![]() |
Ich warte auf Schritt 4. |
Den habe ich gemacht, aber was weiter? Sie hatten mir dazu keine weiteren Anweisungen gegeben. |
Poste bitte die Logs davon. |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-06-2014 Ran by Br. Pirminius Seber at 2014-06-18 21:54:47 Run:1 Running from C:\Users\Br. Pirminius Seber\Downloads\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\Run: [iLivid] => C:\Users\Br. Pirminius Seber\AppData\Local\iLivid\iLivid.exe [6827008 2013-09-09] (Bandoo Media Inc.) HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: F - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {6990a982-fa63-11e1-9c64-b888e31620a2} - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {7788dee7-f745-11e1-9ecd-b888e31620a2} - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {7788def6-f745-11e1-9ecd-b888e31620a2} - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {7788df31-f745-11e1-9ecd-b888e31620a2} - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {c40c67f7-12a4-11e2-9840-74e543436fc5} - F:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: {d6e0105c-6e9f-11e2-8ff2-b888e31620a2} - F:\autorun.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found ProxyServer: http=:;https=: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = WebSearches HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = WebSearches HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1396034803&from=tugs&uid=TOSHIBAXMK5075GSX_52BJCFG5TXX52BJCFG5T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = WebSearches HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = WebSearches HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396034803&from=tugs&uid=TOSHIBAXMK5075GSX_52BJCFG5TXX52BJCFG5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1396034803&from=tugs&uid=TOSHIBAXMK5075GSX_52BJCFG5TXX52BJCFG5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = WebSearches HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = WebSearches HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396034803&from=tugs&uid=TOSHIBAXMK5075GSX_52BJCFG5TXX52BJCFG5T&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe WebSearches BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120902183624.dll No File BHO-x32: Caramava - {1e50bbda-c15a-47d5-9853-d829ff890664} - C:\Program Files (x86)\Caramava\Caramavabho.dll No File BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120902183624.dll No File Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Winsock: Catalog9 01 C:\Windows\SysWOW64\SecureAssist.dll [295080] (SecureAssist) Winsock: Catalog9 02 C:\Windows\SysWOW64\SecureAssist.dll [295080] (SecureAssist) Winsock: Catalog9 03 C:\Windows\SysWOW64\SecureAssist.dll [295080] (SecureAssist) Winsock: Catalog9 04 C:\Windows\SysWOW64\SecureAssist.dll [295080] (SecureAssist) Winsock: Catalog9 15 C:\Windows\SysWOW64\SecureAssist.dll [295080] (SecureAssist) Winsock: Catalog9-x64 01 C:\Windows\system32\SecureAssist64.dll [338120] (SecureAssist) Winsock: Catalog9-x64 02 C:\Windows\system32\SecureAssist64.dll [338120] (SecureAssist) Winsock: Catalog9-x64 03 C:\Windows\system32\SecureAssist64.dll [338120] (SecureAssist) Winsock: Catalog9-x64 04 C:\Windows\system32\SecureAssist64.dll [338120] (SecureAssist) Winsock: Catalog9-x64 15 C:\Windows\system32\SecureAssist64.dll [338120] (SecureAssist) FF DefaultSearchEngine: webssearches R2 SecureAssist; C:\Program Files\SupraSavings\SecureAssist.exe [1558032 2014-03-12] (SecureAssist) [File not signed] S2 Update Caramava; "C:\Program Files (x86)\Caramava\updateCaramava.exe" [X] S2 Util Caramava; "C:\Program Files (x86)\Caramava\bin\utilCaramava.exe" [X] R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-03-29] (StdLib) 2014-06-18 15:26 - 2014-03-28 21:26 - 00000334 _____ () C:\Windows\Tasks\SaveSense.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00002576 _____ () C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001896 _____ () C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001892 _____ () C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001792 _____ () C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001786 _____ () C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001720 _____ () C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2.job 2014-06-18 14:49 - 2014-03-28 20:14 - 00001716 _____ () C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2.job 2014-06-18 14:49 - 2014-03-28 20:13 - 00003468 _____ () C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3.job 2014-06-18 14:49 - 2014-03-28 20:13 - 00003466 _____ () C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3.job 