![]() |
Movie Wizard lässt sich nicht Deinstallieren Hallo,ich sollte mein Videoplayer aktualisieren und hab mir Movie Wizard eingefangen.Hab es in Systemsteuerung gelöscht und auch die anderen Programme die dazu kamen.Danach hab ich CCleaner durchlaufen lassen aber bekomme immer noch werbung.Jetzt ist es sogar so das sich irgendwelche Seiten öffnen obwohl ich nichts mache.Bin echt am verzweifel da nur noch werbeseiten und links kommen:headbang: Hoffe mir kann jemand helfen |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Also die FRST Datei FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01 --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-01-2015 01 |
Ist das ein Firmenrechner? Oder wie kommt man zu ner Win 7 Enterprise Edition? |
Nein das ist ein privat rechner.Nen kumpel hatte den mal ein neues betriebssystem aufgespielt,der kennt sich gut damit aus und hat mehrere softwears. Ist das jetzt gut oder schlecht? |
Heisst das das ist ne geklaute Version? |
NAAAAIIN,um gottes willen.er hat dafür gutes Geld zahlen müssen. Also heißt es neues Betriebssystem aufspielen,aber wenn dann Windows 7 |
Nö :) Scan mit Combofix
|
Nach dem Scan von ComboFix Combofix Logfile: Code: ComboFix 15-01-29.01 - Thomas 01.02.2015 8:59.1.2 - x86 A36C5E4F47E84449FF07ED3517B43A31 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Malware Malwarebytes Anti-Malware www.malwarebytes.org Protection, 27.01.2015 09:38:40, SYSTEM, THOMAS-PC, Protection, Malware Protection, Starting, Protection, 27.01.2015 09:38:40, SYSTEM, THOMAS-PC, Protection, Malware Protection, Started, Protection, 27.01.2015 09:38:40, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Starting, Protection, 27.01.2015 09:39:06, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Started, Update, 27.01.2015 09:39:22, SYSTEM, THOMAS-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.1.14.1, Update, 27.01.2015 09:39:23, SYSTEM, THOMAS-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Error, 27.01.2015 09:39:40, SYSTEM, THOMAS-PC, Manual, 0, Error, 27.01.2015 09:39:40, SYSTEM, THOMAS-PC, Manual, 0, Protection, 27.01.2015 09:39:40, SYSTEM, THOMAS-PC, Protection, Refresh, Starting, Protection, 27.01.2015 09:39:40, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 27.01.2015 09:39:40, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 27.01.2015 09:39:50, SYSTEM, THOMAS-PC, Protection, Refresh, Success, Protection, 27.01.2015 09:39:50, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Starting, Protection, 27.01.2015 09:39:51, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Started, Protection, 27.01.2015 09:53:03, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Stopping, Protection, 27.01.2015 09:53:03, SYSTEM, THOMAS-PC, Protection, Malicious Website Protection, Stopped, Protection, 27.01.2015 09:53:03, SYSTEM, THOMAS-PC, Protection, Malware Protection, Stopping, Protection, 27.01.2015 09:53:36, SYSTEM, THOMAS-PC, Protection, Malware Protection, Stopped, (end) AdwCleaner Logfile: Code: # AdwCleaner v4.109 - Bericht erstellt am 02/02/2015 um 21:55:19 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows 7 Enterprise x86 Ran by Thomas on 02.02.2015 at 22:02:25,04 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update swift browse Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.02.2015 at 22:09:00,25 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015 --- --- --- |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESET Datei Code: ESETSmartInstaller@High as downloader log: UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015 --- --- --- --- --- --- --- --- --- Also bis jetzt ist nichts mehr gekommen :D |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\All Users\jxSWsMqh\dat\jCQhTnSyP.dll Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST Log bitte. |
Fixlog.txt Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-02-2015 Ran by Thomas at 2015-02-04 20:25:31 Run:1 Running from C:\Users\Thomas\Desktop\hille sicherung\Downloads Loaded Profiles: Thomas (Available profiles: Thomas) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\All Users\jxSWsMqh\dat\jCQhTnSyP.dll C:\Users\All Users\jxSWsMqh\dat\QKuxesNmogq.exe D:\Users\All Users\jxSWsMqh\dat\jCQhTnSyP.dll D:\Users\All Users\jxSWsMqh\dat\QKuxesNmogq.exe C:\$RECYCLE.BIN\S-1-5-21-752035569-2837603109-3999526748-1000\$RM6KAOV\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir C:\$RECYCLE.BIN\S-1-5-21-752035569-2837603109-3999526748-1000\$RM6KAOV\Quarantine\C\Users\Thomas\AppData\Roaming\VOPackage\VOPackage.exe.vir C:\ProgramData\jxSWsMqh\dat\jCQhTnSyP.dll C:\ProgramData\jxSWsMqh\dat\QKuxesNmogq.exe C:\Users\Thomas\Desktop\hille sicherung\Downloads\vlc-2.1.5-win32.exe C:\Windows\Installer\fc6c4dc.msi C:\Windows\Installer\MSI103B.tmp-\Smartbar.Installer.CustomActions.dll C:\Windows\Installer\MSI103B.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI103B.