Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Fehlermeldung beim Systemstart: Problem beim Starten von C/User...appdata..exe
Alles gemacht!
Nachdem ich den Suchlauf mit Malwarebytes gemacht hatte gabs übrigens 2 Befunde die ich entfernen konnte. Beim darauf folgenden Neustart kam auch keine Fehlermeldung mehr! yay!
Das kam dann bei Adw Cleaner raus:
Code:
ATTFilter
# AdwCleaner v1.703 - Logfile created 08/01/2012 at 11:26:38
# Updated 20/07/2012 by Xplode
# Operating system : Windows 7 Home Premium (64 bits)
# User : Jessy - JESSY-VAIO
# Running from : C:\Users\Jessy\Desktop\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
Folder Found : C:\Users\Jessy\AppData\LocalLow\Conduit
Folder Found : C:\Users\Jessy\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Found : C:\Program Files (x86)\Conduit
File Found : C:\Users\Jessy\AppData\Roaming\Mozilla\Firefox\Profiles\84uq1byp.default\searchplugins\MyStart Search.xml
File Found : C:\Users\Jessy\AppData\Roaming\Mozilla\Firefox\Profiles\84uq1byp.default\searchplugins\qip-search.xml
***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2724386
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Conduit
[x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit
[x64] Key Found : HKCU\Software\IM
[x64] Key Found : HKCU\Software\ImInstaller
[x64] Key Found : HKCU\Software\Softonic
[x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
***** [Registre - GUID] *****
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.qip.ru/ie
-\\ Mozilla Firefox v12.0 (de)
Profile name : default
File : C:\Users\Jessy\AppData\Roaming\Mozilla\Firefox\Profiles\84uq1byp.default\prefs.js
Found : user_pref("CT2724386..clientLogIsEnabled", true);
Found : user_pref("CT2724386..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2724386..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2724386.CT2724407.CommunityChanged", true);
Found : user_pref("CT2724386.CT2724431.CommunityChanged", true);
Found : user_pref("CT2724386.CT2727162.CommunityChanged", true);
Found : user_pref("CT2724386.CT2727622.CommunityChanged", true);
Found : user_pref("CT2724386.CT2727646.CommunityChanged", true);
Found : user_pref("CT2724386.CT2727678.CommunityChanged", true);
Found : user_pref("CT2724386.CT2727750.CommunityChanged", true);
Found : user_pref("CT2724386.CTID", "ct2724407");
Found : user_pref("CT2724386.CommunitiesChangesLastCheckTime", "Tue Jan 04 2011 14:29:12 GMT+0100");
Found : user_pref("CT2724386.CommunityChanged", true);
Found : user_pref("CT2724386.CurrentServerDate", "17-3-2011");
Found : user_pref("CT2724386.DialogsAlignMode", "LTR");
Found : user_pref("CT2724386.DownloadReferralCookieData", "");
Found : user_pref("CT2724386.FirstServerDate", "4-1-2011");
Found : user_pref("CT2724386.FirstTime", true);
Found : user_pref("CT2724386.FirstTimeFF3", true);
Found : user_pref("CT2724386.FirstTimeSettingsDone", true);
Found : user_pref("CT2724386.FixPageNotFoundErrors", true);
Found : user_pref("CT2724386.GroupingLastCheckTime", "Tue Jan 04 2011 14:27:12 GMT+0100");
Found : user_pref("CT2724386.GroupingLastErrorCode", "");
Found : user_pref("CT2724386.GroupingLastResponse", true);
Found : user_pref("CT2724386.GroupingLastServerUpdateTime", "129373589385170000");
Found : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2724386.HasUserGlobalKeys", true);
Found : user_pref("CT2724386.Initialize", true);
Found : user_pref("CT2724386.InitializeCommonPrefs", true);
Found : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Found : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Found : user_pref("CT2724386.InstalledDate", "Tue Jan 04 2011 14:27:13 GMT+0100");
Found : user_pref("CT2724386.IsGrouping", true);
Found : user_pref("CT2724386.IsMulticommunity", false);
Found : user_pref("CT2724386.IsOpenThankYouPage", false);
Found : user_pref("CT2724386.IsOpenUninstallPage", true);
Found : user_pref("CT2724386.LanguagePackLastCheckTime", "Tue Jan 04 2011 14:27:14 GMT+0100");
Found : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2724386.LastLogin_2.7.2.0", "Tue Jan 04 2011 14:27:14 GMT+0100");
Found : user_pref("CT2724386.LastLogin_3.2.5.2", "Thu Mar 17 2011 16:39:48 GMT+0100");
Found : user_pref("CT2724386.LatestVersion", "3.2.5.2");
Found : user_pref("CT2724386.Locale", "en");
Found : user_pref("CT2724386.LoginCache", 4);
Found : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Found : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Found : user_pref("CT2724386.RadioIsPodcast", false);
Found : user_pref("CT2724386.RadioMediaID", "21080119");
Found : user_pref("CT2724386.RadioMediaType", "Media Player");
Found : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080119");
Found : user_pref("CT2724386.RadioStationName", "Royal-Radio%20");
Found : user_pref("CT2724386.RadioStationURL", "");
Found : user_pref("CT2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT272[...]