2014-06-18 14:49 - 2014-03-28 20:13 - 00002578 _____ () C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4.job 2014-06-18 13:45 - 2013-10-30 19:29 - 00000000 ____D () C:\Users\Br. Pirminius Seber\AppData\Local\iLivid 2014-06-18 13:42 - 2014-03-28 21:29 - 00000000 ____D () C:\Users\Br. Pirminius Seber\AppData\Local\Tuguu_SL 2014-06-18 13:42 - 2014-03-28 21:28 - 00000000 ____D () C:\Users\Br. Pirminius Seber\AppData\Roaming\SupTab 2014-06-18 13:42 - 2014-03-28 21:27 - 00000000 ____D () C:\Program Files\suprasavings 2014-06-18 12:59 - 2014-06-17 20:44 - 00000000 ____D () C:\Program Files (x86)\ConstaSurf C:\Users\Br. Pirminius Seber\AppData\Local\Temp\25829-656347-openoffice.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\BackupSetup.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\cabex.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Caramava_bs.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\FixMyRegistry.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\instloffer.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfc80.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfc80u.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfcm80.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfcm80u.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcm80.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcp80.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcr80.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\OSU.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\PCSpeedMaximizer.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Quarantine.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SkypeSetup.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Somoto_23_03_2014(delay).exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SpeedUpMyComputer.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\speedupmypc.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SpOrder.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\stubhelper.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\unelevate.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Uninstaller.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\VersionUpdater.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WtgDriverInstallX.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WTGXMLUtil.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WtgZip.dll C:\Users\Br. Pirminius Seber\AppData\Local\Temp\ytai_ytareg_setup.exe Task: {02723420-C324-4033-9D54-D1C58B5C2B9C} - System32\Tasks\ShopperPro => C:\Program Files (x86)\ShopperPro\ShopperPro.exe <==== ATTENTION Task: {2E72B586-D272-4CF0-81BA-04BEF39AFCC9} - System32\Tasks\SPDriver => C:\Program Files (x86)\ShopperPro\JSDriver\1.35.1.155\jsdrv.exe <==== ATTENTION Task: {3CF585E3-A203-43CB-BBF1-C608B9FF06B5} - System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2 => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-2.exe <==== ATTENTION Task: {40ABC68F-87ED-4C69-A56E-4E4D95F35835} - System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1 => C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe <==== ATTENTION Task: {7216ABB7-626D-42B9-A692-CAEFFCB1CCFA} - System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3 => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-3.exe <==== ATTENTION Task: {7BD09033-2839-46D8-8D10-5BA7EE0958DF} - System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2 => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-2.exe <==== ATTENTION Task: {89AE3122-54EC-4511-9EDF-EE89B28AD869} - System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4 => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-4.exe <==== ATTENTION Task: {8D04FCCB-254B-4A93-BA8B-EF46881055C6} - System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1 => C:\Program Files (x86)\Sense\Sense-codedownloader.exe <==== ATTENTION Task: {94CD2741-56EF-4B90-A3AD-04F59638ABBF} - System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5 => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-5.exe <==== ATTENTION Task: {B2FF1A69-6E16-4126-AC47-61057E9D47E3} - System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4 => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-4.exe <==== ATTENTION Task: {B8B9E4A1-5F54-4687-8149-92E7BA6FB3DD} - System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3 => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-3.exe <==== ATTENTION Task: {BBBB4417-70D0-46D0-83D2-28D2D628C9DE} - System32\Tasks\SaveSense => C:\Users\BRD788~1.PIR\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {CC767EAC-B4BE-4F97-9067-BDDC780B074B} - System32\Tasks\ShopperProJSUpd => C:\Program Files (x86)\ShopperPro\updater.exe <==== ATTENTION Task: {FFFBD286-540E-4859-830C-C5FFE98DDE93} - System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5 => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-5.exe <==== ATTENTION Task: C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1.job => C:\Program Files (x86)\Sense\Sense-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2.job => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-2.exe <==== ATTENTION Task: C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3.job => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-3.exe <==== ATTENTION Task: C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4.job => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-4.exe <==== ATTENTION Task: C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5.job => C:\Program Files (x86)\Sense\10496340-28c0-47c5-8c23-0aac03e48614-5.exe <==== ATTENTION Task: C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1.job => C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2.job => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-2.exe <==== ATTENTION Task: C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3.job => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-3.exe <==== ATTENTION Task: C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4.job => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-4.exe <==== ATTENTION Task: C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5.job => C:\Program Files (x86)\iWebar\7c82d588-f306-4366-8f8b-71f85e442eb4-5.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSense.job => C:\Users\BRD788~1.PIR\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION AlternateDataStreams: C:\ProgramData\TEMP:AD022376 cmd: netsh winsock reset ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\Software\Microsoft\Windows\CurrentVersion\Run\\iLivid => value deleted successfully. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3090635963-4145032168-3900013317-1001'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6990a982-fa63-11e1-9c64-b888e31620a2}' => Key deleted successfully. 'HKCR\CLSID\{6990a982-fa63-11e1-9c64-b888e31620a2}'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7788dee7-f745-11e1-9ecd-b888e31620a2}' => Key deleted successfully. 'HKCR\CLSID\{7788dee7-f745-11e1-9ecd-b888e31620a2}'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7788def6-f745-11e1-9ecd-b888e31620a2}' => Key deleted successfully. 'HKCR\CLSID\{7788def6-f745-11e1-9ecd-b888e31620a2}'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7788df31-f745-11e1-9ecd-b888e31620a2}' => Key deleted successfully. 'HKCR\CLSID\{7788df31-f745-11e1-9ecd-b888e31620a2}'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c40c67f7-12a4-11e2-9840-74e543436fc5}' => Key deleted successfully. 'HKCR\CLSID\{c40c67f7-12a4-11e2-9840-74e543436fc5}'=> Key not found. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d6e0105c-6e9f-11e2-8ff2-b888e31620a2}' => Key deleted successfully. 'HKCR\CLSID\{d6e0105c-6e9f-11e2-8ff2-b888e31620a2}'=> Key not found. "C:\PROGRA~2\SupTab\SEARCH~2.DLL" => Value Data removed successfully. "C:\PROGRA~2\SupTab\SEARCH~1.DLL" => Value Data removed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}' => Key deleted successfully. 'HKCR\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}' => Key deleted successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1e50bbda-c15a-47d5-9853-d829ff890664}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{1e50bbda-c15a-47d5-9853-d829ff890664}' => Key deleted successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}' => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. 'HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}' => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. 'HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}'=> Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. 'HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}'=> Key not found. Winsock: Catalog entry 000000000001 => Deleted successfully. Winsock: Catalog entry 000000000002 => Deleted successfully. Winsock: Catalog entry 000000000003 => Deleted successfully. Winsock: Catalog entry 000000000004 => Deleted successfully. Winsock: Catalog entry 000000000015 => Deleted successfully. Winsock: Catalog entry 000000000001 => Deleted successfully. Winsock: Catalog entry 000000000002 => Deleted successfully. Winsock: Catalog entry 000000000003 => Deleted successfully. Winsock: Catalog entry 000000000004 => Deleted successfully. Winsock: Catalog entry 000000000015 => Deleted successfully. Firefox DefaultSearchEngine deleted successfully. SecureAssist => Service stopped successfully. SecureAssist => Service deleted successfully. Update Caramava => Service deleted successfully. Util Caramava => Service deleted successfully. wStLibG64 => Service stopped successfully. wStLibG64 => Service deleted successfully. C:\Windows\Tasks\SaveSense.job => Moved successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4.job => Moved successfully. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5.job => Moved successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5.job => Moved successfully. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1.job => Moved successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1.job => Moved successfully. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2.job => Moved successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2.job => Moved successfully. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3.job => Moved successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3.job => Moved successfully. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4.job => Moved successfully. "C:\Users\Br. Pirminius Seber\AppData\Local\iLivid" => File/Directory not found. C:\Users\Br. Pirminius Seber\AppData\Local\Tuguu_SL => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Roaming\SupTab => Moved successfully. C:\Program Files\suprasavings => Moved successfully. C:\Program Files (x86)\ConstaSurf => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\25829-656347-openoffice.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\BackupSetup.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\cabex.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Caramava_bs.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\FixMyRegistry.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\instloffer.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfc80.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfc80u.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfcm80.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\mfcm80u.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcm80.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcp80.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\msvcr80.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\OSU.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\PCSpeedMaximizer.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Quarantine.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SkypeSetup.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Somoto_23_03_2014(delay).exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SpeedUpMyComputer.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\speedupmypc.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\SpOrder.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\stubhelper.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\unelevate.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Uninstaller.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\VersionUpdater.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WtgDriverInstallX.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WTGXMLUtil.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\WtgZip.dll => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\ytai_ytareg_setup.exe => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02723420-C324-4033-9D54-D1C58B5C2B9C}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02723420-C324-4033-9D54-D1C58B5C2B9C}' => Key deleted successfully. C:\Windows\System32\Tasks\ShopperPro => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2E72B586-D272-4CF0-81BA-04BEF39AFCC9}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E72B586-D272-4CF0-81BA-04BEF39AFCC9}' => Key deleted successfully. C:\Windows\System32\Tasks\SPDriver => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3CF585E3-A203-43CB-BBF1-C608B9FF06B5}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CF585E3-A203-43CB-BBF1-C608B9FF06B5}' => Key deleted successfully. C:\Windows\System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7c82d588-f306-4366-8f8b-71f85e442eb4-2' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{40ABC68F-87ED-4C69-A56E-4E4D95F35835}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40ABC68F-87ED-4C69-A56E-4E4D95F35835}' => Key deleted