![]() |
pProtector for Windows & Yontoo Layers Runtime1.10.01? Hey, bei dem Aufräumen meines Laptops sind mir zwei komische Programme aufgefallen, nach denen ich anschließend auch gegooglet habe. Dort bin ich dann auf diese Seite hier gestoßen und wollte euch beten wie den anderen hier, auch mir zu helfen. Die beiden Programme heißen: - bProtector for Windows - Yontoo Layers Runtime1.10.01 Anschließend hab ich einen Malwarebytes Anti-Malware Scan gemacht der das ergab: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.04.04.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16521 Angie :: 4YOU9 [Administrator] 04.04.2013 14:13:38 mbam-log-2013-04-04 (14-13-38).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 414197 Laufzeit: 4 Stunde(n), 3 Minute(n), 22 Sekunde(n) Infizierte Speicherprozesse: 1 C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.BundleInstaller.IB) -> 2020 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 4 HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.BundleInstaller.IB) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service (PUP.BundleInstaller.IB) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} (PUP.BProtector) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\BPROTECTOR (PUP.BProtector) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\bProtector|iexplore homepages (PUP.BProtector) -> Daten: hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050^^ -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\ProgramData\bProtector (PUP.BProtector) -> Keine Aktion durchgeführt. C:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> Keine Aktion durchgeführt. Infizierte Dateien: 6 C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.BundleInstaller.IB) -> Keine Aktion durchgeführt. C:\ProgramData\bProtector\bProtect.settings (PUP.BProtector) -> Keine Aktion durchgeführt. C:\ProgramData\bProtector\bProtect.exe (PUP.BProtector) -> Keine Aktion durchgeführt. C:\ProgramData\bProtector\component_332.decrpt (PUP.BProtector) -> Keine Aktion durchgeführt. C:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> Keine Aktion durchgeführt. C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt. Daraufhin hab ich OTL benutzt: OTL.Txt [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.04.06 19:20:58 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\Canneverbe Limited [2013.02.01 23:12:04 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\DVDVideoSoft [2013.02.01 23:11:41 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\DVDVideoSoftIEHelpers [2012.09.23 19:28:19 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\EPSON [2012.04.06 15:03:32 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\eType [2013.03.26 14:31:06 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\ICQ [2012.01.06 20:21:47 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\Jewel Match 3 [2013.02.01 23:10:34 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\OpenCandy [2012.01.08 18:53:37 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\OpenOffice.org [2012.04.03 01:16:05 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\PhotoScape [2012.04.12 01:58:16 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\PlayFirst [2012.11.13 18:36:16 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\runic games [2012.01.06 19:30:08 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\Screensaver [2012.01.14 21:57:56 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\SNS [2013.04.04 18:48:12 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\SoftGrid Client [2012.01.16 23:48:10 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\TP [2013.02.01 23:13:01 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\TuneUp Software [2012.08.19 22:37:32 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\WildTangent [2012.01.13 07:15:51 | 000,000,000 | ---D | M] -- C:\Users\Angie\AppData\Roaming\Windows Live Writer ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013.02.21 01:56:35 | 000,006,464 | ---- | M] ()(C:\Users\Angie\Documents\er ?.rtf) -- C:\Users\Angie\Documents\er ♥.rtf [2013.02.21 01:56:35 | 000,006,464 | ---- | C] ()(C:\Users\Angie\Documents\er ?.rtf) -- C:\Users\Angie\Documents\er ♥.rtf < End of report > Extras.TxtOTL EXTRAS Logfile: Code: OTL Extras logfile created on: 04.04.2013 18:53:27 - Run 1 Ich hoffe jemand kann mir helfen (: Und schonmal danke im voraus!:dankeschoen: Und hier noch schnell die Gmer- Datei: GMER Logfile: Code: GMER 2.1.19163 - GMER - Rootkit Detector and Remover |
:hallo: OTL.txt ist unvollstaendig! |
Ich hab mich schon gewundert warum das so kurz ist... Hier nochmals die Datei:OTL Logfile: Code: OTL logfile created on: 05.04.2013 11:07:55 - Run 2 |
Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers danach: 3. Schritt Downloade Dir bitte ![]()
|