Found : user_pref("CT2724386.SearchInNewTabEnabled", true);
Found : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Tue Jan 04 2011 14:27:13 GMT+0100");
Found : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2724386.ServiceMapLastCheckTime", "Thu Mar 17 2011 16:39:47 GMT+0100");
Found : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2724386.SettingsLastCheckTime", "Tue Jan 04 2011 14:27:12 GMT+0100");
Found : user_pref("CT2724386.SettingsLastUpdate", "1292878138");
Found : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Tue Jan 04 2011 14:27:12 GMT+0100");
Found : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Found : user_pref("CT2724386.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Found : user_pref("CT2724386.Uninstall", true);
Found : user_pref("CT2724386.UserID", "UN60974308613677695");
Found : user_pref("CT2724386.WeatherNetwork", "");
Found : user_pref("CT2724386.WeatherPollDate", "Tue Jan 04 2011 14:27:13 GMT+0100");
Found : user_pref("CT2724386.WeatherUnit", "C");
Found : user_pref("CT2724386.clientLogIsEnabled", false);
Found : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2724386.ct2724407.DialogsAlignMode", "LTR");
Found : user_pref("CT2724386.ct2724407.FirstTimeSettingsDone", true);
Found : user_pref("CT2724386.ct2724407.GroupingInvalidateCache", false);
Found : user_pref("CT2724386.ct2724407.GroupingLastCheckTime", "Tue Jan 04 2011 14:27:13 GMT+0100");
Found : user_pref("CT2724386.ct2724407.GroupingLastErrorCode", "");
Found : user_pref("CT2724386.ct2724407.GroupingLastResponse", true);
Found : user_pref("CT2724386.ct2724407.GroupingLastServerUpdateTime", "129361239174000000");
Found : user_pref("CT2724386.ct2724407.InvalidateCache", false);
Found : user_pref("CT2724386.ct2724407.LanguagePackLastCheckTime", "Thu Mar 17 2011 16:39:47 GMT+0100");
Found : user_pref("CT2724386.ct2724407.Locale", "de");
Found : user_pref("CT2724386.ct2724407.RadioLastCheckTime", "Tue Jan 04 2011 14:27:13 GMT+0100");
Found : user_pref("CT2724386.ct2724407.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2724386.ct2724407.RadioLastUpdateServer", "129249047784100000");
Found : user_pref("CT2724386.ct2724407.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_[...]
Found : user_pref("CT2724386.ct2724407.SearchInNewTabLastCheckTime", "Thu Mar 17 2011 16:39:48 GMT+0100");
Found : user_pref("CT2724386.ct2724407.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2724386.ct2724407.SettingsLastCheckTime", "Thu Mar 17 2011 16:39:47 GMT+0100");
Found : user_pref("CT2724386.ct2724407.SettingsLastUpdate", "1299165927");
Found : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastCheck", "Thu Mar 17 2011 16:39:47 GMT+0100");
Found : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastUpdate", "1255348257");
Found : user_pref("CT2724386.ct2724407.toolbarAppMetaDataLastCheckTime", "Thu Mar 17 2011 16:39:47 GMT+0100"[...]
Found : user_pref("CT2724386.ct2724407.toolbarContextMenuLastCheckTime", "Thu Mar 17 2011 16:39:47 GMT+0100"[...]
Found : user_pref("CT2724386.myStuffEnabled", true);
Found : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2724386.testingCtid", "");
Found : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2724407", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/ct2724407/CT2724386[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"634[...]
Found : user_pref("CommunityToolbar.EngineOwner", "CT2724386");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "incredimail_mediabar_2");
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2724386");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "incredimail_mediabar_2");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://mystart.incredimail.com/mb44/?loc[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2724386");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386");
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Mar 16 2011 20:13:07 GMT+0100");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Mar 16 2011 20:13:07 GMT+0100");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1291052234");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "0628edaa-4208-40f5-a961-3620aef7abf8");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue Jan 04 2011 14:27:13 GMT+0100");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Jessy\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [14149 octets] - [01/08/2012 11:26:38]
########## EOF - C:\AdwCleaner[R1].txt - [14278 octets] ##########
Themen zu Fehlermeldung beim Systemstart: Problem beim Starten von C/User...appdata..exe
Zum Thema Fehlermeldung beim Systemstart: Problem beim Starten von C/User...appdata..exe - Alles gemacht!
Nachdem ich den Suchlauf mit Malwarebytes gemacht hatte gabs übrigens 2 Befunde die ich entfernen konnte. Beim darauf folgenden Neustart kam auch keine Fehlermeldung mehr! yay!
Das kam - Fehlermeldung beim Systemstart: Problem beim Starten von C/User...appdata..exe...