Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Antiviren-, Firewall- und andere Schutzprogramme (https://www.trojaner-board.de/antiviren-firewall-andere-schutzprogramme/)
-   -   AntiVir Guard inaktiv, lässt sich nicht deinstallieren, startet immer wieder Setup (https://www.trojaner-board.de/86671-antivir-guard-inaktiv-laesst-deinstallieren-startet-immer-setup.html)

cosinus 07.06.2010 10:17

Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
O4 - HKLM..\Run: [AntivirusRegistration] C:\Programme\CA\Etrust Antivirus\Register.exe ()
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
:Files:
C:\Programme\Avira
C:\WINDOWS\system32\drivers\avipbb.sys
C:\WINDOWS\system32\drivers\avgntflt.sys
C:\WINDOWS\system32\drivers\ssmdrv.sys
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann auf den Button Run Fixes!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

multebeere 07.06.2010 10:30

Hi Arne,

hier das Logfile:


All processes killed
========== OTL ==========
Unable to kill active process avgnt.exe!
Service avipbb stopped successfully!
Service avipbb deleted successfully!
C:\WINDOWS\system32\drivers\avipbb.sys moved successfully.
Error: Unable to stop service avgntflt!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avgntflt deleted successfully.
C:\WINDOWS\system32\drivers\avgntflt.sys moved successfully.
Service avgio stopped successfully!
Service avgio deleted successfully!
C:\Programme\Avira\AntiVir Desktop\avgio.sys moved successfully.
Service ssmdrv stopped successfully!
Service ssmdrv deleted successfully!
C:\WINDOWS\system32\drivers\ssmdrv.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AntivirusRegistration deleted successfully.
C:\Programme\CA\Etrust Antivirus\Register.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avgnt deleted successfully.
C:\Programme\Avira\AntiVir Desktop\avgnt.exe moved successfully.
Error: Unable to interpret <:Files:> in the current context!
Error: Unable to interpret <C:\Programme\Avira> in the current context!
Error: Unable to interpret <C:\WINDOWS\system32\drivers\avipbb.sys> in the current context!
Error: Unable to interpret <C:\WINDOWS\system32\drivers\avgntflt.sys> in the current context!
Error: Unable to interpret <C:\WINDOWS\system32\drivers\ssmdrv.sys> in the current context!
Error: Unable to interpret <C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira> in the current context!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Besitzer

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: abc I
->Temp folder emptied: 365303 bytes
->Temporary Internet Files folder emptied: 7116360 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 50330231 bytes
->Flash cache emptied: 717 bytes

User: Gast
->Temp folder emptied: 42204 bytes
->Temporary Internet Files folder emptied: 241800 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 738 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 192 bytes
RecycleBin emptied: 192865075 bytes

Total Files Cleaned = 239,00 mb


OTL by OldTimer - Version 3.2.5.2 log created on 06072010_112313

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...



Gruß

Dilek

cosinus 07.06.2010 10:56

Ups, ich hatte einen kleinen Fehler im Script, bitte nochmal machen mit dieser korrigierten Fassung:

Code:

:OTL
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
O4 - HKLM..\Run: [AntivirusRegistration] C:\Programme\CA\Etrust Antivirus\Register.exe ()
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
:Files
C:\Programme\Avira
C:\WINDOWS\system32\drivers\avipbb.sys
C:\WINDOWS\system32\drivers\avgntflt.sys
C:\WINDOWS\system32\drivers\ssmdrv.sys
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
:Commands
[purity]
[resethosts]
[emptytemp]


multebeere 07.06.2010 11:05

HI Arne,

hier das neue Logfile:


All processes killed
========== OTL ==========
No active process named avgnt.exe was found!
Error: No service named avipbb was found to stop!
Service\Driver key avipbb not found.
File C:\WINDOWS\system32\drivers\avipbb.sys not found.
Error: No service named avgntflt was found to stop!
Service\Driver key avgntflt not found.
File C:\WINDOWS\system32\drivers\avgntflt.sys not found.
Error: No service named avgio was found to stop!
Service\Driver key avgio not found.
File C:\Programme\Avira\AntiVir Desktop\avgio.sys not found.
Error: No service named ssmdrv was found to stop!
Service\Driver key ssmdrv not found.
File C:\WINDOWS\system32\drivers\ssmdrv.sys not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AntivirusRegistration not found.
File C:\Programme\CA\Etrust Antivirus\Register.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avgnt not found.
File C:\Programme\Avira\AntiVir Desktop\avgnt.exe not found.
========== FILES ==========
C:\Programme\Avira\AntiVir Desktop\FAILSAFE folder moved successfully.
C:\Programme\Avira\AntiVir Desktop folder moved successfully.
C:\Programme\Avira folder moved successfully.
File\Folder C:\WINDOWS\system32\drivers\avipbb.sys not found.
File\Folder C:\WINDOWS\system32\drivers\avgntflt.sys not found.
File\Folder C:\WINDOWS\system32\drivers\ssmdrv.sys not found.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\UPDATE folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\TEMP folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\SYSSAFE folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\REPORTS folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\PROFILES folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\LOGFILES folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\JOBS folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\INFECTED folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\IDX folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\EVENTS folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\EVENTDB folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\CONFIG folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\BACKUP folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira folder moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Besitzer

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: abc I
->Temp folder emptied: 297712 bytes
->Temporary Internet Files folder emptied: 638002 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 23931889 bytes
->Flash cache emptied: 550 bytes

User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 24,00 mb


OTL by OldTimer - Version 3.2.5.2 log created on 06072010_120116

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

cosinus 07.06.2010 11:07

Gut. Dann bitte jetzt den CCleaner anwenden, damit auch die Registry aufräumen.

multebeere 07.06.2010 11:23

Hi Arne,

ok scheint funktioniert zu haben, CCleaner hat nach einem Durchlauf nichts mehr gefunden. Und nun?

Gruß

Dilek

cosinus 07.06.2010 11:25

...und nun bitte das AntiVir Setup ausführen, um es erneut und diesmal hoffentlich vernünftig zu installieren.

multebeere 07.06.2010 16:13

Hi Arne,

leider hats nicht funktioniert. Nach dem Setup bleibt das Problem. Der Antivir guard ist unbekannt und lässt sich nicht aktivieren. Und Deinstallieren über Systemsteuerung öffnet auch nur ein neues Antivir Set up.???

Gruß

Dilek

cosinus 07.06.2010 18:52

Dann kommen wir hier nicht weiter. Frag mal im Avira Supportforum nach und weise darauf hin, dass man nichtmal manuell deinstallieren kann.

multebeere 10.06.2010 20:12

Hi Arne,

dann schon mal vielen vielen Dank für Deine Mühe. Danke, das ist echt ein klasse service hier.

Gruß

Dilek


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:03 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131