1. Schritt wurde ausgeführt ohne Probleme: All processes killed ========== OTL ========== Service IBUpdaterService stopped successfully! Service IBUpdaterService deleted successfully! C:\ProgramData\IBUpdaterService\ibsvc.exe moved successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{A0382E3C-7384-429A-9BFA-AF5888E5A193} folder moved successfully. C:\ProgramData\Temp\{64EF903E-D00A-414C-94A4-FBA368FFCDC9} folder moved successfully. C:\ProgramData\Temp\{01FB4998-33C4-4431-85ED-079E3EEFE75D} folder moved successfully. C:\ProgramData\Temp folder moved successfully. File\Folder C:\Users\Angie\*.tmp not found. File\Folder C:\Users\Angie\AppData\*.dll not found. File\Folder C:\Users\Angie\AppData\*.exe not found. C:\Users\Angie\AppData\Local\Temp\APNStub.exe moved successfully. C:\Users\Angie\AppData\Local\Temp\GoogleUpdateSetup.exebe305b8 moved successfully. C:\Users\Angie\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe moved successfully. C:\Users\Angie\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Angie\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Angie\Desktop\cmd.bat deleted successfully. C:\Users\Angie\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Angie ->Temp folder emptied: 1211013540 bytes ->Temporary Internet Files folder emptied: 1466264097 bytes ->Google Chrome cache emptied: 343024339 bytes ->Flash cache emptied: 100582 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 138026761 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 78140 bytes RecycleBin emptied: 602112 bytes Total Files Cleaned = 3.013,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 04052013_120943 Files\Folders moved on Reboot... C:\Users\Angie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Angie\AppData\Local\Temp\MMDUtl.log moved successfully. File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot. File move failed. C:\Windows\temp\LMutilps32.log scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... 2. Schritt ohne Probleme durchgeführt: Logfile nach dem 1. Scan : Malwarebytes Anti-Rootkit BETA 1.01.0.1022 Malwarebytes : Free anti-malware download Database version: v2013.04.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16521 Angie :: 4YOU9 [administrator] 05.04.2013 13:04:07 mbar-log-2013-04-05 (13-04-07).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 29825 Time elapsed: 16 minute(s), 53 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} (PUP.BProtector) -> Delete on reboot. HKCU\SOFTWARE\BPROTECTOR (PUP.BProtector) -> Delete on reboot. Registry Values Detected: 1 HKCU\SOFTWARE\BPROTECTOR|iexplore homepages (PUP.BProtector) -> Data: hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050^^ -> Delete on reboot. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 2 c:\ProgramData\bProtector (PUP.BProtector) -> Delete on reboot. c:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> Delete on reboot. Files Detected: 4 c:\ProgramData\bProtector\bProtect.settings (PUP.BProtector) -> Delete on reboot. c:\ProgramData\bProtector\bProtect.exe (PUP.BProtector) -> Delete on reboot. c:\ProgramData\bProtector\component_332.decrpt (PUP.BProtector) -> Delete on reboot. c:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> Delete on reboot. (end) Logfile nach dem 2. Scan: Malwarebytes Anti-Rootkit BETA 1.01.0.1022 Malwarebytes : Free anti-malware download Database version: v2013.04.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16521 Angie :: 4YOU9 [administrator] 05.04.2013 13:30:48 mbar-log-2013-04-05 (13-30-48).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 29835 Time elapsed: 20 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) 3. Schritt ohne Probleme durchlaufen:AdwCleaner Logfile: Code: # AdwCleaner v2.200 - Datei am 05/04/2013 um 13:35:51 erstellt |
Sehr gut! :daumenhoc Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). danach: ESET Online Scanner
danach: Downloade Dir bitte ![]()
|
aswMBR ohne Probleme durchgeführt: aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-07 13:23:49 ----------------------------- 13:23:49.038 OS Version: Windows x64 6.1.7601 Service Pack 1 13:23:49.038 Number of processors: 2 586 0x200 13:23:49.038 ComputerName: 4YOU9 UserName: Angie 13:23:51.284 Initialize success 13:27:59.072 AVAST engine defs: 13040700 13:28:05.015 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 13:28:05.015 Disk 0 Vendor: TOSHIBA_MK5059GSXP GN003J Size: 476940MB BusType: 11 13:28:05.140 Disk 0 MBR read successfully 13:28:05.140 Disk 0 MBR scan 13:28:05.156 Disk 0 Windows 7 default MBR code 13:28:05.171 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 16384 MB offset 2048 13:28:05.249 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 33556480 13:28:05.327 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 460455 MB offset 33761280 13:28:05.546 Disk 0 scanning C:\Windows\system32\drivers 13:28:30.833 Service scanning 13:29:38.116 Modules scanning 13:29:38.132 Disk 0 trace - called modules: 13:29:38.210 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 13:29:38.740 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005b9c060] 13:29:38.740 3 CLASSPNP.SYS[fffff88001a5843f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800563e680] 13:29:41.049 AVAST engine scan C:\Windows 13:29:48.272 AVAST engine scan C:\Windows\system32 13:38:57.144 AVAST engine scan C:\Windows\system32\drivers 13:39:38.313 AVAST engine scan C:\Users\Angie 13:48:08.418 AVAST engine scan C:\ProgramData 13:54:21.274 Scan finished successfully 18:27:56.798 Disk 0 MBR has been saved successfully to "C:\Users\Angie\Desktop\MBR.dat" 18:27:56.814 The log file has been saved successfully to "C:\Users\Angie\Desktop\aswMBR.txt" |
Kommt der Rest noch? ;) |
ESET Online Scanner durchgeführt: Hat sehr lange gedauert und am Ende war kein Logfile zu finden, dabei wurde alle Schritte befolgt. SercurityCheck ohne Probleme durchgeführt: Results of screen317's Security Check version 0.99.61 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Norton Internet Security Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 Java 7 Update 17 Adobe Reader 10.1.6 Adobe Reader out of Date! Google Chrome 25.0.1364.172 Google Chrome 26.0.1410.43 ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Schaue hier nach: C:\Programme (x86)\Eset\EsetOnlineScanner\ |
Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 10:38 Uhr. |
Copyright ©2000-2025, Trojaner-Board