successfully. C:\Windows\System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7c82d588-f306-4366-8f8b-71f85e442eb4-1' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7216ABB7-626D-42B9-A692-CAEFFCB1CCFA}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7216ABB7-626D-42B9-A692-CAEFFCB1CCFA}' => Key deleted successfully. C:\Windows\System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\10496340-28c0-47c5-8c23-0aac03e48614-3' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7BD09033-2839-46D8-8D10-5BA7EE0958DF}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BD09033-2839-46D8-8D10-5BA7EE0958DF}' => Key deleted successfully. C:\Windows\System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\10496340-28c0-47c5-8c23-0aac03e48614-2' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{89AE3122-54EC-4511-9EDF-EE89B28AD869}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89AE3122-54EC-4511-9EDF-EE89B28AD869}' => Key deleted successfully. C:\Windows\System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7c82d588-f306-4366-8f8b-71f85e442eb4-4' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8D04FCCB-254B-4A93-BA8B-EF46881055C6}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D04FCCB-254B-4A93-BA8B-EF46881055C6}' => Key deleted successfully. C:\Windows\System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\10496340-28c0-47c5-8c23-0aac03e48614-1' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{94CD2741-56EF-4B90-A3AD-04F59638ABBF}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94CD2741-56EF-4B90-A3AD-04F59638ABBF}' => Key deleted successfully. C:\Windows\System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7c82d588-f306-4366-8f8b-71f85e442eb4-5' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B2FF1A69-6E16-4126-AC47-61057E9D47E3}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2FF1A69-6E16-4126-AC47-61057E9D47E3}' => Key deleted successfully. C:\Windows\System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\10496340-28c0-47c5-8c23-0aac03e48614-4' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B8B9E4A1-5F54-4687-8149-92E7BA6FB3DD}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8B9E4A1-5F54-4687-8149-92E7BA6FB3DD}' => Key deleted successfully. C:\Windows\System32\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7c82d588-f306-4366-8f8b-71f85e442eb4-3' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BBBB4417-70D0-46D0-83D2-28D2D628C9DE}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBBB4417-70D0-46D0-83D2-28D2D628C9DE}' => Key deleted successfully. C:\Windows\System32\Tasks\SaveSense => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC767EAC-B4BE-4F97-9067-BDDC780B074B}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC767EAC-B4BE-4F97-9067-BDDC780B074B}' => Key deleted successfully. C:\Windows\System32\Tasks\ShopperProJSUpd => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FFFBD286-540E-4859-830C-C5FFE98DDE93}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFFBD286-540E-4859-830C-C5FFE98DDE93}' => Key deleted successfully. C:\Windows\System32\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\10496340-28c0-47c5-8c23-0aac03e48614-5' => Key deleted successfully. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-1.job not found. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-2.job not found. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-3.job not found. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-4.job not found. C:\Windows\Tasks\10496340-28c0-47c5-8c23-0aac03e48614-5.job not found. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-1.job not found. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-2.job not found. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-3.job not found. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-4.job not found. C:\Windows\Tasks\7c82d588-f306-4366-8f8b-71f85e442eb4-5.job not found. C:\Windows\Tasks\SaveSense.job not found. C:\ProgramData\TEMP => ":AD022376" ADS removed successfully. ========= netsh winsock reset ========= Die Initialisierungsfunktion InitHelperDll in NSHHTTP.DLL konnte nicht gestartet werden. Fehlercode 10107 Der Winsock-Katalog wurde zur�ckgesetzt. Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en. ========= End of CMD: ========= ==== End of Fixlog ==== |
Ne, ich brauche ja die FRST.txt und die Addition.txt |
Es tut mir leid, ich weiß es nicht, das ist das einzige, was ich kriege. |
http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, setze den Haken auch bei Addition.txt und drücke auf Scan. Poste die Logs in die nächste Antwort. |
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014--- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014 |
