![]() |
Avira Desktop lässt sich nicht öffnen/aktivieren Hallo, ich bin neu hier, verzeiht mir daher evtl. Fehler in der Beschreibung meines Problems: Avira Desktop lässt sich nicht mehr öffnen/aktivieren, es erscheint die Fehlermeldung:" Dieses Programm wurde durch eine Gruppenrichtlinie blockiert. Weitere Informationen erhalten Sie vom Systemadministrator." Alle Versuche, das Programm upzudaten sind gescheitert. Ich bin auf euer board gestossen, bitte um Hilfestellung und habe zumindest schon vom adware cleaner die log: # AdwCleaner v3.310 - Bericht erstellt am 30/09/2014 um 12:01:25 # Aktualisiert 12/09/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) # Benutzername : User - USER-PC # Gestartet von : C:\Users\User\Desktop\adwcleaner_3.310.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17280 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1p7bjhlk.default\prefs.js ] Zeile gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...] -\\ Google Chrome v [ Datei : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [6997 octets] - [03/07/2014 20:52:47] AdwCleaner[R1].txt - [7057 octets] - [03/07/2014 20:57:07] AdwCleaner[R2].txt - [1096 octets] - [03/07/2014 21:01:13] AdwCleaner[R3].txt - [1607 octets] - [30/09/2014 11:57:00] AdwCleaner[S0].txt - [6606 octets] - [03/07/2014 20:58:27] AdwCleaner[S1].txt - [1158 octets] - [03/07/2014 21:03:28] AdwCleaner[S2].txt - [1528 octets] - [30/09/2014 12:01:25] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1588 octets] ########## |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST.txt: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-10-2014 01 Additional:FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-10-2014 01 |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Scan mit Combofix
|
Fixlog.txt: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-10-2014 01 Ran by User at 2014-10-05 00:34:56 Run:1 Running from C:\Users\User\Desktop\scan\FRST-OlderVersion Loaded Profile: User (Available profiles: User & Matthis) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION ***************** HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. ==== End of Fixlog ==== C:/Combofix.txt: Combofix Logfile: Code: ComboFix 14-10-04.01 - User 05.10.2014 1:09.1.1 - x86 A36C5E4F47E84449FF07ED3517B43A31 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
mbam.txt: Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 06.10.2014 Suchlauf-Zeit: 02:10:13 Logdatei: MBMVerlaufsprotokoll.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.07.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: User Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 267503 Verstrichene Zeit: 13 Min, 39 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) adwcleaner.txt:AdwCleaner Logfile: Code: # AdwCleaner v3.311 - Bericht erstellt am 06/10/2014 um 02:37:23 JRT.txt: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.0 (10.05.2014:1) OS: Windows 7 Ultimate x86 Ran by User on 06.10.2014 at 2:50:37,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{03FB422F-F472-4C16-99AB-9BC8D87535D0} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{0A2F58E2-FA90-4D0B-842C-27FA44E36710} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{38F6359B-9092-43B2-8457-04E408EF4635} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{4FD5CCB0-23B6-4F07-8F72-ED93401E8B81} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{5884FB88-09D7-48A0-AADE-DB624C601514} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{58B2E08E-192B-474D-A628-1B74553DBBFA} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{69CCF396-3F64-4703-B82E-CCAD11B5C96D} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{7EE90DA3-8D8D-4E4E-9856-3538B37FCB7B} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{93026D5B-8959-4A40-A9C5-537BF29790AD} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{9D444775-B8CC-443D-B5D9-81E9AD370AA4} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{A384C846-3A79-4692-B3AB-0B180E4B4170} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{B5707ACC-FCEE-4DAE-A4BD-DCC8D2716F66} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{B7AD923C-5F87-4EF8-8B7F-B5F7173D92F6} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{D41C06D5-07A4-472B-8916-1F7A43DE0612} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{D984156A-0579-4CEE-B0E9-DF84ADD4E9B7} Successfully deleted: [Empty Folder] C:\Users\User\appdata\local\{E7DDE88A-5FD9-4ACE-9942-4B66EB654777} ~~~ FireFox Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\1p7bjhlk.default\minidumps [23 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06.10.2014 at 2:53:46,27 