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI103B.tmp-\spbe.dll C:\Windows\Installer\MSI103B.tmp-\spbl.dll C:\Windows\Installer\MSI103B.tmp-\sppsm.dll C:\Windows\Installer\MSI103B.tmp-\spusm.dll C:\Windows\Installer\MSI103B.tmp-\srbs.dll C:\Windows\Installer\MSI103B.tmp-\srbu.dll C:\Windows\Installer\MSI103B.tmp-\srptc.dll C:\Windows\Installer\MSI103B.tmp-\srpu.dll C:\Windows\Installer\MSI103B.tmp-\srut.dll C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Installer.CustomActions.dll C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSI3F06.tmp-\spbe.dll C:\Windows\Installer\MSI3F06.tmp-\spbl.dll C:\Windows\Installer\MSI3F06.tmp-\sppsm.dll C:\Windows\Installer\MSI3F06.tmp-\spusm.dll C:\Windows\Installer\MSI3F06.tmp-\srbs.dll C:\Windows\Installer\MSI3F06.tmp-\srbu.dll C:\Windows\Installer\MSI3F06.tmp-\srptc.dll C:\Windows\Installer\MSI3F06.tmp-\srpu.dll C:\Windows\Installer\MSI3F06.tmp-\srut.dll C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Installer.CustomActions.dll C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Resources.LanguageSettings.resources.dll C:\Windows\Installer\MSIDF9E.tmp-\spbe.dll C:\Windows\Installer\MSIDF9E.tmp-\spbl.dll C:\Windows\Installer\MSIDF9E.tmp-\sppsm.dll C:\Windows\Installer\MSIDF9E.tmp-\spusm.dll C:\Windows\Installer\MSIDF9E.tmp-\srbs.dll C:\Windows\Installer\MSIDF9E.tmp-\srbu.dll C:\Windows\Installer\MSIDF9E.tmp-\srptc.dll C:\Windows\Installer\MSIDF9E.tmp-\srpu.dll C:\Windows\Installer\MSIDF9E.tmp-\srut.dll D:\Users\Hille\Desktop\sicherung\Downloads\Player Setup.exe HKLM\...\Run: [Realtime Audio Engine] => "mmrtkrnl.exe" /i HKU\S-1-5-21-752035569-2837603109-3999526748-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:65399;https=127.0.0.1:65399 S2 qAEoPWu; "C:\ProgramData\jxSWsMqh\qAEoPWu.exe" [X] C:\ProgramData\jxSWsMqh Emptytemp: ***************** "C:\Users\All Users\jxSWsMqh\dat\jCQhTnSyP.dll" => File/Directory not found. "C:\Users\All Users\jxSWsMqh\dat\QKuxesNmogq.exe" => File/Directory not found. "D:\Users\All Users\jxSWsMqh\dat\jCQhTnSyP.dll" => File/Directory not found. "D:\Users\All Users\jxSWsMqh\dat\QKuxesNmogq.exe" => File/Directory not found. "C:\$RECYCLE.BIN\S-1-5-21-752035569-2837603109-3999526748-1000\$RM6KAOV\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir" => File/Directory not found. "C:\$RECYCLE.BIN\S-1-5-21-752035569-2837603109-3999526748-1000\$RM6KAOV\Quarantine\C\Users\Thomas\AppData\Roaming\VOPackage\VOPackage.exe.vir" => File/Directory not found. "C:\ProgramData\jxSWsMqh\dat\jCQhTnSyP.dll" => File/Directory not found. "C:\ProgramData\jxSWsMqh\dat\QKuxesNmogq.exe" => File/Directory not found. "C:\Users\Thomas\Desktop\hille sicherung\Downloads\vlc-2.1.5-win32.exe" => File/Directory not found. "C:\Windows\Installer\fc6c4dc.msi" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\Smartbar.Installer.CustomActions.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\spbe.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\spbl.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\sppsm.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\spusm.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\srbs.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\srbu.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\srptc.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\srpu.dll" => File/Directory not found. "C:\Windows\Installer\MSI103B.tmp-\srut.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Installer.CustomActions.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\spbe.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\spbl.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\sppsm.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\spusm.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\srbs.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\srbu.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\srptc.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\srpu.dll" => File/Directory not found. "C:\Windows\Installer\MSI3F06.tmp-\srut.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Installer.CustomActions.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\Smartbar.Resources.LanguageSettings.resources.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\spbe.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\spbl.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\sppsm.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\spusm.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\srbs.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\srbu.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\srptc.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\srpu.dll" => File/Directory not found. "C:\Windows\Installer\MSIDF9E.tmp-\srut.dll" => File/Directory not found. "D:\Users\Hille\Desktop\sicherung\Downloads\Player Setup.exe" => File/Directory not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Realtime Audio Engine => value deleted successfully. "HKU\S-1-5-21-752035569-2837603109-3999526748-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. qAEoPWu => Service deleted successfully. C:\ProgramData\jxSWsMqh => Moved successfully. EmptyTemp: => Removed 1.1 GB temporary data. The system needed a reboot. ==== End of Fixlog 20:27:11 ==== |
Alle Zeitangaben in WEZ +1. Es ist jetzt 04:23 Uhr. |
Copyright ©2000-2025, Trojaner-Board