Schritt 1: FRST Fix Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: F - F:\.\Autorun.exe AUTORUN=1Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2: FRST Scan http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, setze den Haken auch bei Addition.txt und drücke auf Scan. Schritt 3: ESET ESET Online Scanner
Schritt 4: Frage Wie läuft Dein PC? |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-06-2014 Ran by Br. Pirminius Seber at 2014-06-23 18:56:10 Run:2 Running from C:\Users\Br. Pirminius Seber\Downloads\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: F - F:\.\Autorun.exe AUTORUN=1 ***************** 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3090635963-4145032168-3900013317-1001'=> Key not found. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014--- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014 |
OK ich warte auf weitere Logs. |
ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=9f3d10344ed7b8438cffa75a191559c4 # engine=18843 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-23 06:18:15 # local_time=2014-06-23 08:18:15 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 87 455487 167967985 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 74814 155177345 0 0 # scanned=159088 # found=53 # cleaned=0 # scan_time=3811 sh=44A7956A5D046523ABEDE48F6073E90961AAC364 ft=1 fh=7006f955c1e9646d vn="Variante von MSIL/Adware.iBryte.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\BrowserSafeguard\uninstall.BrowserSafeguard.exe.vir" sh=07EE6B2AF931FA381DE38B845181C8A12F092C1A ft=1 fh=a5c2abfedbc93267 vn="Variante von Win32/BrowseFox.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\ConstaSurfBHO.dll.vir" sh=FA9D2CA31C755D0F5A81AE72A3CCB51EE989BAA4 ft=1 fh=05c404252e66b822 vn="Variante von Win32/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\updateConstaSurf.exe.vir" sh=63FFFBF7FA1F7DC08E3EAF79A6A28823FD3AEC47 ft=1 fh=598a7e1eeccac04b vn="Variante von Win32/BrowseFox.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\ConstaSurf.BrowserAdapter.exe.vir" sh=D55371162E7AC08458FC1AC581B44FC5A6FF053F ft=1 fh=3b3d92f7237ca1af vn="Variante von Win64/BrowseFox.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\ConstaSurf.PurBrowse64.exe.vir" sh=DC16A1153D3F88CBFAF13D0E863833C537037600 ft=1 fh=e1707a6df3f3b19b vn="Variante von Win32/BrowseFox.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\ConstaSurfBAApp.dll.vir" sh=FA9D2CA31C755D0F5A81AE72A3CCB51EE989BAA4 ft=1 fh=05c404252e66b822 vn="Variante von Win32/BrowseFox.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\utilConstaSurf.exe.vir" sh=EDE61E449BEDDA5DDD605A395496D49703F573F9 ft=1 fh=8b21ad2fcf9602e3 vn="Variante von Win32/BrowseFox.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\{0782648b-1717-4fef-ac58-8cb3ce03adb3}.dll.vir" sh=E4C197DC89A0611542EA828724C5D1EC585580B9 ft=1 fh=d63ea59554f3e16a vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.Bromon.dll.vir" sh=B04C191760E311310E614768EA151FE0892B750D ft=1 fh=fc6b5dbd9b3b3f44 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.BroStats.dll.vir" sh=9EDB59531A9FA3C3D37E57FF56EEC6D448C5C650 ft=1 fh=2c8832b93e9ac067 vn="möglicherweise Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.BrowserAdapterS.dll.vir" sh=05EADA5D6C46530C679C6A80FB8FBF9E2B21E0D7 ft=1 fh=b33ddd491724e59f vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.CompatibilityChecker.dll.vir" sh=9C4EAB8D84EFB47BE6E31100B31CBE23F8DFA9EC ft=1 fh=81149872a0603674 vn="Variante von MSIL/BrowseFox.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.FFUpdate.dll.vir" sh=35A23CE4F5641DC402C1A22CAB99044C6B9CAA55 ft=1 fh=4d0c1233abec05c4 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.IEUpdate.dll.vir" sh=A4D08D7A58951F22EBFE9A9D121855EE345E56F7 ft=1 fh=edd95934e1ec67b0 vn="Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ConstaSurf\bin\plugins\ConstaSurf.PurBrowseG.dll.vir" sh=CED05266ECDC6547AFB0B18E7AB4DBCCA5535FB9 ft=1 fh=2791e6518558f99b vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir" sh=81FBC911F6F39943B5A508257ED317C6A388CA54 ft=1 fh=f881a71255879118 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir" sh=6F4FD559E82ECD0E9BF238374A8AE7763D9AF88F ft=1 fh=0fe3e64a55eab364 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir" sh=09975ED04166B761DC1CED0B15BAE6D37DCC0560 ft=1 fh=919d2464905062de vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir" sh=CC7735B51ACFC778DAFCE7B9C25798C1149059CA ft=1 fh=bdcf262ba56c13e6 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir" sh=E07AC00C609A9096EFEDCF5839D77AD91C96BD2D