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-10-2014 01 |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESET Logfile: ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=58b472f1bf999149b3bb8feb17562977 # engine=20472 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-07 01:19:53 # local_time=2014-10-07 03:19:53 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 180026 157143967 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 50235 164275984 0 0 # scanned=132817 # found=1 # cleaned=0 # scan_time=3679 sh=AEE0B5F1AE8564D7E4CCD032EDF7AD88339BFF4E ft=1 fh=88c3bdc65b0afccf vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\Documents\KameraSony\Sony_Cyber-shot_DSC-F707_Treiber_Update_03-2014.exe" Security Check txt: Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x86 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` CCleaner JavaFX 2.1.1 Java 7 Update 60 Java version out of Date! Adobe Flash Player 11.5.502.146 Flash Player out of Date! Adobe Reader 10.1.2 Adobe Reader out of Date! Mozilla Firefox (30.0) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Frisches FRST: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-10-2014 01 Frische Addition: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 06-10-2014 01 Ran by User at 2014-10-07 11:50:46 Running from C:\Users\User\Desktop\scan\FRST-OlderVersion Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.22beta (HKLM\...\7-Zip) (Version: - ) Ace of WAV (HKLM\...\Ace of WAV) (Version: - ) Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.1.102.63 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.5.502.146 - Adobe Systems Incorporated) Adobe Reader X (10.1.2) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.2 - Adobe Systems Incorporated) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira) cars2 (HKLM\...\{FF10D622-7BFE-48C6-8DF6-40D8CB1D3C1B}) (Version: 1.00.0000 - Disney Interactive Studios) CCleaner (HKLM\...\CCleaner) (Version: 3.17 - Piriform) Conexant HDA D330 MDC V.92 Modem (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F) (Version: - ) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1007.115.102 - ALPS ELECTRIC CO., LTD.) Dropbox (HKCU\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.) ElsterFormular (HKLM\...\ElsterFormular) (Version: 15.2.20140326 - Landesfinanzdirektion Thüringen) Free YouTube to MP3 Converter version 3.12.32.327 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.32.327 - DVDVideoSoft Ltd.) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden HUAWEI DataCard Driver 4.22.19.00 (HKLM\...\HUAWEI DataCard Driver) (Version: 4.22.19.00 - Huawei technologies Co., Ltd.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Intel(R) PROSet/Wireless Software (HKLM\...\ProInst) (Version: 11.01.0000 - Intel Corporation) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle) Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) K-Lite Codec Pack 8.6.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 8.6.0 - ) Kronen-Design 1.10 (HKLM\...\Kronen-Design 1.10_is1) (Version: - ) Kronen-Design 1.77 (HKLM\...\Kronen-Design_is1) (Version: - ) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Marvell Miniport Driver (HKLM\...\{C950420B-4182-49EA-850A-A6A2ABF06C6B}) (Version: 10.22.6.3 - Marvell) mCore (Version: 9.24.0000 - Intel Corporation) Hidden mDriver (Version: 9.24.0000 - Intel) Hidden mHelp (Version: 9.24.0000 - Intel) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2000 SR-1 Small Business (HKLM\...\{00030407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.3821 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) mMHouse (Version: 9.24.0000 - Intel Corporation) Hidden Modem-Diagnose-Tool (HKLM\...\{F63A3748-B93D-4360-9AD4-B064481A5C7B}) (Version: 1.0.20.0 - Dell) Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) mPfMgr (Version: 9.24.0000 - Intel Corporation) Hidden mWMI (Version: 9.24.0000 - Intel Corporation) Hidden QuickTime (HKLM\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.) RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.51.01 - ) Shockwave (HKLM\...\Shockwave) (Version: - ) SigmaTel Audio (HKLM\...\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}) (Version: 5.10.5210.0 - SigmaTel) Sonic Foundry ACID 4.0 (HKLM\...\{2A38B5AA-EA84-4F87-9937-2FB23982243A}) (Version: 4.0.215 - Sonic Foundry) Sonic Foundry Sound Forge 6.0e (HKLM\...\{B3DE6A9E-1FD0-4208-92F4-EC9004E34774}) (Version: 6.0.237 - Sonic Foundry) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Test Tone Generator 4.4 (HKLM\...\A9CD4C7D-6D93-4B56-A226-1D28DB060A87_is1) (Version: - Timo Esser) TP-LINK TL-WN721N_TL-WN722N Driver (HKLM\...