Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7 Home Premium - SpyHunter 4 deinstallieren

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 11.09.2014, 14:55   #11
SirRolus
 
Windows 7 Home Premium - SpyHunter 4 deinstallieren - Standard

Windows 7 Home Premium - SpyHunter 4 deinstallieren



Moin,

Schritt 1:

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01
Ran by Rolf at 2014-09-11 13:08:10 Run:1
Running from C:\Users\Rolf\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION 
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION 
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION 
SearchScopes: HKCU - {0B47E39E-CC7D-402E-90D9-0CB0E4441D7E} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3297969&CUI=UN36078130452709221&UM=1
C:\ProgramData\iodvf4bn.fee
C:\Users\MC\Firefox_Setup_3.0.19.exe
C:\Users\Rolf\6189140.dll
C:\Users\Rolf\AppData\Roaming\skype.ini
Task: {1912D3EB-FE3A-440F-B559-1970D3A79EAB} - System32\Tasks\{FD9269D2-5D38-4BCF-A7FB-CD06F93250AF} => Firefox.exe 
Task: {3331F12C-D0B5-47DE-A5C7-7B35F7F52C0F} - System32\Tasks\{69B4B3B8-A64F-41DE-88CF-4F324DFBE922} => Firefox.exe 
Task: {51754C10-68D3-4D3D-8202-260883961A8F} - System32\Tasks\{05BDFB23-0F8C-4C5A-B2C6-DA9D84C1FA38} => Firefox.exe 
Task: {6C808585-893A-4DAF-9525-2D672D678999} - System32\Tasks\{186EC9AA-810B-4B45-BF43-ABEA5546A681} => Firefox.exe 
Task: {78540C57-559F-4A50-A976-A259650C0B27} - System32\Tasks\{33EA3D89-AE11-4A13-A70F-E690857C0E72} => Firefox.exe 
Task: {85C39D71-F034-416D-B551-8D3913292C2F} - System32\Tasks\{2818F012-A066-45E2-BC7B-2D03A36F26E1} => Firefox.exe 
Task: {9E6D862B-3ED0-4B4E-A7B3-661CDB376278} - System32\Tasks\{1AB5D059-0D47-48B2-9055-02C565622DAA} => Firefox.exe 
Task: {BC6FA306-5B20-4E8C-BD17-D0F9B624E8B3} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
Task: {E3F8AD3F-EEED-4EB3-B187-2C6BBE3B462D} - System32\Tasks\4584 => Wscript.exe C:\Users\Rolf\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {F1B2581F-873F-4EAD-8E55-691BE65143DE} - System32\Tasks\{FF23ABBD-B04B-4EB4-8839-D959D9A1B31B} => Firefox.exe 
C:\Windows\pss\ctfmon.lnk.Startup
C:\Windows\pss\runctf.lnk.Startup
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rolf^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rolf^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^runctf.lnk
EmptyTemp:
end
         
*****************

Processes closed successfully.
HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B47E39E-CC7D-402E-90D9-0CB0E4441D7E}" => Key deleted successfully.
"HKCR\CLSID\{0B47E39E-CC7D-402E-90D9-0CB0E4441D7E}" => Key not found.
C:\ProgramData\iodvf4bn.fee => Moved successfully.
C:\Users\MC\Firefox_Setup_3.0.19.exe => Moved successfully.
C:\Users\Rolf\6189140.dll => Moved successfully.
C:\Users\Rolf\AppData\Roaming\skype.ini => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1912D3EB-FE3A-440F-B559-1970D3A79EAB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1912D3EB-FE3A-440F-B559-1970D3A79EAB}" => Key deleted successfully.
C:\Windows\System32\Tasks\{FD9269D2-5D38-4BCF-A7FB-CD06F93250AF} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FD9269D2-5D38-4BCF-A7FB-CD06F93250AF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3331F12C-D0B5-47DE-A5C7-7B35F7F52C0F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3331F12C-D0B5-47DE-A5C7-7B35F7F52C0F}" => Key deleted successfully.
C:\Windows\System32\Tasks\{69B4B3B8-A64F-41DE-88CF-4F324DFBE922} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{69B4B3B8-A64F-41DE-88CF-4F324DFBE922}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{51754C10-68D3-4D3D-8202-260883961A8F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51754C10-68D3-4D3D-8202-260883961A8F}" => Key deleted successfully.
C:\Windows\System32\Tasks\{05BDFB23-0F8C-4C5A-B2C6-DA9D84C1FA38} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{05BDFB23-0F8C-4C5A-B2C6-DA9D84C1FA38}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C808585-893A-4DAF-9525-2D672D678999}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C808585-893A-4DAF-9525-2D672D678999}" => Key deleted successfully.
C:\Windows\System32\Tasks\{186EC9AA-810B-4B45-BF43-ABEA5546A681} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{186EC9AA-810B-4B45-BF43-ABEA5546A681}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78540C57-559F-4A50-A976-A259650C0B27}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78540C57-559F-4A50-A976-A259650C0B27}" => Key deleted successfully.
C:\Windows\System32\Tasks\{33EA3D89-AE11-4A13-A70F-E690857C0E72} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{33EA3D89-AE11-4A13-A70F-E690857C0E72}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85C39D71-F034-416D-B551-8D3913292C2F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85C39D71-F034-416D-B551-8D3913292C2F}" => Key deleted successfully.
C:\Windows\System32\Tasks\{2818F012-A066-45E2-BC7B-2D03A36F26E1} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2818F012-A066-45E2-BC7B-2D03A36F26E1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9E6D862B-3ED0-4B4E-A7B3-661CDB376278}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E6D862B-3ED0-4B4E-A7B3-661CDB376278}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1AB5D059-0D47-48B2-9055-02C565622DAA} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1AB5D059-0D47-48B2-9055-02C565622DAA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC6FA306-5B20-4E8C-BD17-D0F9B624E8B3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC6FA306-5B20-4E8C-BD17-D0F9B624E8B3}" => Key deleted successfully.
C:\Windows\System32\Tasks\0 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3F8AD3F-EEED-4EB3-B187-2C6BBE3B462D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3F8AD3F-EEED-4EB3-B187-2C6BBE3B462D}" => Key deleted successfully.
C:\Windows\System32\Tasks\4584 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4584" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F1B2581F-873F-4EAD-8E55-691BE65143DE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1B2581F-873F-4EAD-8E55-691BE65143DE}" => Key deleted successfully.
C:\Windows\System32\Tasks\{FF23ABBD-B04B-4EB4-8839-D959D9A1B31B} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FF23ABBD-B04B-4EB4-8839-D959D9A1B31B}" => Key deleted successfully.
C:\Windows\pss\ctfmon.lnk.Startup => Moved successfully.
C:\Windows\pss\runctf.lnk.Startup => Moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rolf^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rolf^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^runctf.lnk => Key Deleted successfully.
EmptyTemp: => Removed 975.2 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         
Zu Schritt 2 habe ich folgende Frage:

