Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   windows reagiert teilweise nicht besonders Themen der Systemsteuerung (https://www.trojaner-board.de/164488-windows-reagiert-teilweise-besonders-themen-systemsteuerung.html)

ghostriderac 26.02.2015 17:23

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-02-2015 01
Ran by Michael at 2015-02-26 17:20:07 Run:1
Running from C:\Users\Michael\Downloads
Loaded Profiles: Michael (Available profiles: Michael & Sabrina & Gast)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-96331273-387734633-2682027485-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM-x32 - No Name - !{D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-96331273-387734633-2682027485-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {E1342154-4889-42B5-BEF6-19237577048F} hxxp://acerde.oberon-media.com/online/online2/zuma/oberongamesloader.cab
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-02-26] (Enigma Software Group USA, LLC.)
AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:444C53BA
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:981884E7
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:DDE7FCF4
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
C:\Windows\System32\Tasks\{1761FDD0-D86E-41F6-9865-E15CECFC67E2}
C:\Program Files\Enigma Software Group
EmptyTemp:
Hosts:
*****************

"HKU\S-1-5-21-96331273-387734633-2682027485-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully.
HKCR\Wow6432Node\CLSID\!{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
HKU\S-1-5-21-96331273-387734633-2682027485-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{E1342154-4889-42B5-BEF6-19237577048F}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{E1342154-4889-42B5-BEF6-19237577048F}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{C345E174-3E87-4F41-A01C-B066A90A49B4}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{C345E174-3E87-4F41-A01C-B066A90A49B4}" => Key deleted successfully.
SpyHunter 4 Service => Service stopped successfully.
SpyHunter 4 Service => Service deleted successfully.
C:\ProgramData\Temp => ":0B9176C0" ADS removed successfully.
C:\ProgramData\Temp => ":444C53BA" ADS removed successfully.
C:\ProgramData\Temp => ":4CF61E54" ADS removed successfully.
C:\ProgramData\Temp => ":4D066AD2" ADS removed successfully.
C:\ProgramData\Temp => ":5D7E5A8F" ADS removed successfully.
C:\ProgramData\Temp => ":93DE1838" ADS removed successfully.
C:\ProgramData\Temp => ":981884E7" ADS removed successfully.
C:\ProgramData\Temp => ":AB689DEA" ADS removed successfully.
C:\ProgramData\Temp => ":ABE89FFE" ADS removed successfully.
C:\ProgramData\Temp => ":DDE7FCF4" ADS removed successfully.
C:\ProgramData\Temp => ":E1F04E8D" ADS removed successfully.
C:\ProgramData\Temp => ":E3C56885" ADS removed successfully.
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 => Moved successfully.
C:\Windows\System32\Tasks\{1761FDD0-D86E-41F6-9865-E15CECFC67E2} => Moved successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 206.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog 17:20:21 ====


cosinus 26.02.2015 21:22

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, whle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschlieen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Whle das neueste Scan-Protokoll aus und klicke auf Export. Whle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Fge den Inhalt der mbam.txt mit deiner nchsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwnschten Anwendungen" und whle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schliee das Fenster von ESET.
  • Explorer ffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor ffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner lschen und Papierkorb leeren => C:\Programme\Eset


ghostriderac 27.02.2015 16:06

Code:

Inno Setup Uninstall Log (b)                                    Malwarebytes Anti-Malware                                                                                                      Malwarebytes Anti-Malware                                                                                                      0  y  b  %                                                                                                              Ž   *    V 
MICHAEL-PCMichael0C:\Program Files (x86)\Malwarebytes Anti-Malware    5 3   8  L-IFPS    [           
                                       
