Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Webseiten von Microsoft, Avira etc. nicht mehr aufrufbar
top! Die besagten Webseiten können schon mal wieder geöffnet werden.
Kannst Du kurz sagen wer oder was das Problem verursacht hat? Konnte es komplett beseitigt werden?
Code:
ATTFilter
All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-3501483959-2219181981-1860870347-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q=" removed from browser.search.defaulturl
Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=" removed from keyword.URL
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\ft2iwcdl.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ft2iwcdl.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ft2iwcdl.default\searchplugins\icqplugin.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE163F11-1919-4257-A280-FF5AF8DAEECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE163F11-1919-4257-A280-FF5AF8DAEECB}\ deleted successfully.
C:\Programme\icq\Internet Explorer\icq.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-3501483959-2219181981-1860870347-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Cixyi deleted successfully.
C:\Users\xxx\AppData\Roaming\Xoyz\olow.exe moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9aba0abc-3230-11e1-b5d3-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9aba0abc-3230-11e1-b5d3-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9aba0abc-3230-11e1-b5d3-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9aba0abc-3230-11e1-b5d3-806e6f6e6963}\ not found.
File F:\ESRI.exe not found.
C:\Users\xxx\AppData\Roaming\Xoyz folder moved successfully.
C:\Users\xxx\AppData\Roaming\Xosaax folder moved successfully.
C:\Users\xxx\AppData\Roaming\Hepou folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: xxx
->Temp folder emptied: 73904621 bytes
->Temporary Internet Files folder emptied: 55359387 bytes
->Java cache emptied: 2391273 bytes
->FireFox cache emptied: 1063417967 bytes
->Flash cache emptied: 587 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 56725607 bytes
RecycleBin emptied: 3278520683 bytes
Total Files Cleaned = 4.321,00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: xxx
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.44.0 log created on 06202012_112712
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Themen zu Webseiten von Microsoft, Avira etc. nicht mehr aufrufbar
Zum Thema Webseiten von Microsoft, Avira etc. nicht mehr aufrufbar - top! Die besagten Webseiten können schon mal wieder geöffnet werden.
Kannst Du kurz sagen wer oder was das Problem verursacht hat? Konnte es komplett beseitigt werden?
Code:
Alles auswählen Aufklappen - Webseiten von Microsoft, Avira etc. nicht mehr aufrufbar...