![]() |
|
Log-Analyse und Auswertung: Windows 7 - Home 64bit - Computer total verseuchtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #4 |
| ![]() Windows 7 - Home 64bit - Computer total verseucht zunächst mal besten dank für die schnelle Hilfe. Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-07-2014 01 Ran by SYSTEM at 2014-07-23 17:15:50 Run:1 Running from J:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** start HKLM Group Policy restriction on software: C:\Program Files\Microsoft Security Client <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Malwarebytes' Anti-Malware <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Spyware Terminator <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Microsoft Security Client <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Spyware Terminator <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Malwarebytes <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira <====== ATTENTION HKU\Reinhard\...\Run: [AbvaSquz] => regsvr32.exe "C:\ProgramData\AbvaSquz.dat" HKU\Reinhard\...\Run: [UmahMiri] => regsvr32.exe "C:\ProgramData\UmahMiri.dat" HKU\Reinhard\...\Run: [OrexFuyu] => regsvr32.exe "C:\ProgramData\OrexFuyu.dat" HKU\Reinhard\...\Run: [AbziRequ] => regsvr32.exe "C:\ProgramData\AbziRequ\AbziRequ.dat" HKU\Reinhard\...\Run: [OjimIxos] => regsvr32.exe "C:\ProgramData\OjimIxos\OjimIxos.dat" HKU\Reinhard\...\Run: [UcipCojy] => regsvr32.exe "C:\ProgramData\UcipCojy\UcipCojy.dat" HKU\Reinhard\...\Run: [EtfaqDexle] => regsvr32.exe "C:\ProgramData\EtfaqDexle\EtfaqDexle.dat" HKU\Reinhard\...\Run: [UjzirAhobf] => regsvr32.exe "C:\ProgramData\UjzirAhobf\UjzirAhobf.dat" HKU\Reinhard\...\Run: [AxugAyaff] => regsvr32.exe "C:\ProgramData\AxugAyaff\AxugAyaff.dat" C:\ProgramData\AbvaSquz.dat C:\ProgramData\UmahMiri.dat C:\ProgramData\OrexFuyu.dat C:\ProgramData\AbziRequ C:\ProgramData\OjimIxos C:\ProgramData\UcipCojy C:\ProgramData\EtfaqDexle C:\ProgramData\UjzirAhobf C:\ProgramData\AxugAyaff Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aranna.exe () Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aranna.exe () Startup: C:\Users\Reinhard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk ShortcutTarget: explorer.lnk -> C:\ProgramData\08B831C8C5C95390B72EFDBE2D83C48A\9fl8eek.cpp () S2 Winmgmt; C:\ProgramData\08B831C8C5C95390B72EFDBE2D83C48A\kee8lf9.dot [333556 2014-05-24] (Microsoft Corporation) C:\ProgramData\08B831C8C5C95390B72EFDBE2D83C48A C:\Users\Reinhard\Downloads\gggggggggggggggggggggggggggggggggggg.exe C:\Users\Reinhard\Downloads\setup.exe C:\ProgramData\69C67EF23B9CD73186992916CB237AD7 C:\Program Files (x86)\Google\Desktop\Install C:\ProgramData\ozouei.dat C:\ProgramData\vjrbeqv.dat C:\ProgramData\vqnwam.dat end ***************** HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\AbvaSquz => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\UmahMiri => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\OrexFuyu => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\AbziRequ => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\OjimIxos => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\UcipCojy => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\EtfaqDexle => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\UjzirAhobf => value deleted successfully. HKU\Reinhard\Software\Microsoft\Windows\CurrentVersion\Run\\AxugAyaff => value deleted successfully. C:\ProgramData\AbvaSquz.dat => Moved successfully. C:\ProgramData\UmahMiri.dat => Moved successfully. C:\ProgramData\OrexFuyu.dat => Moved successfully. C:\ProgramData\AbziRequ => Moved successfully. C:\ProgramData\OjimIxos => Moved successfully. C:\ProgramData\UcipCojy => Moved successfully. C:\ProgramData\EtfaqDexle => Moved successfully. C:\ProgramData\UjzirAhobf => Moved successfully. C:\ProgramData\AxugAyaff => Moved successfully. C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aranna.exe => Moved successfully. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aranna.exe not found. C:\Users\Reinhard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk => Moved successfully. C:\ProgramData\08B831C8C5C95390B72EFDBE2D83C48A\9fl8eek.cpp => Moved successfully. Winmgmt => Service restored successfully. C:\ProgramData\08B831C8C5C95390B72EFDBE2D83C48A => Moved successfully. C:\Users\Reinhard\Downloads\gggggggggggggggggggggggggggggggggggg.exe => Moved successfully. C:\Users\Reinhard\Downloads\setup.exe => Moved successfully. C:\ProgramData\69C67EF23B9CD73186992916CB237AD7 => Moved successfully. C:\Program Files (x86)\Google\Desktop\Install => Moved successfully. C:\ProgramData\ozouei.dat => Moved successfully. C:\ProgramData\vjrbeqv.dat => Moved successfully. C:\ProgramData\vqnwam.dat => Moved successfully. ==== End of Fixlog ==== Deinstallstion von so tollen programmen wie: Winzipper und v9 funktioniert leider weiterhin nicht. Geändert von Escor (23.07.2014 um 17:21 Uhr) Grund: Nachtrag |
Themen zu Windows 7 - Home 64bit - Computer total verseucht |
adobe, antivir, askbar, avg, avira, computer, desktop, google, hijack, hijackthis, home, kaputt, realtek, registry, rundll, scan, security, services.exe, software, spyware, svchost.exe, symantec, system, temp, usb, windows |