                                  BOOLEAN                                                                                                  !MAIN  -1 =  dll:setup:files:mbam.dll,master.conf ProtectionUninstall   5  dll:uninstall:{app}\mbam.dll ProtectionUninstall    ;  dll:setup:files:mbam.dll,master.conf ProtectionInstall   ?  dll:setup:files:mbam.dll,master.conf SelfProtectionInstall   A  dll:setup:files:mbam.dll,master.conf SelfProtectionUninstall   A  dll:setup:files:mbam.dll,master.conf SelfProtectionInstalled   >  dll:setup:files:mbam.dll,master.conf SelfProtectionActive   H  dll:setup:files:mbam.dll,master.conf SelfProtectionActiveAndEnabled   <  dll:setup:files:mbam.dll,master.conf SchedulerUninstall   4  dll:uninstall:{app}\mbam.dll SchedulerUninstall    :  dll:setup:files:mbam.dll,master.conf SchedulerInstall   9  dll:uninstall:{app}\mbam.dll SelfProtectionUninstall    ;  dll:setup:files:mbam.dll,master.conf InstallerKillMBAM    3  dll:uninstall:{app}\mbam.dll InstallerKillMBAM    F  dll:setup:files:mbam.dll,master.conf InstallerRegisterContextMenu   k  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerMigrateSettings  j  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerShowStartTrial  l  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerPopulateConfig    :  dll:setup:files:mbam.dll,master.conf LicenseIsValid1x   x  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerLicenseContainsAlphaIDAndKey  e  dll:setup:files:mbamsrv.dll,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerCheckConfigIntegrity   l  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerGetAffiliateID    k  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerSetAffiliateID   -  dll:setup:RstrtMgr.dll RmStartSession     )  dll:setup:RstrtMgr.dll RmEndSession    o  dll:setup:files:mbamsrv.dll,master.conf,QtCore4.dll,msvcp100.dll,msvcr100.dll InstallerRegisterResource    )  dll:setup:RstrtMgr.dll RmShutdown     (  dll:setup:RstrtMgr.dll RmRestart      (    INITIALIZEWIZARD  -1      NEEDRESTART  16      ISWIN32  16ISWIN64    ™    ISWINDOWSXP  16GETWINDOWSVERSIONEX    *      REGISTERCONTEXTMENU  -1REGISTERSERVER      EXPANDCONSTANT     o    UNREGISTERCONTEXTMENU  -1UNREGISTERSERVER    #  $    GET1XUNINSTALLER  8REGQUERYSTRINGVALUE     REMOVEQUOTES   G   
  GETOLDVERSION  8 @8O  <    GETOLD1XVERSION  8‹  ;    GETOLD2XVERSION  8  Š    ISUPGRADEFROM1X  16
COMPARESTR    P  Š    ISUPGRADEFROM2X  16  5              ISUPGRADE  16  r    ISUPGRADEFROM2XBEFORE  16 @8  r    ISUPGRADEFROM2XATLEAST  16 @8      ISUPGRADEFROMANY2XVERSION  16          ~    SHOWSTARTTRIAL  16‡  …    UNINSTALL1X  -1EXEC      MSGBOX    
CUSTOMMESSAGE   ABORT       1    MIGRATE1XSETTINGS  -1=      START2XTRIAL  -1[      ACTIVATE2XWITH1XLICENSE  -1_  1    WAITFORFILE          16 @8 @10
FILEEXISTS   SLEEP          GETLAST2XINSTALLPATH  8‰      CHANGESELFPROTECTIONSTATEXP  10 @16„    !  XPUPGRADEWITHSELFPROTECTIONACTIVE  16+!      GETAFFILIATEID  8        SETLENGTH     COPY    )"      PREPARETOINSTALL  8 !16"  n  !  HANDLE2XUPGRADEWITHSELFPROTECTION  -1#   
  BEFOREINSTALL  -1REGDELETEVALUE    #  ‹    AFTERINSTALL  -1        UNLOADDLL    V&  {    BEFOREUNINSTALL  -1&      AFTERUNINSTALL  -1ENABLEFSREDIRECTION   
DELETEFILE   '  X    CURSTEPCHANGED  -1 @21'  X     v2  CURUNINSTALLSTEPCHANGED  -1 @22S(  :    INITIALIZESETUP  16 WIZARDSILENT  *      SHOULDREPLACECONF  16CURRENTFILENAME  1+      SHOULDREPLACELICENSECONF  16E,      REMOVECONTEXTEXTENSION  -1
RENAMEFILE    RESTARTREPLACE     
   
