![]() |
Weißer Bildschirm Beim Windows Start Beim Start von Windows Kommt sofort ein Weißes Fenster, Ich Kann den pc nur noch runter fahren Bitte Um Hilfe :dankeschoen::dankeschoen: Gruß Tecker |
hi, Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil) |
hABE ICH GEMACHT |
FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-10-2013 |
Drücke bitte die ![]() Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Rechner normal starten. |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-10-2013 Ran by DetlefRita at 2013-10-21 09:36:14 Run:1 Running from F:\ Boot Mode: Safe Mode (minimal) ============================================== Content of fixlist: ***************** HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path) HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\DetlefRita\AppData\Roaming\Other.res <==== ATTENTION HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess? Startup: C:\Users\DetlefRita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe () S1 ahosqxar; \??\C:\Windows\system32\drivers\ahosqxar.sys [x] S1 brdsrvtp; \??\C:\Windows\system32\drivers\brdsrvtp.sys [x] S1 dnktfgrs; \??\C:\Windows\system32\drivers\dnktfgrs.sys [x] S1 ecoebjfn; \??\C:\Windows\system32\drivers\ecoebjfn.sys [x] S1 edvkzncg; \??\C:\Windows\system32\drivers\edvkzncg.sys [x] S1 ghiydwpc; \??\C:\Windows\system32\drivers\ghiydwpc.sys [x] S1 gjiemiap; \??\C:\Windows\system32\drivers\gjiemiap.sys [x] S1 kfunemhq; \??\C:\Windows\system32\drivers\kfunemhq.sys [x] S1 lpasmkji; \??\C:\Windows\system32\drivers\lpasmkji.sys [x] S1 qkirfgka; \??\C:\Windows\system32\drivers\qkirfgka.sys [x] C:\Users\DetlefRita\AppData\Roaming\settings.ini ZeroAccess: C:\Users\DetlefRita\AppData\Local\Google\Desktop\Install C:\ProgramData\wavav0bdtzbtb43b.bat C:\ProgramData\wavav0bdtzbtb43b.reg C:\Users\DetlefRita\DSETUP.dll C:\Users\DetlefRita\dsetup32.dll C:\Users\DetlefRita\DXSETUP.exe C:\Users\DetlefRita\AppData\Roaming\i.iniC:\Users\DetlefRita\AppData\Local\Temp\AskSLib.dll C:\Users\DetlefRita\AppData\Local\Temp\avgnt.exe C:\Users\DetlefRita\AppData\Local\Temp\hrsccgwfpgftegakuj.exe C:\Users\DetlefRita\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\DetlefRita\AppData\Local\Temp\omqlxpopnvigkqhfbgoxdbktrubkr.exe 2013-10-05 18:06 - 2013-10-05 18:06 - 00131072 _____ C:\Users\DetlefRita\etjswxafswdjqwdmndy.bfg ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update* => Value deleted successfully. HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. C:\Users\DetlefRita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe => Moved successfully. ahosqxar => Service deleted successfully. brdsrvtp => Service deleted successfully. dnktfgrs => Service deleted successfully. ecoebjfn => Service deleted successfully. edvkzncg => Service deleted successfully. ghiydwpc => Service deleted successfully. gjiemiap => Service deleted successfully. kfunemhq => Service deleted successfully. lpasmkji => Service deleted successfully. qkirfgka => Service deleted successfully. C:\Users\DetlefRita\AppData\Roaming\settings.ini => Moved successfully. C:\Users\DetlefRita\AppData\Local\Google\Desktop\Install => Moved successfully. C:\ProgramData\wavav0bdtzbtb43b.bat => Moved successfully. C:\ProgramData\wavav0bdtzbtb43b.reg => Moved successfully. C:\Users\DetlefRita\DSETUP.dll => Moved successfully. C:\Users\DetlefRita\dsetup32.dll => Moved successfully. C:\Users\DetlefRita\DXSETUP.exe => Moved successfully. "C:\Users\DetlefRita\AppData\Roaming\i.iniC:\Users\DetlefRita\AppData\Local\Temp\AskSLib.dll" => File/Directory not found. C:\Users\DetlefRita\AppData\Local\Temp\avgnt.exe => Moved successfully. C:\Users\DetlefRita\AppData\Local\Temp\hrsccgwfpgftegakuj.exe => Moved successfully. C:\Users\DetlefRita\AppData\Local\Temp\InstallFlashPlayer.exe => Moved successfully. C:\Users\DetlefRita\AppData\Local\Temp\omqlxpopnvigkqhfbgoxdbktrubkr.exe => Moved successfully. C:\Users\DetlefRita\etjswxafswdjqwdmndy.bfg => Moved successfully. ==== End of Fixlog ==== |
Startet der Rechner normal? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 18:40 Uhr. |
Copyright ©2000-2025, Trojaner-Board