\LOGS\PokkiInstall.log --a---- 26 bytes [13:40 28/07/2014] [13:40 28/07/2014] F3E76567156B8DE2B16E865853D54398
C:\SYSTEM.SAV\LOGS\wizinstallerPokki.log --a---- 902 bytes [13:40 28/07/2014] [13:40 28/07/2014] 4F45355F6AAA434D56F2BEBD5BBF602B
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\libPokki.dll --a---- 49324032 bytes [18:50 04/01/2015] [18:50 04/01/2015] 17CA4275F1F867181A67E0ADE24CC782
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\templates\pokkiApp.handlebars --a---- 511 bytes [04:07 04/01/2015] [04:07 04/01/2015] 9FBCA64AA76DF50BE494A33C3EBC8E18
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\views\pokkiApp.js --a---- 4908 bytes [04:07 04/01/2015] [04:07 04/01/2015] D382AE873AB82AE575910EF79F8EF018
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\installed_pokkies.db --a---- 7168 bytes [17:07 19/11/2014] [10:40 24/01/2015] 5005E98E1E88BB4DAA8D083D03601F7F
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\pokkistore.js --a---- 594 bytes [06:35 08/01/2015] [06:35 08/01/2015] 16FCB9D66D5E7D25F0A59D7AF809A306
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHelper.js --a---- 6470 bytes [06:35 08/01/2015] [06:35 08/01/2015] 82C56D3875D29FAF35867873F0761526
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHostedFramework-2.1.1.js --a---- 19835 bytes [06:35 08/01/2015] [06:35 08/01/2015] 7D60EFD1316202268585B90D28845883
C:\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHostedFramework-2.1.1.min.js --a---- 9448 bytes [06:35 08/01/2015] [06:35 08/01/2015] 80A4C29A34DA7768DDFC978E0777E53C
C:\Users\Brigitte Atrops\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Local Storage\http_www.pokki.com_0.localstorage --a---- 3072 bytes [17:49 02/01/2015] [17:49 02/01/2015] D6F3DADEB4DFE8B95543A0ADD4184561
C:\Users\Brigitte Atrops\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Local Storage\http_www.pokki.com_0.localstorage-journal --a---- 3608 bytes [17:49 02/01/2015] [17:49 02/01/2015] 529F316330D2EE55EC473DC0B64A89E6
C:\Users\Brigitte Atrops\AppData\Local\Temp\Pokki-2015-01-28.log --a---- 54848 bytes [08:31 28/01/2015] [13:42 28/01/2015] 92C5F1F36C83164402FB72A873314627
C:\Users\Default\AppData\Local\Pokki\Engine\libPokki.dll --a---- 49324544 bytes [13:40 28/07/2014] [03:01 26/02/2014] 46623D887E63DA6E37FC1B8E58ED0CCE
C:\Users\Default\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\templates\pokkiApp.handlebars --a---- 511 bytes [13:40 28/07/2014] [16:06 17/01/2014] 9FBCA64AA76DF50BE494A33C3EBC8E18
C:\Users\Default\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\views\pokkiApp.js --a---- 4908 bytes [13:40 28/07/2014] [18:21 24/02/2014] D382AE873AB82AE575910EF79F8EF018
C:\Users\Default\AppData\Local\Pokki\Pokkies\34e8f5c0c9e5744bf2cdb514283762dd0524776b\js\lib\pokkiHelper.js --a---- 6470 bytes [13:40 28/07/2014] [02:21 19/02/2014] 82C56D3875D29FAF35867873F0761526
C:\Users\Default\AppData\Local\Pokki\Pokkies\34e8f5c0c9e5744bf2cdb514283762dd0524776b\js\lib\pokkiHostedFramework-2.0.1.min.js --a---- 8227 bytes [13:40 28/07/2014] [02:21 19/02/2014] 1CB54942923BF83D9E34E26F6C76259B
C:\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\pokkistore.js --a---- 594 bytes [13:40 28/07/2014] [16:07 17/01/2014] 16FCB9D66D5E7D25F0A59D7AF809A306
C:\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHelper.js --a---- 6470 bytes [13:40 28/07/2014] [16:07 17/01/2014] 82C56D3875D29FAF35867873F0761526
C:\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHostedFramework-2.1.1.js --a---- 19835 bytes [13:40 28/07/2014] [16:07 17/01/2014] 7D60EFD1316202268585B90D28845883
C:\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHostedFramework-2.1.1.min.js --a---- 9448 bytes [13:40 28/07/2014] [16:06 17/01/2014] 80A4C29A34DA7768DDFC978E0777E53C
-= EOF =-
|
| | #3 |
![]() | Mail mit Makro-Viren von "dirk schirakowski und uwe schütze" geöffnet Hi,
__________________ich weiß nicht, ob ich beim letzten Mal nicht alles mitkopiert habe,- jetzt habe ich es jedenfalls noch Mal gemacht und darauf geachtet. Ich habe also genau folgendes in das Textfeld kopiert: :regfind Pokki :filefind *Pokki* (Einmal Pokki ohne Sternchen und einmal mit Sternchen?) Dabei kam folgender Systemlook-Text zustande: Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff
Log created at 13:17 on 01/02/2015 by Brigitte Atrops
Administrator - Elevation successful
========== regfind ==========
Searching for "Pokki"
No data found.
========== filefind ==========
Searching for "*Pokki*"
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\libPokki.dll.xBAD --a---- 49324032 bytes [18:50 04/01/2015] [18:50 04/01/2015] 17CA4275F1F867181A67E0ADE24CC782
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\templates\pokkiApp.handlebars.xBAD --a---- 511 bytes [04:07 04/01/2015] [04:07 04/01/2015] 9FBCA64AA76DF50BE494A33C3EBC8E18
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\views\pokkiApp.js.xBAD --a---- 4908 bytes [04:07 04/01/2015] [04:07 04/01/2015] D382AE873AB82AE575910EF79F8EF018
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\installed_pokkies.db.xBAD --a---- 7168 bytes [17:07 19/11/2014] [10:40 24/01/2015] 5005E98E1E88BB4DAA8D083D03601F7F
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\pokkistore.js.xBAD --a---- 594 bytes [06:35 08/01/2015] [06:35 08/01/2015] 16FCB9D66D5E7D25F0A59D7AF809A306
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHelper.js.xBAD --a---- 6470 bytes [06:35 08/01/2015] [06:35 08/01/2015] 82C56D3875D29FAF35867873F0761526
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHostedFramework-2.1.1.js.xBAD --a---- 19835 bytes [06:35 08/01/2015] [06:35 08/01/2015] 7D60EFD1316202268585B90D28845883
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\0b58b62e0b6796431f68bebf7ecc5506382a4481\js\lib\pokkiHostedFramework-2.1.1.min.js.xBAD --a---- 9448 bytes [06:35 08/01/2015] [06:35 08/01/2015] 80A4C29A34DA7768DDFC978E0777E53C
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Local Storage\http_www.pokki.com_0.localstorage-journal.xBAD --a---- 3608 bytes [17:49 02/01/2015] [17:49 02/01/2015] 529F316330D2EE55EC473DC0B64A89E6
C:\FRST\Quarantine\C\Users\Brigitte Atrops\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Local Storage\http_www.pokki.com_0.localstorage.xBAD --a---- 3072 bytes [17:49 02/01/2015] [17:49 02/01/2015] D6F3DADEB4DFE8B95543A0ADD4184561
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Engine\libPokki.dll --a---- 49324544 bytes [13:40 28/07/2014] [03:01 26/02/2014] 46623D887E63DA6E37FC1B8E58ED0CCE
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\templates\pokkiApp.handlebars --a---- 511 bytes [13:40 28/07/2014] [16:06 17/01/2014] 9FBCA64AA76DF50BE494A33C3EBC8E18
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Engine\sysapps\notifications\assets\scripts\platform\views\pokkiApp.js --a---- 4908 bytes [13:40 28/07/2014] [18:21 24/02/2014] D382AE873AB82AE575910EF79F8EF018
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\34e8f5c0c9e5744bf2cdb514283762dd0524776b\js\lib\pokkiHelper.js --a---- 6470 bytes [13:40 28/07/2014] [02:21 19/02/2014] 82C56D3875D29FAF35867873F0761526
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\34e8f5c0c9e5744bf2cdb514283762dd0524776b\js\lib\pokkiHostedFramework-2.0.1.min.js --a---- 8227 bytes [13:40 28/07/2014] [02:21 19/02/2014] 1CB54942923BF83D9E34E26F6C76259B
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\pokkistore.js --a---- 594 bytes [13:40 28/07/2014] [16:07 17/01/2014] 16FCB9D66D5E7D25F0A59D7AF809A306
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHelper.js --a---- 6470 bytes [13:40 28/07/2014] [16:07 17/01/2014] 82C56D3875D29FAF35867873F0761526
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHostedFramework-2.1.1.js --a---- 19835 bytes [13:40 28/07/2014] [16:07 17/01/2014] 7D60EFD1316202268585B90D28845883
C:\FRST\Quarantine\C\Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\js\lib\pokkiHostedFramework-2.1.1.min.js --a---- 9448 bytes [13:40 28/07/2014] [16:06 17/01/2014] 80A4C29A34DA7768DDFC978E0777E53C
C:\SYSTEM.SAV\LOGS\PokkiInstall.log --a---- 26 bytes [13:40 28/07/2014] [13:40 28/07/2014] F3E76567156B8DE2B16E865853D54398
C:\SYSTEM.SAV\LOGS\wizinstallerPokki.log --a---- 902 bytes [13:40 28/07/2014] [13:40 28/07/2014] 4F45355F6AAA434D56F2BEBD5BBF602B
C:\Users\Brigitte Atrops\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk --a---- 273 bytes [09:51 29/01/2015] [09:51 29/01/2015] 94F5F77F65ABC899FEF83D03BF1A831D
-= EOF =-
Ich bin jetzt bis Donnerstag unterwegs und nicht mehr hier am Rechner. Melde mich aber danach sofort wieder. Viele Grüße Jolande |
![]() |
| Themen zu Mail mit Makro-Viren von "dirk schirakowski und uwe schütze" geöffnet |
| angeblichen, arbeiten, aufgetaucht, bereits, datei, enthalten, enthält, gefunde, gen, konnte, mail, makro-viren, makros, offline, plötzlich, programme, rechner, scan, schütze, swapfile.sys, troja, trojaner, versehentlich, viren, virenscan, virus, warnung |