![]() |
|
Log-Analyse und Auswertung: Windows Vista 32 Bit: Browserseiten/fenster werden selbständig aufgerufenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #9 |
| ![]() Windows Vista 32 Bit: Browserseiten/fenster werden selbständig aufgerufen Hey, als ich Online ging um ESET das Update machen zu lassen, hat es wieder angefangen Fenster zu öffnen. Hab trotzdem mal alles zu Ende gemacht. Kann das sein, dass sich das einfach nachläd? Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=a88f21587638f644998b069de4bc0e32 # engine=23879 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-05-16 04:54:49 # local_time=2015-05-16 06:54:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 271787 54775683 0 0 # scanned=117900 # found=2 # cleaned=0 # scan_time=7764 sh=EB5485B5A125AFBEB61D1CE1F706A29C7699AE03 ft=1 fh=c5633cde84af1b8e vn="Variante von Win32/ReImageRepair.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\user\Downloads\ReimageRepair (1).exe" sh=E5E55F157C1CC8F09FD2FDE4D943CFA502A8E636 ft=0 fh=0000000000000000 vn="Win32/SweetIM.J evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\LocalLow\SweetNT.crx" Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-05-2015 01 Ran by user at 2015-05-16 14:54:02 Run:1 Running from C:\Users\user\Desktop Loaded Profiles: user (Available profiles: user) Boot Mode: Normal ============================================== Content of fixlist: ***************** start CloseProcesses: HKU\S-1-5-21-3645637860-4088369842-987407559-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION FirewallRules: [{15E6AFDE-298E-469F-A3FA-F6EFDF573324}] => (Allow) C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe FirewallRules: [{5E7C4CFC-68D1-4826-B30C-E36F8F6A0A13}] => (Allow) C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe FirewallRules: [{E343569E-504F-4AD2-8AD7-EC0ECF174333}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{893737F0-2F57-4775-8E84-011CE9AF6758}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{06E3F4C0-40D8-44F4-92DD-17BFE8158226}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{4128CE8A-BEEA-4C9F-832E-7435FE28F9A5}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{3289E00E-73F9-4EEB-8A4C-A38B28FA627C}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{9DBF4A2F-E86B-4FD7-BB9D-2F5719711690}] => (Allow) C:\Windows\System32\dmwu.exe folder: C:\Users\user\AppData\Local\Apps\2.0 RemoveProxy: EmptyTemp: end ***************** Processes closed successfully. "HKU\S-1-5-21-3645637860-4088369842-987407559-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{15E6AFDE-298E-469F-A3FA-F6EFDF573324} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5E7C4CFC-68D1-4826-B30C-E36F8F6A0A13} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E343569E-504F-4AD2-8AD7-EC0ECF174333} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{893737F0-2F57-4775-8E84-011CE9AF6758} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{06E3F4C0-40D8-44F4-92DD-17BFE8158226} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4128CE8A-BEEA-4C9F-832E-7435FE28F9A5} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3289E00E-73F9-4EEB-8A4C-A38B28FA627C} => value deleted successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9DBF4A2F-E86B-4FD7-BB9D-2F5719711690} => value deleted successfully. ========================= folder: C:\Users\user\AppData\Local\Apps\2.0 ======================== 2015-05-10 23:45 - 2015-05-10 23:45 - 0000000 ____D () C:\Users\user\AppData\Local\Apps\2.0\8X9PQCZW.KW8 2015-05-10 23:45 - 2015-05-10 23:45 - 0000000 ____D () C:\Users\user\AppData\Local\Apps\2.0\8X9PQCZW.KW8\OGVKHC8G.6P9 2015-05-10 23:45 - 2015-05-10 23:45 - 0000000 ____D () C:\Users\user\AppData\Local\Apps\2.0\8X9PQCZW.KW8\OGVKHC8G.6P9\manifests ====== End of Folder: ====== ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. HKU\S-1-5-21-3645637860-4088369842-987407559-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\S-1-5-21-3645637860-4088369842-987407559-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. ========= End of RemoveProxy: ========= EmptyTemp: => Removed 1.1 GB temporary data. The system needed a reboot. ==== End of Fixlog 14:59:20 ==== Code:
ATTFilter Results of screen317's Security Check version 1.001 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` JavaFX 2.1.1 Java 7 Update 17 Java version 32-bit out of Date! Adobe Flash Player 9 Flash Player out of Date! Adobe Flash Player 17.0.0.169 Adobe Reader 10.1.6 Adobe Reader out of Date! Mozilla Firefox (37.0.2) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Geändert von Swissi (16.05.2015 um 18:20 Uhr) |
Themen zu Windows Vista 32 Bit: Browserseiten/fenster werden selbständig aufgerufen |
adware/perinet.d.1, adware/perinet.d.2, adware/perinet.lasc.1, adware/yontoo.gen2, antivirus, entfernen, fehlercode %nt-autorität607, fehlercode 0x0, fehlercode 0x8007006d, fehlercode windows, flash player, iexplore.exe, internet, internet explorer, launch, maleware, programm, pup.optional.sweetim, pup.optional.sweetpacks.a, registry, software, svchost.exe, win32/reimagerepair.b, win32/sweetim.j |