Geht das ganze auch Offline? Ich habe Manschetten 3 Stunden ohne Firewall online zu sein.

tschau sirrolus

 

Themen zu Windows 7 Home Premium - SpyHunter 4 deinstallieren
ask.com-toolbar, conduitsearch, conduitsearch entfernen, fehlercode 0x40000015, fehlercode 0x5, fehlercode 0xc0000005, spy hunter 4, spyhunter, spyhunter entfernen, win32/koyotelab.a, win32/reveton.j, win32/reveton.m, win32/toolbar.babylon.f, win32/toolbar.babylon.i, win32/toolbar.babylon.w, win32/toolbar.conduit.y, win32/toolbar.iminent.e, win32/toolbar.montiera.b, win32/toolbar.searchsuite.m, win64/toolbar.searchsuite.a, win64/toolbar.searchsuite.b, window 7, ändern




Ähnliche Themen: Windows 7 Home Premium - SpyHunter 4 deinstallieren


  1. Win7 Home Premium 64 Bit Malware Colormedia + Plus-HD-1.6 + Spyhunter wie entfernen?
    Log-Analyse und Auswertung - 12.05.2015 (10)
  2. Windows 7 Home Premium SP1 Langsam
    Log-Analyse und Auswertung - 03.05.2015 (7)
  3. Windows 7 Home Premium - Avast - Gruppenrichtlinie
    Log-Analyse und Auswertung - 04.11.2014 (5)
  4. WIndows Vista Home Premium: Avira lässt sich nicht deinstallieren (Gruppenrichtlinie)
    Log-Analyse und Auswertung - 17.08.2014 (9)
  5. Umstellung xp zu windows 7 home premium
    Alles rund um Windows - 20.03.2014 (5)
  6. Windows 7 Home Premium Stürzt ab/PC Neustart
    Alles rund um Windows - 17.12.2013 (3)
  7. Windows / Home Premium BKA/Interpol Speerbildschirm
    Log-Analyse und Auswertung - 13.10.2013 (3)
  8. GVU-Trojaner mit Windows 7 Home Premium
    Log-Analyse und Auswertung - 28.08.2013 (19)
  9. Gvu Trojaner unter Windows 7 home Premium
    Plagegeister aller Art und deren Bekämpfung - 06.08.2013 (1)
  10. Windows 7 Home Premium auf Laptop neu aufspielen
    Alles rund um Windows - 21.07.2013 (13)
  11. GVU Trojaner 2.07 Windows Vista Home Premium
    Plagegeister aller Art und deren Bekämpfung - 28.06.2013 (5)
  12. Polizeivirus auf Windows Vista Home Premium
    Plagegeister aller Art und deren Bekämpfung - 13.10.2012 (33)
  13. Backdoor.bot auf Windows-7 Home Premium (x64)
    Plagegeister aller Art und deren Bekämpfung - 08.10.2012 (49)
  14. GVU Trojaner 2.07 - Windows Vista Home Premium 32 Bit
    Log-Analyse und Auswertung - 07.10.2012 (6)
  15. BKA Trojaner - Windows 7 Home Premium 64bit
    Plagegeister aller Art und deren Bekämpfung - 12.08.2012 (17)
  16. Windows 7 Home Premium 64 Bit laptop brennen
    Alles rund um Windows - 05.06.2010 (1)
  17. VIRUSS! Windows Vista Home Premium
    Alles rund um Windows - 10.04.2010 (3)

Zum Thema Windows 7 Home Premium - SpyHunter 4 deinstallieren - Moin, Schritt 1: Code: Alles auswählen Aufklappen ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01 Ran by Rolf at 2014-09-11 13:08:10 Run:1 Running - Windows 7 Home Premium - SpyHunter 4 deinstallieren...
Archiv
Du betrachtest: Windows 7 Home Premium - SpyHunter 4 deinstallieren auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.