![]() |
Movie Wizard entfernen Hallöchen, einmal falsch geklickt ..... 10 Programme installiert .... 9 davon haben sich einfach entfernen lassen (hofe ich ;) ) aber movie wizard bekomme ich nicht weg, seitdem ballert mir das alle Seiten voll mit Werbung (trotz Blocker, dann sind die Fenster eben leer.....) Wer kann / mag mir helfen ? 1000 Dank im voraus. chris |
Ist zwar scheinbar kein Plagegeist im herkömmlichen Sinn, aber versuch mal Revo Uninstaller: Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, sag Bescheid. |
danke erstmal. habe das so getan, das Programm ist nun aus der Systemsteuerung verschwunden, und es ist auch nichts mehr dort zu finden, dass ich Gestern erst installiert habe (die hatte ich über die Systemsteuerung gestern schon alle bis auf eben Movie Wizard deinstalliert). das dumme ist ..... die Werbung erscheint trotzdem nach wie vor. Der Inhalt ist geblockt (Ad Blocker) aber das Fenster nervt eben wie die Sau .... auch wenn es nur weiß ist. Drunter steht "Ad by Movie Wizard" Was kann ich da noch tun ? danke |
Lass uns mal schauen: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2015 +++++ FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2015 |
Lade Dir bitte von hier ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade Dir bitte ![]()
Starte noch einmal FRST.
|
revo erledigt adw:AdwCleaner Logfile: Code: # AdwCleaner v4.106 - Bericht erstellt am 05/01/2015 um 16:35:06 rest folgt ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 8.1 x64 Ran by Christian on 05.01.2015 at 16:47:49,41 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update clearthink ~~~ Files Successfully deleted: [File] "C:\Users\Christian\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage" Successfully deleted: [File] "C:\Users\Christian\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal" ~~~ Folders Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.01.2015 at 16:55:54,65 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 05.01.2015 Scan Time: 16:59:50 Logfile: mbam.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2015.01.05.06 Rootkit Database: v2014.12.30.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8.1 CPU: x64 File System: NTFS User: Christian Scan Type: Threat Scan Result: Completed Objects Scanned: 395774 Time Elapsed: 42 min, 37 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 1 PUP.Optional.MovieWizard.A, C:\ProgramData\jItQNyBVnXO\rYsSZF.exe, 3248, Delete-on-Reboot, [9c2e3fb46326e056cfff901813eec53b] Modules: 0 (No malicious items detected) Registry Keys: 6 PUP.Optional.MovieWizard.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rYsSZF, Quarantined, [9c2e3fb46326e056cfff901813eec53b], PUP.Optional.Snapdo.T, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [e4e6787be3a62016a116f4297f8435cb], PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [8149d81bf5948da9aace6300847fcc34], PUP.Optional.CrossRider.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, Quarantined, [547637bc3d4cc670bc83680dc0432ed2], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], Registry Values: 1 PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_57, Quarantined, [48826b88d2b77eb860aa1a4efa098d73], Registry Data: 6 PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfBjU-QQWRZo0MEKYtVExFYw_wZR3gqptKtktHaYxKsvFn-FbVbapFJhoQLVyUdO6SwVYZgmxafTObJ0ifN_9A,,, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfBjU-QQWRZo0MEKYtVExFYw_wZR3gqptKtktHaYxKsvFn-FbVbapFJhoQLVyUdO6SwVYZgmxafTObJ0ifN_9A,,),Replaced,[9634d41f602936002bb0c1bc91749c64] PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}),Replaced,[309a9e5553361620bc24ea934bbab848] PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}),Replaced,[6d5d82711b6e3501815d3c41a06546ba] PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}),Replaced,[3c8e4ca77b0ea1951ac985f8a75ee51b] PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}),Replaced,[c00a4fa42861b08613d12657d92c03fd] PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2678595623-4148133582-4009595467-1015-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880Sv7sAtbkRqk2nM_zupkJTpIlAn0-yxzyhK-5AKV7malnMG_lHTaboiUJMCHrotFlWDma73k59q4ZeQdT5elfzEQAXeTm9Lg39jwBlJ8uck-RGeInHO0FqLzKJrojniDvRSHxD-SOAIZ47hJZfUc6k8xE2miFS1R7ERJzqntQ,,&q={searchTerms}),Replaced,[fbcfa94a1f6a91a5a93dbac37095629e] Folders: 31 PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.MovieWizard.A, C:\Users\Christian\AppData\Local\MovieWizard, Quarantined, [cbfffaf98efb5bdb01508305ab585aa6], Rogue.Multiple, C:\ProgramData\2355320829, Quarantined, [4882b241ddaca393b5d53be3c43f847c], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], Files: 116 PUP.Optional.MovieWizard.A, C:\ProgramData\jItQNyBVnXO\rYsSZF.exe, Delete-on-Reboot, [9c2e3fb46326e056cfff901813eec53b], PUP.Optional.MovieWizard.A, C:\ProgramData\jItQNyBVnXO\dat\FBQPiVZL.exe, Delete-on-Reboot, [19b10de60e7b2214f3dbc4e454ad47b9], PUP.Optional.MovieWizard.A, C:\ProgramData\jItQNyBVnXO\dat\IHHpKvw.exe, Delete-on-Reboot, [ca0003f0a1e85adc824c198fbb46e719], PUP.Optional.MovieWizard.A, C:\ProgramData\jItQNyBVnXO\dat\kSRMXqJ.dll, Delete-on-Reboot, [73572dc6cbbef83e2457f188f0153cc4], PUP.Optional.CrossRider.A, C:\Users\Christian\AppData\Roaming\ABOHA.exe, Quarantined, [ac1ed221d2b772c44994e8d4fd087e82], PUP.Optional.MediaPlayerVideo.A, C:\Users\Christian\AppData\Roaming\YKHICJXT.exe, Quarantined, [d3f7ce2557329d9978ef6b530ff6a858], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, Quarantined, [5377698a6a1f67cfc666857f05fd7c84], PUP.Optional.Tuto4PC.A, C:\Users\Christian\AppData\Local\Temp\20da783a-30b5-47a2-bc40-2b94ef986a56\games desktop.exe, Quarantined, [fcce22d12366e6503d5599614db4ba46], PUP.Optional.MovieWizard.A, C:\Users\Christian\AppData\Local\Temp\405917f5-d559-4e06-aa02-4b843880eabb\setup.exe, Quarantined, [24a6ae452f5a58de0f0272eb659bea16], PUP.Optional.StormWatch.A, C:\Users\Christian\AppData\Local\Temp\4d8efcb2-fe7f-4b3a-ab85-1687a2333324\setup.exe, Quarantined, [8248d51ee6a38ea89222b0a5fe029868], PUP.Optional.CrossRider.A, C:\Users\Christian\AppData\Local\Temp\8bd513da-160f-4d3a-9fdc-6ddf99d5df7d\setup.exe, Quarantined, [07c339ba0683181e2a0ab42d40c1936d], PUP.Optional.XTab.A, C:\Users\Christian\AppData\Local\Temp\~dl38E0\~dljyb\tmp\STab_v4.0.exe, Quarantined, [dcee36bdfc8d51e5e646b74da06213ed], PUP.Optional.WindowsProtectManger.A, C:\Users\Christian\AppData\Local\Temp\~dl38E0\~dljyb\tmp\wpm_v20.0.0.1337.exe, Quarantined, [45854aa90f7a89ad1abe5c66e31e5ba5], PUP.Optional.Bandoo, C:\Users\Christian\Downloads\iLividSetup-r400-n-bc.exe, Quarantined, [d0fa747f6920082eeb4d71b9bf42d62a], PUP.Optional.Softonic, C:\Users\Christian\Downloads\SoftonicDownloader_fuer_photoscape.exe, Quarantined, [606ad320088196a059de4ed76a97cb35], Adware.Linkular, C:\Users\Christian\Downloads\VLCPlus_Setup (1).exe, Quarantined, [e8e28e652d5cfc3a628df4bc20e5af51], Adware.Linkular, C:\Users\Christian\Downloads\VLCPlus_Setup.exe, Quarantined, [a426af4430593204b738dfd1778e58a8], PUP.Optional.SnapDo.A, C:\Windows\Installer\24ab3d40.msi, Quarantined, [3a90c82b07822214751f673da35e04fc], PUP.Optional.SmartBar, C:\Windows\Installer\MSI610F.tmp, Quarantined, [01c95c978801c96d532ce44a4db3a759], PUP.Optional.SmartBar, C:\Windows\Installer\MSIC332.tmp, Quarantined, [c406fef5b3d6ba7cf08f52dcda262bd5], PUP.Optional.SmartBar, C:\Windows\Installer\MSI2CB3.