|
Plagegeister aller Art und deren Bekämpfung: whilokii entfernenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.11.2014, 13:15 | #16 |
/// the machine /// TB-Ausbilder | whilokii entfernen Java und Adobe updaten. MBAM Funde löschen lassen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.11.2014, 21:51 | #17 |
| whilokii entfernen Hey,
__________________hier die files: FRST fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-11-2014 Ran by Julia in Aktion at 2014-11-11 21:38:48 Run:1 Running from C:\Users\Julia in Aktion\Rest\Downloads Loaded Profile: Julia in Aktion (Available profiles: Julia & Julia in Aktion & Gast) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Emptytemp: ***************** "C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5" directory move: Could not move "C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5\maintainer.bak" => Scheduled to move on reboot. Could not move "C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5\maintainer.exe" => Scheduled to move on reboot. Could not move "C:\ProgramData\d9ce53a2-5b0a-4d8e-9021-3efb72b12cd5" directory. => Scheduled to move on reboot. "C:\Windows\system32\GroupPolicy\Machine" directory move: Could not move "C:\Windows\system32\GroupPolicy\Machine\Registry.pol" => Scheduled to move on reboot. Could not move "C:\Windows\system32\GroupPolicy\Machine" directory. => Scheduled to move on reboot. Could not move "C:\Windows\system32\GroupPolicy\GPT.ini" => Scheduled to move on reboot. "HKLM\SOFTWARE\Policies\Google" => Error deleting key. The key could be protected. EmptyTemp: => Removed 2.2 GB temporary data. Code:
ATTFilter Farbar Service Scanner Version: 21-07-2014 Ran by Julia in Aktion (ATTENTION: The logged in user is not administrator) on 11-11-2014 at 21:48:55 Running from "C:\Users\Julia in Aktion\Rest\Downloads" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Action Center: ============ wscsvc Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => File is digitally signed C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed C:\Windows\System32\dhcpcore.dll => File is digitally signed C:\Windows\System32\drivers\afd.sys => File is digitally signed C:\Windows\System32\drivers\tdx.sys => File is digitally signed C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed C:\Windows\System32\dnsrslvr.dll => File is digitally signed C:\Windows\System32\mpssvc.dll => File is digitally signed C:\Windows\System32\bfe.dll => File is digitally signed C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed C:\Windows\System32\SDRSVC.dll => File is digitally signed C:\Windows\System32\vssvc.exe => File is digitally signed C:\Windows\System32\wscsvc.dll => File is digitally signed C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed C:\Windows\System32\wuaueng.dll => File is digitally signed C:\Windows\System32\qmgr.dll => File is digitally signed C:\Windows\System32\es.dll => File is digitally signed C:\Windows\System32\cryptsvc.dll => File is digitally signed C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed C:\Windows\System32\ipnathlp.dll => File is digitally signed C:\Windows\System32\iphlpsvc.dll => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed **** End of log **** |
12.11.2014, 19:13 | #18 |
/// the machine /// TB-Ausbilder | whilokii entfernen Nö kannste behalten
__________________
Frisches FRST log bitte. Noch Probleme?
__________________ |