                                                                
            _            _     _                 `   `"        `  `    
    +      `      `  `  
       `   `   `    _       _                  `           `    {app}\mbamext.dll   `%        `    $        `!     `   `u                          `
                    `
                    `      `                           `      `                           `           `    {app}\mbamext.dll   `%        `       `'                  `  R  Software\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1   `%            ` _       `    UninstallString       `   `
      `
    €   `)     `   `    _            ` _ _*                  `  4  Software\Microsoft\Windows\CurrentVersion\Uninstall\    ` _    `    _is1   `%            ` _       `    DisplayVersion       `   `
      `
    €   `)     `   `    _                    `    Malwarebytes' Anti-Malware _+                `    Malwarebytes Anti-Malware _+           _         j    _  
        `    2.00.0.0000       `      `/      `   `
       _   `         _         j    _  
        `    2.00.0.0000       `      `/      `   `
       _   `         _.      _      `0   _   `         _0  [    _  
        ` _       `      `/      `   `
       _   `         _0  [    _  
        ` _       `      `/       `   `
       _   `         _                  _.  $    _      `     ` _   `9    _  
     `      `   `
     _   `       
       `.     `a           `   `       `  
      `
          `            `  (  /VERYSILENT /SUPPRESSMSGBOXES /NORESTART      `(     `7     `'      `      `   `
         `   `   `p 
 
      `
            `           `    Uninstall1x   `9     `8  :               `.     ` 
     `         
       `.        `      `     `   `   `           `   `       `  
      `
          `            `    /starttrial                 `    {app}\mbam.exe   `%     `7        
          
             
       `     `           `   `       `  
      `
          `            `    /installer_activatewith1x                 `    {app}\mbam.exe   `%     `7        
        
           
          `        `        ` _      `   `    $      `      `   `       `   `      `       ` _   `?     `
         `   `
       `       `        `   `     ` 
      `
    @    _   `                `  Q  Software\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1          ` _       `    InstallLocation       `   `
      `
    €   `)     `   `    _                 
 
      `
       
     `      `   `
    9      `  
     `      `   `
       `   `   `P     `A           `  $  Chameleon\Windows\mbam-chameleon.exe   `%      `   `       Q17w  ` _       `4      `
              `    /p /d      `    /p /e          `   `       `  
      `
                    `         
  `   `       `   `   `7    _   `             `4        `      `!     `   `9      `  
     `      `   `
       `   `   `    _       _             
 
      `
             `   `E  
      `
            `   `   `         `   `
         `T 
      `   `
      `
          `   ` _F            _                             `C      `   `     `;        `    DisableSelfProtection _9      _                   `4  9      `  
     `      `   `
       `   `   `                 6          `    InstallPath       `  #  Software\Malwarebytes' Anti-Malware
      `
    €   `J  
                     H     D                      `    {tmp}\mbam.dll   `%  L           `    {tmp}\mbamsrv.dll   `%  L         `    {app}   `%         `    {commonappdata}   `%         `   `       `   `  ;  =        `      `#          `      `    
      `
 
          `    {app}\Languages\lang_vi.qm   `%     `>    
      `
 
          `    {app}\Languages\lang_en.qm   `%     `>        `    
         ` 
     `        `   
         ` 
     `             & 
     `
  
     `  
     `            `    {app}\mbam.dll   `%  L                 `       `        `       `O  Z              `    {sys}\drivers\mbamswissarmy.sys   `%     `P           `   `   `O               ` _     `
  I  )       ` _     `  K               ` _     `
  M  )       ` _     `  N               ,     -    _          `   `"        `  `    
    `      `      `  `    
    +      `      `  `  
       `   `   `   `•      `      `  `    
    +      `      `  `  
       `   `+      `      `  `  
       `   `   `   `   `       `T     `   `   
 
      `
          `           `    OutdatedWindows   `9     `8      `   `
       `     _                   `V     `%           `   `   `?     `(        `   ` _   _     _         ` _   `                    `  Q  {commonappdata}\Malwarebytes\Malwarebytes Anti-Malware\Configuration\license.conf   `%           `   `   `?     `a       `U     `    _  -       _    _       _                    `    {app}\mbamext.dll   `%           `   `   `P     `   `•        `    {app}\mbamext.dll.old   `%           `   `       `   `   `Y         `            `   `Z                                          0C:\Program Files (x86)\Malwarebytes Anti-MalwareNC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-MalwareMalwarebytes Anti-Malwarede            OutdatedWindows'  Your version of Windows is outdated and presents a serious threat to the security of your system.