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [5c6e688bfb8e9a9c5c23e84645bbc63a], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\HPNotify.exe, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, Quarantined, [b81231c28cfd3ff77dfc85de23e006fa], PUP.Optional.OmigaPlus.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage, Quarantined, [bf0b25cee9a04cea5d83b5b336cdf20e], PUP.Optional.OmigaPlus.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage-journal, Quarantined, [5674fcf741486bcbd0103b2d956e11ef], PUP.Optional.MovieWizard.A, C:\Users\Christian\AppData\Local\MovieWizard\data2.dat, Quarantined, [cbfffaf98efb5bdb01508305ab585aa6], Rogue.Multiple, C:\ProgramData\2355320829\BIT2BF0.tmp, Quarantined, [4882b241ddaca393b5d53be3c43f847c], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\GoogleCrashHandler.exe, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\GoogleUpdate.exe, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\GoogleUpdateBroker.exe, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\GoogleUpdateHelper.msi, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\GoogleUpdateOnDemand.exe, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\goopdate.dll, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\goopdateres_en.dll, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\npGoogleUpdate4.dll, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\psmachine.dll, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.91348\psuser.dll, Quarantined, [9c2e1dd6f198d3638b4a68df33d0ea16], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\GoogleCrashHandler.exe, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\GoogleUpdate.exe, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\GoogleUpdateBroker.exe, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\GoogleUpdateHelper.msi, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\GoogleUpdateOnDemand.exe, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\goopdate.dll, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\goopdateres_en.dll, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\npGoogleUpdate4.dll, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\psmachine.dll, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], PUP.Optional.GlobalUpdate.A, C:\Users\Christian\AppData\Local\Temp\comh.94121\psuser.dll, Quarantined, [dbefbc37cbbec571d40156f1c83b827e], Physical Sectors: 0 (No malicious items detected) (end) FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2015 --- --- --- |
Das sieht schon sehr gut aus, der Movie Wizard dürfte aktuell nicht mehr auftauchen. Noch ein paar Reste und verwaistes + temporäre Dateien löschen, der ESET Scan am Ende wird einige Zeit brauchen (Stunden) : Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKU\S-1-5-21-2678595623-4148133582-4009595467-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte ![]()
ESET Online Scanner
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2015 Ran by Christian at 2015-01-06 17:02:02 Run:1 Running from C:\Users\Christian\Downloads Loaded Profiles: Christian & NeroMediaHomeUser.4 (Available profiles: Christian & NeroMediaHomeUser.4) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-2678595623-4148133582-4009595467-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File emptytemp: ***************** "HKU\S-1-5-21-2678595623-4148133582-4009595467-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll not found. C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll not found. EmptyTemp: => Removed 1.2 GB temporary data. The system needed a reboot. ==== End of Fixlog 17:02:36 ==== Results of screen317's Security Check version 0.99.93 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender avast! Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 51 Java version 32-bit out of Date! Adobe Reader XI Google Chrome (39.0.2171.71) Google Chrome (39.0.2171.95) ````````Process Check: objlist.exe by Laurent```````` Symantec Norton Online Backup NOBuClient.exe Symantec Norton Online Backup NOBuAgent.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=004ed65630d97544a7830b60d80b6ab0 # engine=21839 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-01-06 07:42:45 # local_time=2015-01-06 08:42:45 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777214 100 97 2296358 184993855 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 4751027 36696645 0 0 # scanned=228888 # found=48 # cleaned=0 # scan_time=10947 sh=9DF3638EE93AB2DB89A89AC6B67BF088DC64416B ft=1 fh=c71c00110e78363b vn="Variante von Win32/ELEX.BH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir" sh=7F55F0BDF9198C07107A5C331DAF1FD0B2D68BDB ft=1 fh=40df201e40390e46 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir" sh=AD1BF4CF62786788C0440C060BCFBCA0A06A3188 ft=1 fh=a16c06f51dd861fe vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\LPT\sppsm.dll.vir" sh=DDE17349886FC1A7D13E8D0F41D6A4CE5A394D01 ft=1 fh=c9bce873ebed2a5f vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\LPT\spusm.dll.vir" sh=C7ACB89F4541A3F65D5CFE90B9004C6BFEC2C8FA ft=1 fh=9e66ceb26218c551 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\LPT\srbs.dll.vir" sh=542C70B56113D6CB5A2FD51DAFA02FB3FDEE1917 ft=1 fh=9bb68e157a308082 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\LPT\srptc.dll.vir" sh=70511E1DC237B11EB2DA47764E2F58D66884A8D4 ft=1 fh=8926dceffb73a01c vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir" sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dl l.vir" sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dl l.vir" sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dl l.vir" sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dl l.vir" sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dl l.vir" sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dl l.vir" sh=C513E316EE88ED66F7EA1A44BD889C89B1860E0D ft=1 fh=001996f75051ad99 vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Christian\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.SafeMode.dll.vir " sh=E6BD8F5EFE24CF921209AE0C2A2E5BEFBE8ACEDE ft=1 fh=f5839ea66906a236 vn="Win32/Toolbar.Conduit.G evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\Local\Conduit\CT2481020\Ashampoo_DEAutoUpdateHelper.exe" sh=1B37BEC7610109F594112CFB3D31145270C9B448 ft=1 fh=40977a3eb07e85f1 vn="Variante von Win64/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\hk64tbAsh0.dll" sh=34FF8E2D281CBFECE71100A04C0FF4436818382E ft=1 fh=7b66b1ed06cb1b80 vn="Variante von Win64/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\hk64tbAsh2.dll" sh=D0ED81A632CE3D57C8B76105DA25F471D47B3E75 ft=1 fh=fc399cefd8e91d81 vn="Variante von Win32/Toolbar.Conduit.X evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\hktbAsh0.dll" sh=AE7B8F3BB6E040CE20B02DE558471FAA4C58386E ft=1 fh=6a41a8d0046fd7b4 vn="Variante von Win32/Toolbar.Conduit.X evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\hktbAsh2.dll" sh=2AA1E2644D392689B767F9208ABD40C8CF9A0830 ft=1 fh=6a69b43ed4700d25 vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\ldrtbAsh0.dll" sh=87BE5F13318AC3BA3F403A73E332E1784304C21D ft=1 fh=3e5cd6b65c184efc vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\ldrtbAsh2.dll" sh=A1280B1F085B8284DC157EC359BD1ADA091CFE7E ft=1 fh=d8aa3384d1249a40 vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\ldrtbAsha.dll" sh=9D2D4D6F4434A89BCEEE7132C24890550E01479C ft=1 fh=2a05e04e6030aaf6 vn="Variante von Win32/Toolbar.Conduit.X evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\tbAsh0.dll" sh=F16D879DF00FDBFC5935AA3E543331AC8E23CB3F ft=1 fh=84f57c161db7dac2 vn="Variante von Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\tbAsh1.dll" sh=1E6279D9317A709616211812CCA5AB8B26EB4AB2 ft=1 fh=dd2582521ac42eea vn="Variante von Win32/Toolbar.Conduit.X evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\tbAsh2.dll" sh=92E84D2216A7763D580E42FA2493CCF67D0D0560 ft=1 fh=e8efc42494afd9f6 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\tbAsha.dll" sh=ABF759CA3BFB16DE62197DD7C417AC5039A43AE0 ft=1 fh=1801af74030ebca1 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\AppData\LocalLow\Ashampoo_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGongIE.dll" sh=DF03019EA4962809E1AE99549D8A650DDE8DE9B6 ft=1 fh=f4bae2cd41aaec6e vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Altes c\Christian Rüttger\Downloads\ashampoo_burning_studio_6_free_6.81_3639.exe" sh=80915927D23ED0F93DDF234F1A07AACF3EB90CD4 ft=1 fh=d3372b907a7753ac vn="Variante von Win32/Adware.ADON evtl. unerwünschte Anwendung" ac=I fn="C:\Altes d\Eigene Dateien\ps_radio2015.exe" sh=BBC107B3C4335A094162EA909ED16DEC2B56B01F ft=1 fh=421fc8cb27121ff1 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Altes d\Eigene Dateien\downloads\Integrated_FreewareDE.exe" sh=40A8D0BA792EB7A48CEA0F54994CD4B04D76CD9A ft=1 fh=1b9df70b39057000 vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Altes d\Eigene Dateien\downloads\SoftonicDownloader_fuer_7-zip.exe" sh=67218EC7AB4C2306F2B76E5320556953DE34DDAB ft=1 fh=b9f2ea2dd5ee429f vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\ProgramData\jItQNyBVnXO\dat\hmngBbhAam.dll" sh=67218EC7AB4C2306F2B76E5320556953DE34DDAB ft=1 fh=b9f2ea2dd5ee429f vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\Users\All Users\jItQNyBVnXO\dat\hmngBbhAam.dll" sh=DDD7E789E67132CF6C5D8169B2F46E3498FCA60F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\AppData\Roaming\ABOHA" sh=DDD7E789E67132CF6C5D8169B2F46E3498FCA60F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\AppData\Roaming\YKHICJXT" sh=E15EC5DFC39C5F7E7EEAB86EB8942EA0140C8BF4 ft=1 fh=923e0f9c2b7728b2 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\Classic Shell - CHIP-Installer.exe" sh=D0357617961BF3D526BEFAAB0048CBB983EA4DF9 ft=1 fh=c604c933e8b9509f vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\PDFCreator-1_7_0_setup.exe" sh=E2C028A886AA7352539DEE32CBB38770C529A76E ft=1 fh=d2aeb2930bcba9f7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\PDFCreator-1_7_3_setup (1).exe" sh=E2C028A886AA7352539DEE32CBB38770C529A76E ft=1 fh=d2aeb2930bcba9f7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\PDFCreator-1_7_3_setup (2).exe" sh=E2C028A886AA7352539DEE32CBB38770C529A76E ft=1 fh=d2aeb2930bcba9f7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\PDFCreator-1_7_3_setup (3).exe" sh=E2C028A886AA7352539DEE32CBB38770C529A76E ft=1 fh=d2aeb2930bcba9f7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\PDFCreator-1_7_3_setup.exe" sh=84BC086CBF57ACE0050B8E543EED4900C6E1B26F ft=1 fh=e9eb93c84dbab371 vn="Variante von Win32/InstallCore.PL evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Christian\Downloads\samsung-kies_setup.exe" sh=5204CDF0A800C869C45AB2407D70BC0A9B85A84E ft=1 fh=7ec9834b5d8a918a vn="Variante von