![]() |
|
Log-Analyse und Auswertung: Incredibar MyStart entfernenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Incredibar MyStart entfernen Hallo zusammen, auch ich habe mir beim Download des pdf-creator über chip.de die Incredibar/ MyStart-Toolbar eingefangen. ![]() Bislang habe ich die entsprechenden Einträge in der Systemsteuerung/ Software deinstalliert sowie die Plugins in Firefox gelöscht. Avira hatte sofort Alarm geschlagen und ich habe 2 Funde (nach 12stündigem Komplettscan ![]() Ergebnis: Die Toolbar erscheint immer beim Start eines neuen Tabs in Firefox. Beim ersten Tab sehe ich sie nicht. Ansonsten bemerke ich keine Auswirkungen, aber ich will natürlich diese Toolbar loswerden, zumal mir nicht klar ist, was das alles sonst noch mit dem Rechner macht. ![]() Nach Lesen der einschlägigen Threads in diesem Forum habe ich außerdem erstmal Malwarebytes Antimalware laufen lassen. Ergenis: kein Fund (Logfile poste ich bei Bedarf). Dann nochmal AdwCleaner laufen lassen. Logfile s.u.. "Delete" habe ich noch nicht geklickt... (nicht getraut). Meine Frage: Was nun? Delete beim AdwCleaner?! DANKE! Reportauszug Avira (2 Funde) Code:
ATTFilter Die Datei 'C:\Users\Jens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AM1I8PN9\4ff206756408e[1].exe' enthielt einen Virus oder unerwünschtes Programm 'ADWARE/Multplug.A.1' [adware]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4ed9ae97.qua' verschoben! Die Datei 'C:\Users\Jens\AppData\Local\Temp\{9471491E-B6E0-7684-407D-B2DD905DB863}\Addons\download_save.exe' enthielt einen Virus oder unerwünschtes Programm 'ADWARE/Multplug.A.1' [adware]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '567f810f.qua' verschoben! Logfile AdwCleaner (QuickScan) Code:
ATTFilter # AdwCleaner v1.701 - Logfile created 07/12/2012 at 21:52:23 # Updated 02/07/2012 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (64 bits) # User : Jens - JENS-HP # Running from : C:\Users\Jens\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Jens\AppData\LocalLow\facemoods.com Folder Found : C:\Users\Jens\AppData\Roaming\pdfforge Folder Found : C:\Program Files (x86)\facemoods.com File Found : C:\Users\Jens\AppData\Local\Temp\Uninstall.exe File Found : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\6n9orim2.default\searchplugins\MyStart Search.xml File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml ***** [Registry] ***** Key Found : HKCU\Software\facemoods.com Key Found : HKCU\Software\IM Key Found : HKCU\Software\ImInstaller Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 Key Found : HKLM\SOFTWARE\facemoods.com Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods Key Found : HKLM\SOFTWARE\Web Assistant Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] [x64] Key Found : HKCU\Software\facemoods.com [x64] Key Found : HKCU\Software\IM [x64] Key Found : HKCU\Software\ImInstaller [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 [x64] Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc [x64] Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl [x64] Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 [x64] Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore [x64] Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 [x64] Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [x64] Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 [x64] Key Found : HKLM\SOFTWARE\Web Assistant [x64] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37} Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}] [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.facemoods.com/?a=ddrnw [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.facemoods.com/?a=ddrnw&f=2 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 -\\ Mozilla Firefox v13.0.1 (de) Profile name : default File : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\6n9orim2.default\prefs.js Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb139?a=6OyGKE8B43&loc=FF_NT"); Found : user_pref("extensions.facemoods._xpiupdate", true); Found : user_pref("extensions.facemoods.aflt", "_#wbst"); Found : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4"); Found : user_pref("extensions.facemoods.first_time", false); Found : user_pref("extensions.facemoods.id", "_#4a7bba46c0e54ef0891e435569b29ae2"); Found : user_pref("extensions.facemoods.instlDay", "_#15256"); Found : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com"); Found : user_pref("extensions.facemoods.sid", "_#4a7bba46c0e54ef0891e435569b29ae2"); Found : user_pref("extensions.facemoods.uninst", true); Found : user_pref("extensions.facemoods.update", "_#v1.4.0"); Found : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5"); Found : user_pref("extensions.incredibar.admin", false); Found : user_pref("extensions.incredibar.aflt", "orgnl"); Found : user_pref("extensions.incredibar.cntry", "DE"); Found : user_pref("extensions.incredibar.dfltLng", ""); Found : user_pref("extensions.incredibar.dfltSrch", false); Found : user_pref("extensions.incredibar.did", "10669"); Found : user_pref("extensions.incredibar.envrmnt", "production"); Found : user_pref("extensions.incredibar.excTlbr", false); Found : user_pref("extensions.incredibar.hdrMd5", "0BE9D29A08051BDEE6C785E75DD9B082"); Found : user_pref("extensions.incredibar.hmpg", false); Found : user_pref("extensions.incredibar.id", "425d9bf5000000000000d0df9a8261a9"); Found : user_pref("extensions.incredibar.installerproductid", "26"); Found : user_pref("extensions.incredibar.instlDay", "15523"); Found : user_pref("extensions.incredibar.instlRef", ""); Found : user_pref("extensions.incredibar.isDcmntCmplt", true); Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1422:37:18"); Found : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Found : user_pref("extensions.incredibar.newTab", false); Found : user_pref("extensions.incredibar.noFFXTlbr", false); Found : user_pref("extensions.incredibar.ppd", "123%5F1"); Found : user_pref("extensions.incredibar.prdct", "incredibar"); Found : user_pref("extensions.incredibar.productid", "26"); Found : user_pref("extensions.incredibar.propectorlck", 79821941); Found : user_pref("extensions.incredibar.prtkHmpg", 1); Found : user_pref("extensions.incredibar.prtnrId", "Incredibar"); Found : user_pref("extensions.incredibar.sg", "none"); Found : user_pref("extensions.incredibar.smplGrp", "none"); Found : user_pref("extensions.incredibar.tlbrId", "base"); Found : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyGKE8B43&loc=IB_T[...] Found : user_pref("extensions.incredibar.upn2", "6OyGKE8B43"); Found : user_pref("extensions.incredibar.upn2n", "92261687798544527"); Found : user_pref("extensions.incredibar.vrsn", "1.5.11.14"); Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1422:37:18"); Found : user_pref("extensions.incredibar.vrsni", "1.5.11.14"); Found : user_pref("extensions.incredibar_i.aflt", "orgnl"); Found : user_pref("extensions.incredibar_i.dfltLng", ""); Found : user_pref("extensions.incredibar_i.did", "10669"); Found : user_pref("extensions.incredibar_i.excTlbr", false); Found : user_pref("extensions.incredibar_i.id", "425d9bf5000000000000d0df9a8261a9"); Found : user_pref("extensions.incredibar_i.installerproductid", "26"); Found : user_pref("extensions.incredibar_i.instlDay", "15523"); Found : user_pref("extensions.incredibar_i.instlRef", ""); Found : user_pref("extensions.incredibar_i.ms_url_id", ""); Found : user_pref("extensions.incredibar_i.newTab", false); Found : user_pref("extensions.incredibar_i.ppd", "123%5F1"); Found : user_pref("extensions.incredibar_i.prdct", "incredibar"); Found : user_pref("extensions.incredibar_i.productid", "26"); Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Found : user_pref("extensions.incredibar_i.smplGrp", "none"); Found : user_pref("extensions.incredibar_i.tlbrId", "base"); Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyGKE8B43&loc=IB[...] Found : user_pref("extensions.incredibar_i.upn2", "6OyGKE8B43"); Found : user_pref("extensions.incredibar_i.upn2n", "92261687798544527"); Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1422:37:18"); Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Found : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&a=6OyGKE8B43&&i=26&search="[...] ************************* AdwCleaner[R1].txt - [14439 octets] - [12/07/2012 21:26:28] AdwCleaner[R2].txt - [14498 octets] - [12/07/2012 21:27:57] AdwCleaner[R3].txt - [14520 octets] - [12/07/2012 21:52:23] ########## EOF - C:\AdwCleaner[R3].txt - [14649 octets] ########## |
Themen zu Incredibar MyStart entfernen |
adwcleaner, avira, browser, chip.de, desktop, download, entfernen, explorer, firefox, frage, google, helper, incredibar, internet, internet explorer, kein fund, logfile, loswerden, malware, malwarebytes, microsoft, mozilla, mystart, opera, programm, registry, scan, searchscopes, software, virus, windows |