Malwarebytes Anti-Malware requires at least Windows XP Service Pack 2 to be fully-functional. It is highly recommended that you upgrade Windows. Do you want to continue with installation anyway?   Uninstall1x  Malwarebytes Anti-Malware 1.x   ʷo . , Malwarebytes Anti-Malware 1.x, .          PUPPrompt1  PUP, or Potentially Unwanted Programs are software which are not malware but might be undesirable such as adware/advertising software and toolbars.  Malwarebytes Anti-Malware is able to detect and remove these types of software, but since they are not malware some users might not want them to be removed.   PUPChooseHow3  Anti-Malware PUP :  PUPComboOptionA*  PUP ,   PUPComboOptionB@  , PUP   PUPComboOptionC  PUP   PUPHyperlinkTextV  , Malwarebytes PUP  NameAndVersion
  %1 Version %2  AdditionalIcons  Zustzliche Symbole:  CreateDesktopIcon  &Desktop-Symbol erstellen  CreateQuickLaunchIcon*  Symbol in der Schnellstartleiste erstellen  ProgramOnTheWeb  %1 im Internet  UninstallProgram   %1 entfernen
  LaunchProgram
  %1 starten  AssocFileExtension+  &Registriere %1 mit der %2-Dateierweiterung  AssocingFileExtension2  %1 wird mit der %2-Dateierweiterung registriert...
  UpdateProgram  Aktualisiere %1  UpdatingProgram  %1 Aktualisierung
  AcceptLicense6  Ich akzeptiere die Bedingungen der Lizenzvereinbarung.
  AcceptNonCommR  Ich akzeptiere die Software nur fr den nicht-kommerziellen gebrauch zu verwenden.  MoreInfo   (Mehr Infos)
  StartTrial%  Aktiviere kostenlosen Test von %1 PRO  OutdatedWindowsV  Ihre Windowsversion ist nicht aktuell und stellt eine Gefahr fr die Sicherheit Ihres System dar.

