![]() |
|
Log-Analyse und Auswertung: Windows Vista: Verseuchtes RTF geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #11 |
| ![]() Windows Vista: Verseuchtes RTF geöffnet Hallo! ![]() 1.) Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:21-06-2014 01 Ran by hoppy at 2014-06-22 13:54:14 Run:1 Running from C:\Users\hoppy\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start C:\Users\hoppy\Downloads\wzmp_8.exe Task: {0D916954-D865-40D2-B14D-3BB01121FA64} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION Task: {8811A628-62B5-48C7-91D9-879B017C5BBD} - System32\Tasks\4741 => Wscript.exe C:\Users\hoppy\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION Reboot: end ***************** C:\Users\hoppy\Downloads\wzmp_8.exe => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0D916954-D865-40D2-B14D-3BB01121FA64}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D916954-D865-40D2-B14D-3BB01121FA64}' => Key deleted successfully. C:\Windows\System32\Tasks\0 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8811A628-62B5-48C7-91D9-879B017C5BBD}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8811A628-62B5-48C7-91D9-879B017C5BBD}' => Key deleted successfully. C:\Windows\System32\Tasks\4741 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4741' => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 14:40 on 22/06/2014 by hoppy Administrator - Elevation successful ========== folderfind ========== Searching for "*Winzip Malware Protector*" C:\Users\hoppy\AppData\Roaming\Nico Mak Computing\WinZip Malware Protector d------ [11:52 15/06/2014] C:\zoek_backup\C_Program Files_WinZip Malware Protector d-a---- [19:14 21/06/2014] C:\zoek_backup\C_PROGRA~2_Nico Mak Computing_WinZip Malware Protector d-a---- [19:14 21/06/2014] ========== regfind ========== Searching for "Winzip Malware Protector" [HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip Malware Protector] [HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip Malware Protector] "InstalledPath"="C:\Program Files\WinZip Malware Protector" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe"="WinZip Malware Protector" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\unins000.exe"="Setup/Uninstall" [HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Malware Protector] [HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Malware Protector] "InstalledPath"="C:\Program Files\WinZip Malware Protector" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\WinZip Malware Protector] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Eventlog\Application\WinZip Malware Protector] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinZip Malware Protector] [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001\Software\Nico Mak Computing\WinZip Malware Protector] [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001\Software\Nico Mak Computing\WinZip Malware Protector] "InstalledPath"="C:\Program Files\WinZip Malware Protector" [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe"="WinZip Malware Protector" [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\unins000.exe"="Setup/Uninstall" [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe"="WinZip Malware Protector" [HKEY_USERS\S-1-5-21-585729200-1109542704-3709798812-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\WinZip Malware Protector\unins000.exe"="Setup/Uninstall" -= EOF =- 4.) checkup.txt: Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` ESET Smart Security 7.0 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 51 Java version out of Date! Adobe Flash Player 13.0.0.214 Adobe Reader 8 Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` ESET NOD32 Antivirus egui.exe ESET NOD32 Antivirus ekrn.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Nach Fixlog hatte ich wieder Rebootprobleme, ging nur mit CD und dauerte sehr lange. Danke! Hi Matthias! Wollte den PC noch einmal starten um zu sehen, ob die letzten Aktionen Erfolg gebracht haben. Jetzt geht leider überhaupt nichts mehr. ![]() Blauer Bildschirm und folgende Meldung: A Problem has been detected and windows has been shut down to prevent damage to your computer. DRIVER_POWER_STATE_FAILURE If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follw these steps: Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any windows updates you might need. I problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode. Technical Information: *** STOP: 0x0000009F (0x00000003, 0x8DE33BB0, 0x8DE33BB0, 0x8E747008) Warmstart funktioniert nicht, kann maximal den Stecker ziehen, will aber nicht mehr kaputt machen, als eh schon ist. Kannst du mir bitte weiterhelfen? OK, Knöpfchen gedrückt und nach dem 6. Versuch wieder drinnen. Stelle jetzt nur mehr auf Standby. |
Themen zu Windows Vista: Verseuchtes RTF geöffnet |
4d36e972-e325-11ce-bfc1-08002be10318, association, canon, converter, desktop, device driver, email, error, excel, failed, fehler, flash player, home, iexplore.exe, installation, launch, mozilla, netzwerk, performance, registry, rundll, scan, security, senden, software, starten, svchost.exe, system, vista, windows, wscript.exe |