\{86A7EED0-02D0-4D91-8183-8D2F23F5E6AE}) (Version: 1.3.1 - TP-LINK) VLC media player 2.0.8 (HKLM\...\VLC media player) (Version: 2.0.8 - VideoLAN) winLAME 2010 beta 1 (HKLM\...\{63C16E81-327C-49B6-9643-4F5EFD8A6B2D}) (Version: 1.0.2010.1 - Michael Fink) WM Converter 2.0 (HKLM\...\WM Converter 2.0) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{20DD1B9E-87C4-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{232E456A-87C3-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{38911D8E-E448-11D0-84A3-00DD01104159}\InprocServer32 -> C:\Windows\system32\comct332.ocx (Microsoft Corporation ) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{38911D90-E448-11D0-84A3-00DD01104159}\InprocServer32 -> C:\Windows\system32\comct332.ocx (Microsoft Corporation ) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{38911D92-E448-11D0-84A3-00DD01104159}\InprocServer32 -> C:\Windows\system32\comct332.ocx (Microsoft Corporation ) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6352-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6353-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6354-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6355-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6356-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6357-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{586A6359-87C8-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{603C7E80-87C2-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{B09DE715-87C1-11D1-8BE3-0000F8754DA1}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FE38753A-44A3-11D1-B5B7-0000C09000C4}\InprocServer32 -> C:\Windows\system32\mscomct2.ocx (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-202807160-4012287017-4108981099-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\User\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File ==================== Restore Points ========================= 07-10-2014 01:47:57 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {67B17EBC-79F0-4738-9EA8-A056FD80258C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe Task: {84F5DE67-9EC3-40B7-A515-04DEEE888EBC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-22] (Google Inc.) Task: {8CA8E105-B78D-4C82-9957-A927D204FF90} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C83813FA-300A-4C7C-B827-1B1054EBD647} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-22] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2007-04-25 11:55 - 2007-04-25 11:55 - 01167360 _____ () C:\Program Files\Intel\Wireless\Bin\acAuth.dll 2007-07-25 17:25 - 2007-07-25 17:25 - 00118784 _____ () C:\Program Files\Intel\Wireless\Bin\IWMSPROV.DLL 2012-04-25 19:39 - 2012-03-22 19:58 - 06593993 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\avcodec-lav-54.dll 2012-04-25 19:39 - 2012-03-22 19:58 - 00207835 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\avutil-lav-51.dll 2012-04-25 19:39 - 2012-03-22 20:00 - 03471360 _____ () C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax 2012-04-25 19:39 - 2012-03-22 19:58 - 00374115 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\swscale-lav-2.dll 2012-04-25 19:39 - 2012-03-22 19:58 - 00143974 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\avfilter-lav-2.dll 2014-10-06 11:11 - 2014-10-06 11:11 - 00043008 _____ () c:\users\user\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp8seoi_.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\User\AppData\Roaming\Dropbox\bin\libcef.dll 2012-04-25 19:39 - 2012-03-22 19:58 - 01183264 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\avformat-lav-54.dll 2012-04-25 19:39 - 2012-03-22 19:58 - 00172032 _____ () C:\Program Files\K-Lite Codec Pack\Filters\LAV\libbluray.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:5D432CE3 AlternateDataStreams: C:\Users\User\Desktop\2008-07-27 05.14.55.jpg:com.dropbox.attributes ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-202807160-4012287017-4108981099-500 - Administrator - Disabled) Gast (S-1-5-21-202807160-4012287017-4108981099-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-202807160-4012287017-4108981099-1004 - Limited - Enabled) Matthis (S-1-5-21-202807160-4012287017-4108981099-1002 - Limited - Enabled) => C:\Users\Matthis User (S-1-5-21-202807160-4012287017-4108981099-1000 - Administrator - Enabled) => C:\Users\User ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/06/2014 11:08:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (10/06/2014 09:03:36 PM) (Source: NetBT) (EventID: 4319) (User: ) Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error: (10/06/2014 09:03:13 