Malwarebytes Anti-Malware bentigt mindestens Windows XP Service Pack 2 um vollstndig funktionieren zu knnen. Es wird daher dringend geraten eine Aktualisierung von Windows durchzufhren. Wollen Sie dennoch mit der Installation fortfahren?  DisableSelfProtectionu  Der Selbstschutz muss unter "Erweiterte Einstellungen" deaktiviert werden, bevor Sie mit der Installation fortfahren.‹          /  -C:\Windows\system32\drivers\mbamswissarmy.sys   2  0C:\Program Files (x86)\Malwarebytes Anti-Malware‚ €  *  $C:\Windows\system32\drivers\mbam.sys    ‚ €  *  $C:\Windows\system32\drivers\mwac.sys    ‚   3  -C:\Windows\system32\drivers\mbamchameleon.sys    ‚ €  B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll    ‚ €  ?  9C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.dll    ‚ €  C  =C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll    ‚ €  B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamsrv.dll    ‚ €  ?  9C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe    ‚ €  F  @C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe    ‚ €  H  BC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe    ‚ €  A  ;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbampt.exe    ‚ €  B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamdor.exe    ‚    B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\license.rtf    ‚    B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\changes.txt      <  :C:\Program Files (x86)\Malwarebytes Anti-Malware\Languages‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ar.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_bg.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ca.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_cs.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_da.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_de.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_el.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_en.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Ma   Ž€lware\Languages\lang_es.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_et.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_fi.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_fr.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_he.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_hu.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_id.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_it.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ja.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ko.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_lt.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_lv.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_nl.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_no.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_pl.qm    ‚    N  HC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_pt_BR.qm    ‚    N  HC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_pt_PT.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ro.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_ru.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_sk.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_sl.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_sv.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_th.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_tr.qm    ‚    K  EC:\Program Files (x86)\Malwarebytes Anti-Malware\Languages\lang_vi.qm    ‚    E  ?C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\rules.ref    ‚    G  AC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\actions.ref    ‚    I  CC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\swissarmy.ref    ‚    G  AC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\domains.ref    ‚    C  =C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\ips.ref    ‚    B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\master.conf      E  CC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration‚    R  LC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\net.conf    ‚    T  NC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\build.conf    ‚    W  QC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\database.conf    ‚    W  QC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\manifest.conf    ‚    X  RC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\marketing.conf      M  KC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore‚    Z  TC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\net.conf    ‚    \  VC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\build.conf    ‚    _  YC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\database.conf    ‚    _  YC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\manifest.conf    ‚    `  ZC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\marketing.conf    ‚    `  ZC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\scheduler.conf    ‚    a  [C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\statistics.conf    ‚    a  [C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\gatekeeper.conf    ‚    d  ^C:\ProgramData\Malwarebytes\Malwarebytes Anti-Mal   6ware\Configuration\Restore\notifications.conf    ‚    ^  XC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\license.conf    ‚    _  YC:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\settings.conf      :  8C:\Program Files (x86)\Malwarebytes Anti-Malware\Plugins‚ €  L  FC:\Program Files (x86)\Malwarebytes Anti-Malware\Plugins\fixdamage.exe      ?  =C:\Program Files (x86)\Malwarebytes Anti-Malware\imageformats‚ €  M  GC:\Program Files (x86)\Malwarebytes Anti-Malware\imageformats\qgif4.dll      =  ;C:\Program Files (x86)\Malwarebytes Anti-Malware\accessible‚ €  Z  TC:\Program Files (x86)\Malwarebytes Anti-Malware\accessible\qtaccessiblewidgets4.dll    ‚ €  =  7C:\Program Files (x86)\Malwarebytes Anti-Malware\7z.dll    ‚ €  C  =C:\Program Files (x86)\Malwarebytes Anti-Malware\msvcp100.dll    ‚ €  C  =C:\Program Files (x86)\Malwarebytes Anti-Malware\msvcr100.dll    ‚ €  B  <C:\Program Files (x86)\Malwarebytes Anti-Malware\QtCore4.dll    ‚ €  A  ;C:\Program Files (x86)\Malwarebytes Anti-Malware\QtGui4.dll    ‚ €  E  ?C:\Program Files (x86)\Malwarebytes Anti-Malware\QtNetwork4.dll      <  :C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon   D  BC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows‚ €  V  PC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm    ‚ €  X  RC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-killer.exe    ‚ €  [  UC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.exe    ‚ €  [  UC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.com    ‚ €  [  UC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.pif    ‚ €  [  UC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.scr    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.exe    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.com    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.pif    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.scr    ‚ €  U  OC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe    ‚ €  U  OC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe    ‚ €  U  OC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\rundll32.exe    ‚ €  T  NC:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\windows.exe      P  NC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware‚    n  lC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk‚    n  lC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.pif   V  TC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools‚    ~  |C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk‚    ~  |C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.pif   P  NC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware‚    x  vC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware entfernen.lnk‚    x  vC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware entfernen.pif‚    7  5C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk‚    7  5C:\Users\Public\Desktop\Malwarebytes Anti-Malware.pif†   €>  <SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mbam.exe†   €>  <SOFTWARE\Microsoft\Windows\CurrentVersion  rEƮ\App Paths\mbam.exe†   €S  QSoftware\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1          5 5 


cosinus 27.02.2015 16:08

Wasn das frn Log??? :wtf:

ghostriderac 28.02.2015 01:05

Code:

<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2015/02/27 07:55:39 +0100</date>
<logfile>mbam-log-2015-02-27 (07-55-39).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.00.4.1028</version>
<malware-database>v2015.02.27.03</malware-database>
<rootkit-database>v2015.02.25.01</rootkit-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>disabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Michael</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>cancelled</result>
<objects>458700</objects>
<time>1581</time>
<processes>0</processes>
<modules>0</modules>
<keys>6</keys>
<values>0</values>
<datas>0</datas>
<folders>0</folders>
<files>3</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<key><path>HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Feven Pro</path><vendor>PUP.Optional.Feven.A</vendor><action>success</action><hash>f07ff42fb1d976c000b3439f7a89649c</hash></key>
<key><path>HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-1.2</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>0768859e37531a1c506623b863a0a45c</hash></key>
<key><path>HKU\S-1-5-21-96331273-387734633-2682027485-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>5916c95a8cfeda5ce9fecb32e81cf709</hash></key>
<key><path>HKU\S-1-5-21-96331273-387734633-2682027485-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>6708ab78becc6fc7519588758f757987</hash></key>
<key><path>HKU\S-1-5-21-96331273-387734633-2682027485-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent</path><vendor>PUP.Optional.Iminent.A</vendor><action>success</action><hash>422d9a89b5d5dd599b7db53440c301ff</hash></key>
<key><path>HKU\S-1-5-21-96331273-387734633-2682027485-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Datamngr</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>f07f4ad93e4c7cba8463af4eef153fc1</hash></key>
<file><path>C:\Users\Michael\Downloads\2014_06rechnung_0724300002_sign.zip</path><vendor>Trojan.Ransom.CRV</vendor><action>success</action><hash>16596fb4adddb6805ac4c3dd51b4be42</hash></file>
<file><path>C:\Users\Michael\Downloads\hdplugin_firefox.exe</path><vendor>PUP.BundleInstaller.DW</vendor><action>success</action><hash>c3acd64deb9fd85e719027079968cc34</hash></file>
<file><path>C:\Users\Michael\Downloads\Skyfall.2012.DVDScr.German.AC3LD.XviD-DerSchuft.avi.exe</path><vendor>PUP.BundleInstaller.DW</vendor><action>success</action><hash>97d867bc6a2066d0fe031618768bab55</hash></file>
</items>
</mbam-log>