ft=1 fh=a44174895411af10 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir" sh=3AE79DE1D9A3C56075DB1B53DF9D7880AE03A5F6 ft=1 fh=bd390a3911fc5a39 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir" sh=0F00EB8310C851AAD8AE9C7C17EF5F0D81617D3A ft=1 fh=1090c94a8e08b65e vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir" sh=2ADB3F435305E66F52A44D4E6509661F8B5BA47A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam\1.26.249_0\extensionData\plugins\91.js.vir" sh=DC2F44E408378C231AFA4D5E0BC65855573FA17D ft=1 fh=576bb7911dc12d10 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Local\iLivid\Helper.dll.vir" sh=93578A0F21346F205CD6A11CE02BD58ABB98EE11 ft=1 fh=f2d1349e4484dc5e vn="Variante von Win32/Toolbar.SearchSuite.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Local\iLivid\Uninstall.exe.vir" sh=9949E2AA700EA8DC0CFEE91198AC53800C6BD0D6 ft=1 fh=aa0558f6d40a46cb vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe.vir" sh=E082854FA3F7C89221E44406EA71086403E834E7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\Mozilla\Firefox\Profiles\2x0a1rkf.default\Extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com\extensionData\plugins\91.js.vir" sh=AFFB7478306D0BAF1CBC2C646B61FB39DD4AB1FA ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\Mozilla\Firefox\Profiles\2x0a1rkf.default\Extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com\extensionData\plugins\91.js.vir" sh=B8E6BA69D75149795E4283A8A484B694CC50C001 ft=1 fh=7690bee84a2cb28f vn="Win32/VOPackage.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\VOPackage\Uninstall.exe.vir" sh=44ED55CB1079D34027CB77CD62248064FF5A0A09 ft=1 fh=3916453e74289c7d vn="Win32/VOPackage.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\VOPackage\VOPackage.exe.vir" sh=312B4326F089F044FEFE73A81FD94223E3F36410 ft=1 fh=789dc111d976203c vn="Variante von Win32/VOPackage.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Br. Pirminius Seber\AppData\Roaming\VOPackage\VOsrv.exe.vir" sh=CCBAAB1EB050FA9CAB112ABED57872373467F2D4 ft=1 fh=fa50e357e61e53d8 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\Br. Pirminius Seber\AppData\Local\Temp\PCSpeedMaximizer.exe.xBAD" sh=668865374E1866E82174D7683B968CEC3527691A ft=1 fh=d8f6daf83def6dca vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\Br. Pirminius Seber\AppData\Local\Temp\speedupmypc.exe.xBAD" sh=990A77ECC18BC46820C2354D3726F20FAAC791E9 ft=0 fh=0000000000000000 vn="Variante von Win32/AdWare.Adpeak.I Anwendung" ac=I fn="C:\temp\t.msi" sh=3B155C78095C8F4A7851112D14C35A8128113C2C ft=1 fh=1de3c52b009f0bf0 vn="Variante von Win32/SpeedBit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Installer\Install_10128\ytai.exe" sh=3B155C78095C8F4A7851112D14C35A8128113C2C ft=1 fh=1de3c52b009f0bf0 vn="Variante von Win32/SpeedBit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Installer\Install_19196\ytai.exe" sh=3B155C78095C8F4A7851112D14C35A8128113C2C ft=1 fh=1de3c52b009f0bf0 vn="Variante von Win32/SpeedBit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Installer\Install_32603\ytai.exe" sh=8E5D0DDD88C86A467E04B9323475029CD80A66D8 ft=1 fh=f12484e4e350440f vn="Variante von Win32/BrowseFox.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FNEW0LN\Setup[1].exe" sh=B2141692BDF56352A137D83E9EC73D05C423D2E5 ft=1 fh=e9e99cb68f1bf246 vn="Win32/SpeedUpMyPC evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FNEW0LN\SpeedUpMyPC-standalone-setup[1].exe" sh=19CA6B0692A041B3DA02EC0BA7B8D970CFC61F15 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\MsiToExe.SetupExtension.msi" sh=8398427DEE8FECAF5BC25B22C826FC2DC6DF9747 ft=1 fh=81c159dc949cee29 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsg653B.tmp" sh=ACC1C7D6CD8420D4EA46A35522AFC0F096B77CCD ft=1 fh=54c2a27e7a7711bf vn="Variante von Win32/Injected.F Trojaner" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsi3A76.tmp" sh=939C16ADE15384AA65A71E9DD19E53ABBBDC344C ft=1 fh=96b3e5887a7711bf vn="Variante von Win32/Injected.F Trojaner" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsq433E.tmp" sh=BBAC352F257862DF68413AE710544A318DD2A091 ft=1 fh=c7ae4474b5cb8b84 vn="Variante von Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Uninstall.exe582819.del" sh=D2EAFFAD45CC86DE6E07E9D8E42440CD25DA5754 ft=1 fh=855d8e396d7ffddb vn="Win32/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\0967d265-08c9-4fb3-929e-9662bc5292a5\software\Cloud_Backup_Setup.exe" sh=BBAC352F257862DF68413AE710544A318DD2A091 ft=1 fh=c7ae4474b5cb8b84 vn="Variante von Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\580542.Uninstall\Uninstall.exe" sh=DE7457A095FE26A437AE65ABFF603EBC7041B29A ft=1 fh=21434bd82dbff710 vn="Variante von Win32/Packed.ScrambleWrapper.