MSIL/Toolbar.Linkury.I evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll" sh=782C3DDE42011916B89CD4668A43F5FDA292DBCD ft=1 fh=fd5408eb1a78d8ce vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\sppsm.dll" sh=E3A2963378AB8574657E5D3158F2922975DBCB3D ft=1 fh=9155912454d21124 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\spusm.dll" sh=9940AB97898E7C4F5A46C846E687AAE686954D57 ft=1 fh=b045d5d7555ccc06 vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\srbs.dll" sh=FB0465D7EA7112E23783518738711C283D6B7E27 ft=1 fh=bd1ab8932c63b270 vn="Variante von MSIL/Toolbar.Linkury.F evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\srbu.dll" sh=9C82ABC3B93FCAB4B17266F854BB07CACE5C6899 ft=1 fh=b81a20d7128256d0 vn="Variante von MSIL/Toolbar.Linkury.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI2CB3.tmp-\srptc.dll" so, das war alles glaub ich .... und wie schauts ? |
Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Avast! meldet das er nicht up-to-date ist ! Das ESET Log sieht ok aus. Noch ein paar Reste löschen: Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: "C:\ProgramData\jItQNyBVnXO\" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Im Eset Log sind ausserdem noch einige .dlls die scheinbar aus einer Laufwerk-Sicherung stammen, muss man nicht unbedingt löschen, ausser du würdest das komplette Laufwerk daraus wiederherstellen, was mich erstaunen würde :lach: Ein paar Setups mit Adware, ist leider gang und gebe heutzutage. Ein Tipp zu Chip+Softonic: ![]() Bei Chip.de und Softonic gibt es beim Download zwei Möglichkeiten: einmal den Chip Downloader mit DownloadSponsor, der Werbung mitbringt und gern versucht, den User dazu zu überreden, noch diese und jene Toolbar zu installieren. Und es gibt immer den alternativen Download, das ist die eigentliche Anwendung als Setup, so wie sie vom Hersteller kommt. Der Alternativlink ist genau unter der Chip Download-Schaltfläche. http://www.trojaner-board.de/picture...&pictureid=516 http://www.trojaner-board.de/picture...&pictureid=519 Die Reihenfolge ist hier entscheidend.
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ändere regelmäßig alle deine Passwörter, jetzt, nach der Bereinigung ist ein idealer Zeitpunkt dafür
Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-01-2015 Ran by Christian at 2015-01-08 16:51:31 Run:2 Running from C:\Users\Christian\Downloads Loaded Profiles: Christian & NeroMediaHomeUser.4 (Available profiles: Christian & NeroMediaHomeUser.4) Boot Mode: Normal ============================================== Content of fixlist: ***************** "C:\ProgramData\jItQNyBVnXO\" "C:\Users\All Users\jItQNyBVnXO\" "C:\Users\Christian\AppData\Roaming\ABOHA" "C:\Users\Christian\AppData\Roaming\YKHICJXT" ***************** C:\ProgramData\jItQNyBVnXO => Moved successfully. "C:\Users\All Users\jItQNyBVnXO" => File/Directory not found. C:\Users\Christian\AppData\Roaming\ABOHA => Moved successfully. C:\Users\Christian\AppData\Roaming\YKHICJXT => Moved successfully. ==== End of Fixlog 16:51:32 ==== danke soweit, das mit: Die Reihenfolge ist hier entscheidend. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten) etc habe ich nicht verstanden :( |
Zitat:
Falls Defogger benutzt wurde.... hast du nicht, also ignorieren Falls Combofix benutzt wurde.... hast du nicht, also ignorieren :pfeiff: Warum ich das geschrieben habe ? Nunja, wir arbeiten mit Textbausteinen, weil wir anstatt z.b. 10 User am Tag zu bearbeiten, nur 2 User schaffen würden und dann die Nase voll vom Tippen hätten... :killpc: |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:29 Uhr. |
Copyright ©2000-2025, Trojaner-Board