sorry war der falsche

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=ab36aa512a8cef4a850ae807d37b1279
# engine=22680
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-27 07:18:42
# local_time=2015-02-27 08:18:42 (+0100, Mitteleuropische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='AVG Internet Security 2014'
# compatibility_mode=1049 16777213 100 100 45677 112198706 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 25222800 176694572 0 0
# scanned=434581
# found=3
# cleaned=0
# scan_time=13482
sh=B0DF4D2984A473A5280FC1CA085939A45132C30D ft=1 fh=d91f3e9f7695112c vn="Variante von Win32/ReImageRepair.E evtl. unerwnschte Anwendung" ac=I fn="C:\Users\Michael\Downloads\ReimageRepair.exe"
sh=D3849BD1F527A917C0DEF298080BB2FC10B8E238 ft=1 fh=e09bbe0f3d16f431 vn="Win32/RegistryBooster evtl. unerwnschte Anwendung" ac=I fn="C:\Users\Michael\Downloads\Programme\registrybooster.exe"
sh=7D6DD7AE0F6793E5F95F9136C209FE80260D3C2C ft=0 fh=0000000000000000 vn="Win32/Toolbar.Iminent.I evtl. unerwnschte Anwendung" ac=I fn="C:\Users\Sabrina\AppData\Local\Mozilla\Firefox\Profiles\7ee47sv9.default\Cache\D\F2\5398Ad01"


cosinus 28.02.2015 01:16

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchluft!


Drcke bitte die Windowstaste + R Taste und schreibe notepad in das Ausfhren Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\Michael\Downloads\ReimageRepair.exe
C:\Users\Michael\Downloads\Programme\registrybooster.exe
C:\Users\Sabrina\AppData\Local\Mozilla\Firefox\Profiles\7ee47sv9.default\Cache\D\F2\5398Ad01
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


ghostriderac 28.02.2015 08:04

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-02-2015 01
Ran by Michael at 2015-02-28 08:00:58 Run:2
Running from C:\Users\Michael\Downloads
Loaded Profiles: Michael (Available profiles: Michael & Sabrina & Gast)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Michael\Downloads\ReimageRepair.exe
C:\Users\Michael\Downloads\Programme\registrybooster.exe
C:\Users\Sabrina\AppData\Local\Mozilla\Firefox\Profiles\7ee47sv9.default\Cache\D\F2\5398Ad01
EmptyTemp:
Hosts:
*****************

C:\Users\Michael\Downloads\ReimageRepair.exe => Moved successfully.
C:\Users\Michael\Downloads\Programme\registrybooster.exe => Moved successfully.
C:\Users\Sabrina\AppData\Local\Mozilla\Firefox\Profiles\7ee47sv9.default\Cache\D\F2\5398Ad01 => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 54.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog 08:01:01 ====


cosinus 28.02.2015 19:02

Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) empfehle ich die Erweiterung Ghostery, diese verhindert weitgehend Usertracking bzw. das Anzeigen von Werbebannern.