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 10.0.1.80 registriert werden. Der Computer mit IP-Adresse 10.0.1.96 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (10/06/2014 08:46:28 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "NONAME-E135", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{EDD4EE35-45FC-40AC-BA89-BB0FAF-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (10/06/2014 07:40:06 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (10/06/2014 11:08:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 560 @ 2.13GHz Percentage of memory in use: 55% Total physical RAM: 2038.04 MB Available physical RAM: 911.15 MB Total Pagefile: 4076.09 MB Available Pagefile: 2547.96 MB Total Virtual: 2047.88 MB Available Virtual: 1890.42 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:48.83 GB) (Free:18.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:62.96 GB) (Free:19.04 GB) NTFS Drive f: (INTENSO) (Removable) (Total:3.71 GB) (Free:0.05 GB) FAT32 Drive h: (HP_RECOVERY) (Fixed) (Total:6.2 GB) (Free:0.77 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive i: (Musik/Backup) (Fixed) (Total:66.77 GB) (Free:2.95 GB) NTFS Drive j: (OS_TOOLS) (Fixed) (Total:1.55 GB) (Free:1.29 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 000CFB8F) Partition 1: (Active) - (Size=48.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=63 GB) - (Type=07 NTFS) Attempted reading MBR returned 0 bytes. Could not read MBR for disk 1. ======================================================== Disk: 2 (Size: 74.5 GB) (Disk ID: C024ECFB) Partition 1: (Active) - (Size=66.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=6.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=1.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ So, erstmal vielen Dank für die Hilfe, ich melde mich nochmal, wenn alles läuft. Wie beim Doktor: "Was hat er denn nun gehabt?" Grüsse |
Java, Flash und Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: GroupPolicyUsers\S-1-5-21-202807160-4012287017-4108981099-1002\User: Group Policy restriction detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Hallo Schrauber, ich werde in den kommenden Tagen alles mal checken und mich nochmal melden, wie's gelaufen ist. Vielen Dank für deine Mühe und die Tips am Rande! Letztes FRST: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-10-2014 01 Ran by User at 2014-10-08 13:59:51 Run:2 Running from C:\Users\User\Desktop\scan Loaded Profile: User (Available profiles: User & Matthis) Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicyUsers\S-1-5-21-202807160-4012287017-4108981099-1002\User: Group Policy restriction detected <======= ATTENTION ***************** C:\Windows\system32\GroupPolicyUsers\S-1-5-21-202807160-4012287017-4108981099-1002\User => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Hallo Schrauber, nach einigem hin und her hier nun die hoffentlich letzte Fixlog: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-10-2014 01 Ran by User at 2014-10-08 21:15:09 Run:1 Running from C:\Users\User\Desktop Loaded Profile: User (Available profiles: User & Matthis) Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicyUsers\S-1-5-21-202807160-4012287017-4108981099-1002\User: Group Policy restriction detected <======= ATTENTION ***************** "C:\Windows\system32\GroupPolicyUsers\S-1-5-21-202807160-4012287017-4108981099-1002\User" => File/Directory not found. ==== End of Fixlog ==== und noch den DelFix.txt: # DelFix v10.8 - Datei am 08/10/2014 um 20:47:06 erstellt # Aktualisiert am 29/07/2014 von Xplode # Benutzer : User - USER-PC # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\Qoobox Gelöscht : C:\FRST Gelöscht : C:\AdwCleaner Gelöscht : C:\Users\User\Desktop\uninstall.exe.exe Gelöscht : C:\ComboFix.txt Gelöscht : C:\Windows\grep.exe Gelöscht : C:\Windows\PEV.exe Gelöscht : C:\Windows\NIRCMD.exe Gelöscht : C:\Windows\MBR.exe Gelöscht : C:\Windows\SED.exe Gelöscht : C:\Windows\SWREG.exe Gelöscht : C:\Windows\SWSC.exe Gelöscht : C:\Windows\SWXCACLS.exe Gelöscht : C:\Windows\Zip.exe Gelöscht : HKLM\SOFTWARE\AdwCleaner Gelöscht : HKLM\SOFTWARE\Swearware Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #344 [Removed TP-LINK Wireless Configuration Utility and Driver | 10/08/2014 13:18:12] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## Combofix hat sich nicht von alleine verzogen, da musste ich nachhelfen. Ich hoffe, das war's. Vielen Dank für deine Hilfe, ich halt mich an Mozilla und deine tips zu den add-ons. Grüsse ins Netz, Gero |
Gern Geschehen :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 07:45 Uhr. |
Copyright ©2000-2025, Trojaner-Board