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_11175\sense.exe" sh=ADEA6F0F89F9B4A6BDCFF42C4E4AD7DA93D3B724 ft=1 fh=9219e53dcc10c3ae vn="Variante von Win32/Packed.ScrambleWrapper.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_18125\iwebar.exe" sh=3B155C78095C8F4A7851112D14C35A8128113C2C ft=1 fh=1de3c52b009f0bf0 vn="Variante von Win32/SpeedBit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_26552\ytai.exe" sh=DEA5116E65880CCB22EC504C4C4CC7E0A1FE65B2 ft=1 fh=f49a059729fb3b71 vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\Downloads\installer_openoffice_Deutsch.exe" sh=BBAC352F257862DF68413AE710544A318DD2A091 ft=1 fh=c7ae4474b5cb8b84 vn="Variante von Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Br. Pirminius Seber\Downloads\VideoPlayerSetup.exe" sh=146F0A6C10435A26DB5100D044452322EE84FCFE ft=1 fh=314a90aba3c22b66 vn="Variante von MSIL/Adware.Proxomoto.F Anwendung" ac=I fn="C:\Windows\Microsoft\System Update kb77600\WindowsUpdater.exe" Der Laptop funktioniert bislang wieder sehr gut. |
Schritt 1: FRST Fix Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\Br. Pirminius Seber\AppData\Local\InstallerSpeichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2: Datenträgerbereinigung Datenträgerbereinigung
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-06-2014 Ran by Br. Pirminius Seber at 2014-06-23 20:45:15 Run:3 Running from C:\Users\Br. Pirminius Seber\Downloads\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion\FRST-OlderVersion Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Br. Pirminius Seber\AppData\Local\Installer C:\Users\Br. Pirminius Seber\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FNEW0LN C:\Users\Br. Pirminius Seber\AppData\Local\Temp\MsiToExe.SetupExtension.msi C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsg653B.tmp C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsi3A76.tmp C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsq433E.tmp C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Uninstall.exe582819.del C:\Users\Br. Pirminius Seber\AppData\Local\Temp\0967d265-08c9-4fb3-929e-9662bc5292a5\software\Cloud_Backup_Setup.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\580542.Uninstall\Uninstall.exe C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_11175 C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_18125 C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_26552 C:\Users\Br. Pirminius Seber\Downloads\installer_openoffice_Deutsch.exe C:\Users\Br. Pirminius Seber\Downloads\VideoPlayerSetup.exe C:\Windows\Microsoft\System Update kb77600 HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\...\MountPoints2: F - F:\.\Autorun.exe AUTORUN=1 ***************** C:\Users\Br. Pirminius Seber\AppData\Local\Installer => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FNEW0LN => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\MsiToExe.SetupExtension.msi => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsg653B.tmp => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsi3A76.tmp => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\nsq433E.tmp => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Uninstall.exe582819.del => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\0967d265-08c9-4fb3-929e-9662bc5292a5\software\Cloud_Backup_Setup.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\580542.Uninstall\Uninstall.exe => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_11175 => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_18125 => Moved successfully. C:\Users\Br. Pirminius Seber\AppData\Local\Temp\Install_26552 => Moved successfully. C:\Users\Br. Pirminius Seber\Downloads\installer_openoffice_Deutsch.exe => Moved successfully. C:\Users\Br. Pirminius Seber\Downloads\VideoPlayerSetup.exe => Moved successfully. C:\Windows\Microsoft\System Update kb77600 => Moved successfully. 'HKU\S-1-5-21-3090635963-4145032168-3900013317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3090635963-4145032168-3900013317-1001'=> Key not found. ==== End of Fixlog ==== |
Hallo, nach meiner Erkenntnis, ist Dein PC soweit sauber. :abklatsch: Die Reihenfolge ist hier entscheidend.
Falls Du mir Feedback geben willst, kannst Du es hier gerne tun: Lob, Kritik und Wünsche - Trojaner-Board Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Sicheres Browsen
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
| Alle Zeitangaben in WEZ +1. Es ist jetzt 16:06 Uhr. |
Copyright ©2000-2025, Trojaner-Board