![]() |
so das neuste ohne w updates , mit firefox FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 |
Auf den ersten Blick gut, aber: Ich seh nen Windows.old Ordner, das bedeutet du hast nicht formatiert, du hast drüber installiert. Bei nem FileInfector ne echt besch.... idee ;) Mach mal nen ESET Onlinescan. |
ja ich dachte bei der instalation wir automatisch formattiert hier der eset scn C:\Windows.old\Documents and Settings\user\AppData\Local\Anwendungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Documents and Settings\user\AppData\Local\Anwendungsdaten\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Documents and Settings\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Documents and Settings\user\AppData\Local\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Documents and Settings\user\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Documents and Settings\user\Lokale Einstellungen\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Users\user\AppData\Local\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Users\user\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application C:\Windows.old\Users\user\Lokale Einstellungen\Temporary Internet Files\Content.IE5\1PSL574Y\LyricsContainer_1060-8001_v122[1] a variant of Win32/Adware.AddLyrics.I application |
Lösch den Ordner Winodws.old, dann sollte alles gut sein :) |
Ok erst mal nochmal vielen Dank :crazy: Das neue System läuft rund, AVG antivir zeigt keine Fehler, ich hänge aber nochmal n frst scan an kann nicht schaden kommt mir aber sauber vor.. Gruss FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 (ATTENTION: ====> FRST version is 8 days old and could be outdated) |
ist auch sauber :) |
weitere merkwürdigkeiten hi wieder probleme nach dl eines mmorpg (silkroad) erkennt avg viele trojaner ich hab aber das directory und alles gleich geloescht aber irgendwas ist falsch system laeuft langsam hoch das avg scan log find ich eben nicht gmer scan GMER Logfile: Code: GMER 2.1.19163 - hxxp://www.gmer.net frst FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 (ATTENTION: ====> FRST version is 38 days old and could be outdated) |
Das Log von AVG brauch ich aber. Schau mal in AVG selbst. |
ich find kein log file von avg. das neueste scan berichtet keine fehler nachdem ich diese grosse rar datei geloescht habe aber das davor hat 200 dateien gesichert zB aus c:\eclipse was immer das heist (gesichert?, die waren infiziert und sind jetzt weg, quarantäne, wo?) z.B. vieles aus c:\eclipse ich kann den alten sicherungsbericht nicht in txt datei umwandeln oder alle einzeln entsichern. schlecht dokumentiert. oder ich loesch und installier c:\eclipse neu? :wtf: |
nee lass. Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
okAdwCleaner Logfile: Code: # AdwCleaner v3.002 - Bericht erstellt am 05/09/2013 um 11:52:43 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.7 (09.01.2013:1) OS: Windows 7 Ultimate x64 Ran by juergi on 05.09.2013 at 11:55:34,01 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3021084168-3049403070-40832557-1000\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthelper.exe Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\qvo6software Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r429-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r429-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r429-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r429-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} ~~~ Files Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk Successfully disinfected: [Shortcut] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Successfully disinfected: [Shortcut] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\microsoft\windows\start menu\Programs\Internet Explorer (64-bit).lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\microsoft\windows\start menu\Programs\Internet Explorer.lnk Successfully disinfected: [Shortcut] C:\Users\juergi\AppData\Roaming\microsoft\windows\start menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Successfully disinfected: [Shortcut] C:\Users\Public\Desktop\Google Chrome.lnk Successfully disinfected: [Shortcut] C:\Users\Public\Desktop\Mozilla Firefox.lnk ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\esafe" ~~~ FireFox Successfully deleted the following from C:\Users\juergi\AppData\Roaming\mozilla\firefox\profiles\s5bkhtd7.default\prefs.js user_pref("browser.newtab.url", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=OCZ-AGILITY3_OCZ-56LXG2GV412AN888&ts=1378210189" user_pref("browser.search.defaultenginename", "qvo6"); user_pref("browser.search.order.1", "qvo6"); user_pref("browser.search.selectedEngine", "qvo6"); user_pref("browser.startup.homepage", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=OCZ-AGILITY3_OCZ-56LXG2GV412AN888&ts=13782 Emptied folder: C:\Users\juergi\AppData\Roaming\mozilla\firefox\profiles\s5bkhtd7.default\minidumps [31 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.09.2013 at 12:01:09,29 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
Frisches FRST log bitte. Noch Probleme? |
Ok scheint soweit ok : dies googlupdate ist ueberfluessig und was ist /windows/erunt ?? FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 (ATTENTION: ====> FRST version is 39 days old and could be outdated) |
erunt ist eins unserer Programme, zum Sichern der Registry. Fertig :) Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
hi wieder ähnliche Probs nach dl von jdownloader hab wohl nen fake erwischt unterstrichenen Wörter auf alle websites und "Ihr kompi ist zu langsam" mist führte dann aus TFC adwcleaner neuste jrt neuste gmer frst 64 ohne zu fixen effekt immer noch da... alle logfilesAdwCleaner Logfile: Code: # AdwCleaner v3.005 - Bericht erstellt am 24/09/2013 um 17:15:28 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ GMER Logfile: Code: GMER 2.1.19163 - GMER - Rootkit Detector and Remover FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 (ATTENTION: ====> FRST version is 58 days old and could be outdated) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:21 Uhr. |
Copyright ©2000-2025, Trojaner-Board