Info: Cookies sind keine Schdlinge direkt, aber es besteht die Gefahr der missbruchlichen Verwendung (eindeutige Wiedererkennung zB fr gezielte Werbung o.. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen fr den Firefox zB wre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession berall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

ghostriderac 28.02.2015 21:10

Leider ist es immernoch nicht in Ordnung.
die windows search funktion funktioniert nicht,
ich als admin kommen nicht in die Buntzerkonten, bildschirmauflsung( Systemsteuerung>Anzeige reagiert garnicht, viele Punkter in der Systemsteuerung lassen sich nicht ffnen.

cosinus 28.02.2015 21:41

Benutzerprofil schrott?
Erstell dir mal einen neuen Benutzer ber die Systemsteuerung, log dich aus, und mit dem neuen ein. Teste. Berichte.

ghostriderac 28.02.2015 21:48

Ich komme nicht auf die benutzerkonten

cosinus 28.02.2015 21:49

Dann probiers im abgesicherten Modus

ghostriderac 28.02.2015 22:00

Selbst im abgesicherten Modus gewhrt er mir keinen Zugriff
Systemsteuerung ja dann Ende keine Unterfunktion kann ich ffnen

cosinus 28.02.2015 22:14

Probier das mal bitte:

http://www.deeprybka.trojaner-board....r/wraioneu.PNG
  • Lade Dir bitte Windows Repair - All in one von tweaking.com hier herunter und installiere es.
  • Deaktiviere bitte (wenn mglich) Dein Antivirusprogramm.
  • Bedenke, dass die einzelnen Reparaturen einige Zeit bentigen. Starte keine anderen Anwendungen in dieser Zeit.
  • Starte das Programm und fhre die Punkte 1-5 durch. (Siehe Bildanleitung)
  • Achte darauf, dass bei Dir die Hkchen so gesetzt sind wie unter Punkt 4.
  • Setze auch ein Hkchen bei "Restart/Shutdown System" und klicke "Restart System" an bevor Du Punkt 5 durchfhrst.
http://deeprybka.trojaner-board.de/b...srepair271.png

ghostriderac 01.03.2015 00:21

Was ist mit Stephie 5 Backup?

Step 5

Was soll ich nun machen? Alles durchgelaufen!

Code:

Tweaking.com - Windows Repair v2.11.2
--------------------------------------------------------------------------------

System Variables
--------------------------------------------------------------------------------
OS: Windows 7 Home Premium
OS Architecture: 64-bit
OS Version: 6.1.7601
OS Service Pack: Service Pack 1
Computer Name: MICHAEL-PC
Windows Drive: C:\
Windows Path: C:\Windows
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Michael
Current Profile SID: S-1-5-21-96331273-387734633-2682027485-1000
Current Profile Classes: S-1-5-21-96331273-387734633-2682027485-1000_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\Windows\ServiceProfiles
Local Settings AppData: C:\Users\Michael\AppData\Local
--------------------------------------------------------------------------------

System Information
--------------------------------------------------------------------------------
System Up Time: 0 Days 00:27:26

Process Count: 54
Commit Total: 1,77 GB
Commit Limit: 8,00 GB
Commit Peak: 2,07 GB
Handle Count: 17468
Kernel Total: 440,15 MB
Kernel Paged: 366,17 MB
Kernel Non Paged: 73,98 MB
System Cache: 2,41 GB
Thread Count: 781
--------------------------------------------------------------------------------

Memory Before Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 4,00 GB
Memory Used: 1,32 GB(33,0991%)
Memory Avail.: 2,68 GB
--------------------------------------------------------------------------------

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 4,00 GB
Memory Used: 1,02 GB(25,5057%)
Memory Avail.: 2,98 GB
--------------------------------------------------------------------------------

Starting Repairs...
  Started at (28.02.2015 23:23:39)

Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair...
Total Missing 'InstallDate' Fixed: 0
 
01 - Reset Registry Permissions 01/03
  HKEY_CURRENT_USER & Sub Keys
  Start (28.02.2015 23:23:40)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under Current User Account
  Done (28.02.2015 23:24:00)

01 - Reset Registry Permissions 02/03
  HKEY_LOCAL_MACHINE & Sub Keys
  Start (28.02.2015 23:24:00)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.


Decompressing & Updating Windows Permission File services.txt
Done,  0,17 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:28:59)

01 - Reset Registry Permissions 03/03
  HKEY_CLASSES_ROOT & Sub Keys
  Start (28.02.2015 23:28:59)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under System Account
  Done (28.02.2015 23:30:33)

03 - Reset Service Permissions
  Start (28.02.2015 23:30:33)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under System Account
  Done (28.02.2015 23:30:47)

04 - Register System Files
  Start (28.02.2015 23:30:47)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:31:33)

05 - Repair WMI
  Start (28.02.2015 23:31:33)

  Starting Security Center So We Can Export The Security Info.

  Exporting Antivirus Info...
  No Antivirus Products Reported.

  Exporting AntiSpyware Info...
  Windows Defender Exported.
  AVG Internet Security 2014 Exported.

  Exporting 3rd Party Firewall Info...
  AVG Internet Security 2014 Exported.

  Running Repair Under Current User Account
  Done (28.02.2015 23:33:44)

06 - Repair Windows Firewall
  Start (28.02.2015 23:33:44)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,16 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:33:58)

07 - Repair Internet Explorer
  Start (28.02.2015 23:33:58)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:34:46)

08 - Repair MDAC/MS Jet
  Start (28.02.2015 23:34:46)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:35:06)

09 - Repair Hosts File
  Start (28.02.2015 23:35:06)
  Running Repair Under System Account
  Done (28.02.2015 23:35:07)

10 - Remove Policies Set By Infections
  Start (28.02.2015 23:35:07)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:35:12)

11 - Repair Start Menu Icons Removed By Infections
  Start (28.02.2015 23:35:12)
  Running Repair Under System Account
  Done (28.02.2015 23:35:13)

12 - Repair Icons
  Start (28.02.2015 23:35:13)
  Running Repair Under Current User Account
  Done (28.02.2015 23:35:14)

13 - Repair Winsock & DNS Cache
  Start (28.02.2015 23:35:14)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:35:38)

15 - Repair Proxy Settings
  Start (28.02.2015 23:35:38)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:35:40)

17 - Repair Windows Updates
  Start (28.02.2015 23:35:40)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,16 seconds.

  Running Repair Under System Account
  Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
  Done (28.02.2015 23:36:14)

18 - Repair CD/DVD Missing/Not Working
  Start (28.02.2015 23:36:14)
  iTunes was found, adding UpperFilters for iTunes Reg Key
  UpperFilters added?: True
  Done (28.02.2015 23:36:14)

19 - Repair Volume Shadow Copy Service
  Start (28.02.2015 23:36:14)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,16 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:36:41)

21 - Repair MSI (Windows Installer)
  Start (28.02.2015 23:36:41)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,17 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:36:55)

23.01 - Repair bat Association
  Start (28.02.2015 23:36:55)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:36:57)

23.02 - Repair cmd Association
  Start (28.02.2015 23:36:57)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:36:59)

23.03 - Repair com Association
  Start (28.02.2015 23:36:59)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:01)

23.04 - Repair Directory Association
  Start (28.02.2015 23:37:01)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:04)

23.05 - Repair Drive Association
  Start (28.02.2015 23:37:04)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:06)

23.06 - Repair exe Association
  Start (28.02.2015 23:37:06)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:08)

23.07 - Repair Folder Association
  Start (28.02.2015 23:37:08)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:10)

23.08 - Repair inf Association
  Start (28.02.2015 23:37:10)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:12)

23.09 - Repair lnk (Shortcuts) Association
  Start (28.02.2015 23:37:12)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:15)

23.10 - Repair msc Association
  Start (28.02.2015 23:37:15)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:17)

23.11 - Repair reg Association
  Start (28.02.2015 23:37:17)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:19)

23.12 - Repair scr Association
  Start (28.02.2015 23:37:19)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:21)

24 - Repair Windows Safe Mode
  Start (28.02.2015 23:37:21)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:24)

25 - Repair Print Spooler
  Start (28.02.2015 23:37:24)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,16 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:37:40)

26 - Restore Important Windows Services
  Start (28.02.2015 23:37:40)
  Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done,  0,16 seconds.

  Running Repair Under System Account
  Done (28.02.2015 23:37:51)

27 - Set Windows Services To Default Startup
  Start (28.02.2015 23:37:51)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:37:59)

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

31 - Repair Windows 'New' Submenu
  Start (28.02.2015 23:37:59)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (28.02.2015 23:38:01)

Cleaning up empty logs...

All Selected Repairs Done.
  Done at (28.02.2015 23:38:01)
  Total Repair Time: 00:14:24


...YOU MUST RESTART YOUR SYSTEM...

der cbs log kann ich nicht schicken, editor verweigert mit den zugang


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131