Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
WIN7 / Deinstallation von SpeedUpMyComputer / FixMyRegistry
Danke für die Schnelle Antwort,
So habe deine Anweisungen nun Befolgt und Poste dem Entsprechend nach den Schritten.
1. FIX Log
Zitat:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:01-05-2014
Ran by Mehmet at 2014-05-01 15:54:03 Run:2
Running from C:\Users\Mehmet\Desktop\New folder
Boot Mode: Normal
HKU\S-1-5-21-313780734-520731875-1683923912-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyComputer => Value not found.
HKU\S-1-5-21-313780734-520731875-1683923912-1000\Software\Microsoft\Windows\CurrentVersion\Run\\FixMyRegistry => Value not found.
"C:\Program Files\SmartTweak" => File/Directory not found.
"C:\Users\Mehmet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software" => File/Directory not found.
"C:\ProgramData\RegClean" => File/Directory not found.
"C:\Users\Mehmet\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe" => File/Directory not found.
"C:\Users\Mehmet\AppData\Local\Temp\*.exe" => File/Directory not found.
==== End of Fixlog ====
2 SystemLook
Zitat:
SystemLook 30.07.11 by jpshortstuff
Log created at 15:59 on 01/05/2014 by Mehmet
Administrator - Elevation successful
Additional scan result of Farbar Recovery Scan Tool (x86) Version:01-05-2014
Ran by Mehmet at 2014-05-01 16:03:54
Running from C:\Users\Mehmet\Desktop\New folder
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: ESET Smart Security 7.0 (Enabled - Out of date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Out of date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Kişisel güvenlik duvarı (Disabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ESET Smart Security (HKLM\...\{60E4EE37-9927-4985-A8DC-2F3459E57CFC}) (Version: 7.0.302.26 - ESET, spol s r. o.)
FixMyRegistry (HKLM\...\FixMyRegistry) (Version: 38.1 - SmartTweak Software) <==== ATTENTION
Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.)
Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Mozilla Firefox 28.0 (x86 tr) (HKLM\...\Mozilla Firefox 28.0 (x86 tr)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Name: Coprocessor
Description: Coprocessor
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Application errors:
==================
Error: (05/01/2014 03:57:34 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 03:15:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 03:06:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 02:32:33 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (05/01/2014 03:57:22 PM) (Source: Service Control Manager) (User: )
Description: The ESET Service service hung on starting.
Error: (05/01/2014 03:15:14 PM) (Source: Service Control Manager) (User: )
Description: The ESET Service service hung on starting.
Error: (05/01/2014 03:06:25 PM) (Source: Service Control Manager) (User: )
Description: The ESET Service service hung on starting.
Error: (05/01/2014 02:32:21 PM) (Source: Service Control Manager) (User: )
Description: The ESET Service service hung on starting.
Error: (05/01/2014 02:15:13 PM) (Source: Service Control Manager) (User: )
Description: The Update maucampo service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (05/01/2014 01:50:37 PM) (Source: Service Control Manager) (User: )
Description: The ESET Service service hung on starting.
Error: (05/01/2014 01:48:10 PM) (Source: Service Control Manager) (User: )
Description: The Application Experience service failed to start due to the following error:
%%1115
Error: (05/01/2014 01:48:10 PM) (Source: Service Control Manager) (User: )
Description: The Portable Device Enumerator Service service failed to start due to the following error:
%%1115
Error: (05/01/2014 01:48:10 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service failed to start due to the following error:
%%1069
Error: (05/01/2014 01:48:10 PM) (Source: Service Control Manager) (User: )
Description: The WinHttpAutoProxySvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
%%50
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
Microsoft Office Sessions:
=========================
Error: (05/01/2014 03:57:34 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 03:15:22 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 03:06:35 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/01/2014 02:32:33 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 59%
Total physical RAM: 1919.27 MB
Available physical RAM: 770.74 MB
Total Pagefile: 3838.55 MB
Available Pagefile: 2487.14 MB
Total Virtual: 2047.88 MB
Available Virtual: 1922.98 MB
Zum Thema WIN7 / Deinstallation von SpeedUpMyComputer / FixMyRegistry - Danke für die Schnelle Antwort,
So habe deine Anweisungen nun Befolgt und Poste dem Entsprechend nach den Schritten.
1. FIX Log
Zitat:
Fix result of Farbar Recovery Tool (FRST written - WIN7 / Deinstallation von SpeedUpMyComputer / FixMyRegistry...