![]() |
|
Plagegeister aller Art und deren Bekämpfung: Fehlermeldung beim Start des LaptopsWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #16 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fehlermeldung beim Start des Laptops Was machen die Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #17 |
![]() | ![]() Fehlermeldung beim Start des Laptops Leider immer noch das gleiche :/
__________________ |
![]() | #18 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fehlermeldung beim Start des Laptops Immer noch diese Fehlermeldung?
__________________
__________________ |
![]() | #19 |
![]() | ![]() Fehlermeldung beim Start des Laptops ja, ich schreib sie nochmal schnell ab. ( Ist jetzt aber nur noch 1x gekommen sonst waren es 3x dann 2x.) Problem beim Starten von C:\PROGRA~1\COMMON~1\System\SysMenu.dll Das angegebene Modul wurde nicht gefunden. |
![]() | #20 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fehlermeldung beim Start des Laptops Gibts doch nit ![]() Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #21 |
![]() | ![]() Fehlermeldung beim Start des Laptops Gibts leider doch ![]() SystemLook 30.07.11 by jpshortstuff Log created at 14:31 on 03/03/2014 by Tom Administrator - Elevation successful ========== filefind ========== Searching for "SysMenu.dll" No files found. ========== regfind ========== Searching for "SysMenu" [HKEY_CURRENT_USER\Software\Classes\*\ShellEx\ContextMenuHandlers\SysMenuExt] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SysMenu.DLL] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}] @="SysMenu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\SysMenu.DLL] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}] @="SysMenu" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\SysMenu.DLL] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}] @="SysMenu" [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001\Software\Classes\*\ShellEx\ContextMenuHandlers\SysMenuExt] [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001_Classes\*\ShellEx\ContextMenuHandlers\SysMenuExt] Searching for " " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Code] "AppJavaScript"=" /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: Documentation *************************************************************************************/ HOST = "hxxp://wt.iwebar.com"; TOOLBAR_URL = HOST + '/js/toolbar.js'; AFFILIATE_ID = 'NONE'; appAPI.ready(function($) { /* if (appAPI.db.get('user_id') === null) { if (appAPI.db.get('installation') === null){ appAPI.db.set('installation', new Date().getTime()); return; } else { if ((new Date().getTime() - appAPI.db.get('installation')) < 1000 * 60 * 60 * 48){ //No need to display toolbar... hasn't been 2 days yet. return; } } }*/ console.log("=======> Extension [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Db\Internal\Resources_resource_183015] "Value"=""/*\n\nCopyright (C) 2011 by Yehuda Katz\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in\nall copies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{EA7831AD-D662-402E-8537-75BB7D5ADE38}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{5B39D1B8-ED49-4055-8A47-04B29A579AD6}" ratingID="{11F7079A-563B-4a4c-9478-156F615A78DE}"/> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{78D8CC82-372F-44e4-B70C-8944DB7BCC24}"/> <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{75AEE0A2-8640-4a20-8DE5-EC93D8DAB219}"/> </Ratings>" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;RM)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Reso [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell.Workflow] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell.workflow" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" UseSharedProcess="true" ProcessIdleTimeoutSec="1209600" RunAsUser="" RunAsPassword="" AutoRestart="false" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> <Param Name="AssemblyName" Value="Microsoft.PowerShell.Workflow.ServiceCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=MSIL"/> <Param Name="PSSessionConfigurationTypeName" Value="Microsoft.PowerShell.Workflow.PSWorkflowSessionConfiguration"/> <Param Name="SessionConfigurationData" Value=" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" Architecture="32" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;RM)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SWD\WPDBUSENUM\{9a7f7b38-9fdc-11e3-bec0-24fd52154251}#0000000000007E00] "DeviceDesc"="0PLA380 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SWD\WPDBUSENUM\{9a7f7ca9-9fdc-11e3-bec0-24fd52154251}#0000000000007E00] "DeviceDesc"="0AS " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SWD\WPDBUSENUM\{9a7f7b38-9fdc-11e3-bec0-24fd52154251}#0000000000007E00] "DeviceDesc"="0PLA380 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SWD\WPDBUSENUM\{9a7f7ca9-9fdc-11e3-bec0-24fd52154251}#0000000000007E00] "DeviceDesc"="0AS " [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Code] "AppJavaScript"=" /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: Documentation *************************************************************************************/ HOST = "hxxp://wt.iwebar.com"; TOOLBAR_URL = HOST + '/js/toolbar.js'; AFFILIATE_ID = 'NONE'; appAPI.ready(function($) { /* if (appAPI.db.get('user_id') === null) { if (appAPI.db.get('installation') === null){ appAPI.db.set('installation', new Date().getTime()); return; } else { if ((new Date().getTime() - appAPI.db.get('installation')) < 1000 * 60 * 60 * 48){ //No need to display toolbar... hasn't been 2 days yet. return; } } [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Db\Internal\Resources_resource_183015] "Value"=""/*\n\nCopyright (C) 2011 by Yehuda Katz\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in\nall copies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PAR [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Code] "AppJavaScript"=" /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: Documentation *************************************************************************************/ HOST = "hxxp://wt.iwebar.com"; TOOLBAR_URL = HOST + '/js/toolbar.js'; AFFILIATE_ID = 'NONE'; appAPI.ready(function($) { /* if (appAPI.db.get('user_id') === null) { if (appAPI.db.get('installation') === null){ appAPI.db.set('installation', new Date().getTime()); return; } else { if ((new Date().getTime() - appAPI.db.get('installation')) < 1000 * 60 * 60 * 48){ //No need to display toolbar... hasn't been 2 days yet. return; } } }*/ c [HKEY_USERS\S-1-5-21-1714481637-1342907066-1217133146-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar\Db\Internal\Resources_resource_183015] "Value"=""/*\n\nCopyright (C) 2011 by Yehuda Katz\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in\nall copies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR P -= EOF =- |
![]() | #22 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fehlermeldung beim Start des Laptops Kopiere den Text in der Codebox in deinen Editor (z.B. Notepad) und speichere es unter dem Namen regfix.reg (bei Dateityp bitte "alle Dateien" wählen) Code:
ATTFilter Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SysMenu.DLL] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\SysMenu.DLL] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\SysMenu.DLL] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}]
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #23 |
![]() | ![]() Fehlermeldung beim Start des Laptops Hura!! Die Meldung ist weg, ich glaubs nicht. Danke dir ![]() ![]() |
![]() | #24 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fehlermeldung beim Start des Laptops Fertig ![]() Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |