![]() |
| |||||||
Log-Analyse und Auswertung: Advanced System Protector entfernen bei Windows 7Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #9 |
| | Advanced System Protector entfernen bei Windows 7 Hallo M-K-D-B, musste bei HitmanPro die Firewall deaktivieren.... Wow, endlich alles durchgelaufen, hat ja schon lange gedauert. Hier die logfiles: Fixlog von FRTS: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by **** at 2014-04-04 19:50:33 Run:1
Running from C:\Users\****\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - !{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - No Name - !{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
C:\Users\AppData\LocalLow\Conduit
Task: {4D1883FA-CDF8-4302-9533-CE4DAD64F20C} - \Advanced System Protector_startup No Task File
Task: {B38113D7-5543-4A2F-91A6-7231B0A9DD21} - \Advanced System Protector No Task File
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\Iminent.Messengers.exe" /f
Reg: reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f
end
*****************
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\!{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Value deleted successfully.
HKCR\CLSID\!{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\!{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\!{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found.
C:\Users\AppData\LocalLow\Conduit => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4D1883FA-CDF8-4302-9533-CE4DAD64F20C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D1883FA-CDF8-4302-9533-CE4DAD64F20C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector_startup => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B38113D7-5543-4A2F-91A6-7231B0A9DD21} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B38113D7-5543-4A2F-91A6-7231B0A9DD21} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector => Key deleted successfully.
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\Iminent.Messengers.exe" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
==== End of Fixlog ====
Code:
ATTFilter HitmanPro 3.7.9.216
www.hitmanpro.com
Computer name . . . . : ****-HP
Windows . . . . . . . : 6.1.1.7601.X64/4
User name . . . . . . : ****-HP\****
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2014-04-04 20:08:49
Scan mode . . . . . . : Normal
Scan duration . . . . : 9m 24s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 85
Objects scanned . . . : 2.458.570
Files scanned . . . . : 173.342
Remnants scanned . . : 823.456 files / 1.461.772 keys
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\Unknown\shell\openas\command\Advanced System Protector.bak (AdvSysProtector) -> Deleted
HKLM\SOFTWARE\Classes\Unknown\shell\opendlg\command\Advanced System Protector.bak (AdvSysProtector) -> Deleted
HKU\S-1-5-21-3883071668-826525904-3960972044-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} (SearchQU) -> Deleted
HKU\S-1-5-21-3883071668-826525904-3960972044-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4f12-8568-69135F087DB0},\ (SearchQU) -> Deleted
Cookies _____________________________________________________________________
C:\Users\Administrator.****-HP\AppData\Roaming\Mozilla\Firefox\Profiles\r2edbjxf.default\cookies.sqlite:apmebf.com
C:\Users\Administrator.****-HP\AppData\Roaming\Mozilla\Firefox\Profiles\r2edbjxf.default\cookies.sqlite:doubleclick.net
C:\Users\Administrator.****-HP\AppData\Roaming\Mozilla\Firefox\Profiles\r2edbjxf.default\cookies.sqlite:mediaplex.com
C:\Users\Administrator.****-HP\AppData\Roaming\Mozilla\Firefox\Profiles\r2edbjxf.default\cookies.sqlite:www.googleadservices.com
C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:247realmedia.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:2o7.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:3276817.fls.doubleclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad-emea.doubleclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.123-template.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.360yield.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.ad-srv.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.adc-serv.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.adnet.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.dyntracker.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.movad.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.torrentus.to
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.betweendigital.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.creative-serving.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.dk-online.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.escinteractive.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.p161.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.pubmatic.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.stickyadstv.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ads.yahoo.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:adtech.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:adtechus.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:advertising.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:adviva.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:apmebf.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ar.atwola.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:at.atwola.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:atdmt.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:bs.serving-sys.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:burstnet.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:casalemedia.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:conrad.122.2o7.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:cunda.122.2o7.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:de.sitestat.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:doubleclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:eas.apm.emediate.eu
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:emjcd.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:fastclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:googleads.g.doubleclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:in.getclicky.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:invitemedia.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:loyaltypartner.122.2o7.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:media6degrees.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:mediaplex.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:overture.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:paypal.112.2o7.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:pool-eu-ie.creative-serving.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:realmedia.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:revsci.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ru4.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:serving-sys.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:smartadserver.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:specificclick.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:stat.dealtime.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:statcounter.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:stats.paypal.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:stats.webstarts.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:statse.webtrendslive.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:tacoda.at.atwola.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:track.adform.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:track.effiliation.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:track.hubrus.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:track.tnm.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:track.zalando.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:tradedoubler.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:tribalfusion.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:uk.at.atwola.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:ww251.smartadserver.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:www.etracker.de
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:www.googleadservices.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:www4.smartadserver.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:xiti.com
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:yadro.ru
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:yieldmanager.net
C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\uttrjezt.default\cookies.sqlite:zedo.com
ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=50d4b86b7283a345b2fb7198feaa51bf
# engine=17760
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-04 11:16:44
# local_time=2014-04-05 01:16:44 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 77 0 4669194 0 0
# compatibility_mode=3074 16777213 100 100 28020058 98969386 0 0
# compatibility_mode=5893 16776573 100 94 42514 148283254 0 0
# scanned=153630
# found=0
# cleaned=0
# scan_time=17351
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=50d4b86b7283a345b2fb7198feaa51bf
# engine=17763
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-05 09:33:06
# local_time=2014-04-05 11:33:06 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 77 0 4706176 0 0
# compatibility_mode=3074 16777213 100 100 28057040 99006368 0 0
# compatibility_mode=5893 16776573 100 94 79496 148320236 0 0
# scanned=450034
# found=0
# cleaned=0
# scan_time=34198
und SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.80
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus out of date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 51
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 12.0.0.77
Adobe Reader 10.1.9 Adobe Reader out of Date!
Mozilla Firefox (28.0)
````````Process Check: objlist.exe by Laurent````````
Comodo Firewall cmdagent.exe
Comodo Firewall cfp.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
Lg Melian |
| Themen zu Advanced System Protector entfernen bei Windows 7 |
| 4d36e972-e325-11ce-bfc1-08002be10318, advanced system protector, antivirus, branding, checkliste, converter, device driver, excel, flash player, homepage, iexplore.exe, koyote, programm, pup.optional.datamngr.a, pup.optional.feven.a, pup.optional.iminent.a, pup.optional.searchqu, schädling, services.exe, siteadvisor, svchost.exe, symantec, vista, windows |