|
Plagegeister aller Art und deren Bekämpfung: Polizeivirus ÖsterreichWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.07.2012, 21:14 | #1 |
| Polizeivirus Österreich Hallo liebe Helfer ! Erstmals finde ich es toll dass es euch gibt und ihr schon so viele User helfen konntet , echt toll von euch! Ich hab mir wie so viele andere , nun auch diesen Polizeitrojaner (Österreich Version mit der aufforderung 100 € einzuzahlen usw) eingefangen. Ich bitte euch um Hilfe, ich weiss nicht mehr weiter. In den eigentlichen Benutzer komm ich nicht mehr rein. Ich hab mir einen 2ten Benutzer via Abegsicherter Modus angelegt und bin jetzt hier drinnen habe aber viele wichtige Daten am befallenen Benutzerkonto die ich retten bzw nicht löschen möchte ! Ich wollte einfach Systemwiederherstellung machen doch das geht anscheinend bei mehreren Windows 7 Nutzer nicht. Ich hab mir Malwarebytes und OTL bereits geladen..... Malwarebytes hat bei mir zwei Logdatein angegeben ?!? Ich häng mal an, lieben dank einstweil ! PHP-Code: |
22.07.2012, 22:44 | #2 |
/// Helfer-Team | Polizeivirus ÖsterreichFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL SRV - [2012.07.12 11:57:38 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) DRV - [2006.07.24 17:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen) IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\URLSearchHook: {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{6EBE8718-D052-3530-1F83-0FF35056FFC9}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms} IE - HKCU\..\SearchScopes,DefaultScope = {2D6C0518-920E-41C0-83B1-7773B7A85754} IE - HKCU\..\SearchScopes\{2D6C0518-920E-41C0-83B1-7773B7A85754}: "URL" = http://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{3F1E9CAF-5845-4881-90D7-256D0AF31ED6}: "URL" = http://go.web.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{4CFF6993-C1B8-44B1-967A-C543696A9DD2}: "URL" = http://services.zinio.com/search?s={searchTerms}&rf=sonyslices IE - HKCU\..\SearchScopes\{52F54DBE-B9BA-4773-93FB-07C610A1796C}: "URL" = http://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{54BBFBD3-67D3-4E30-8273-EB960405A670}: "URL" = http://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie IE - HKCU\..\SearchScopes\{A3463F22-E1B5-4487-9EE9-C03FA7277086}: "URL" = http://rover.ebay.com/rover/1/5221-29898-16445-29/4?mpre=http://shop.ebay.at/?oemInLn=ieSrch-Q311&_nkw={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) O2 - BHO: (BittorrentBar_DE Toolbar) - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (BittorrentBar_DE Toolbar) - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (BittorrentBar_DE Toolbar) - {64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll (Conduit Ltd.) O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O4 - HKCU..\Run: [DriverFinder] C:\Program Files (x86)\DriverFinder\DriverFinder.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Reg Error: Key error.) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\Shell - "" = AutoRun O33 - MountPoints2\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\Shell\AutoRun\command - "" = E:\autorun.exe [2012.07.18 19:32:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverFinder [2012.07.22 21:15:00 | 004,503,728 | ---- | M] () -- C:\ProgramData\kp_0loor.pad [2012.07.12 11:57:35 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012.07.21 18:11:01 | 004,503,728 | ---- | C] () -- C:\ProgramData\kp_0loor.pad [2012.06.23 23:32:27 | 000,000,000 | ---- | M] () -- C:\ProgramData\039142067658bf8c5af309d9f90637f8_c [2012.07.22 16:01:39 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.07.22 16:01:34 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job :Files ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
23.07.2012, 14:35 | #3 |
| Polizeivirus ÖsterreichCode:
ATTFilter All processes killed ========== OTL ========== Service AdobeFlashPlayerUpdateSvc stopped successfully! Service AdobeFlashPlayerUpdateSvc deleted successfully! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe moved successfully. Service StarOpen stopped successfully! Service StarOpen deleted successfully! C:\Windows\SysWOW64\drivers\StarOpen.sys moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}\ deleted successfully. C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6EBE8718-D052-3530-1F83-0FF35056FFC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EBE8718-D052-3530-1F83-0FF35056FFC9}\ not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2D6C0518-920E-41C0-83B1-7773B7A85754}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D6C0518-920E-41C0-83B1-7773B7A85754}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3F1E9CAF-5845-4881-90D7-256D0AF31ED6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F1E9CAF-5845-4881-90D7-256D0AF31ED6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4CFF6993-C1B8-44B1-967A-C543696A9DD2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4CFF6993-C1B8-44B1-967A-C543696A9DD2}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52F54DBE-B9BA-4773-93FB-07C610A1796C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52F54DBE-B9BA-4773-93FB-07C610A1796C}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{54BBFBD3-67D3-4E30-8273-EB960405A670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54BBFBD3-67D3-4E30-8273-EB960405A670}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3463F22-E1B5-4487-9EE9-C03FA7277086}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3463F22-E1B5-4487-9EE9-C03FA7277086}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}\ not found. File C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}\ not found. File C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}\ not found. File C:\Program Files (x86)\BittorrentBar_DE\prxtbBitt.dll not found. 64bit-Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ deleted successfully. C:\Programme\WEB.DE Toolbar\IE\uitb.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ deleted successfully. C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DriverFinder not found. C:\Program Files (x86)\DriverFinder\DriverFinder.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{eecbccd5-d0e4-11e1-92fb-9439e5a44826}\ not found. File E:\autorun.exe not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverFinder folder moved successfully. C:\ProgramData\kp_0loor.pad moved successfully. C:\Windows\SysWOW64\FlashPlayerApp.exe moved successfully. File C:\ProgramData\kp_0loor.pad not found. C:\ProgramData\039142067658bf8c5af309d9f90637f8_c moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Thomas\Desktop\cmd.bat deleted successfully. C:\Users\Thomas\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Secure ->Temp folder emptied: 3509724 bytes ->Temporary Internet Files folder emptied: 108198914 bytes ->FireFox cache emptied: 17476873 bytes ->Flash cache emptied: 60593 bytes User: Thomas ->Temp folder emptied: 88362365 bytes ->Temporary Internet Files folder emptied: 684016097 bytes ->Java cache emptied: 53468 bytes ->FireFox cache emptied: 1085647121 bytes ->Google Chrome cache emptied: 6333347 bytes ->Flash cache emptied: 103540 bytes User: Valerie ->Temp folder emptied: 49533833 bytes ->Temporary Internet Files folder emptied: 347529628 bytes ->Java cache emptied: 11429040 bytes ->FireFox cache emptied: 689969291 bytes ->Flash cache emptied: 58624 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 447120 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 250211 bytes RecycleBin emptied: 2557648605 bytes Total Files Cleaned = 5.389,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public User: Secure ->Flash cache emptied: 0 bytes User: Thomas ->Flash cache emptied: 0 bytes User: Valerie ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07232012_152512 Files\Folders moved on Reboot... C:\Users\Thomas\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Thomas\AppData\Local\Temp\~DF3AEFA5C13F0132E8.TMP not found! File\Folder C:\Users\Thomas\AppData\Local\Temp\~DF8315B4D03C7A07C4.TMP not found! File\Folder C:\Users\Thomas\AppData\Local\Temp\~DFC719A06FE0C0EA84.TMP not found! File\Folder C:\Users\Thomas\AppData\Local\Temp\~DFDDDEAC6CA26D6B80.TMP not found! C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGMSDLZK\afr[1].htm moved successfully. C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L066NMO0\120150-polizeivirus-osterreich[1].htm moved successfully. C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L066NMO0\ads[4].htm moved successfully. C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IRHE9VK2\affilinet_tpage[1].htm moved successfully. PendingFileRenameOperations files... File C:\Users\Thomas\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\Thomas\AppData\Local\Temp\~DF3AEFA5C13F0132E8.TMP not found! File C:\Users\Thomas\AppData\Local\Temp\~DF8315B4D03C7A07C4.TMP not found! File C:\Users\Thomas\AppData\Local\Temp\~DFC719A06FE0C0EA84.TMP not found! File C:\Users\Thomas\AppData\Local\Temp\~DFDDDEAC6CA26D6B80.TMP not found! File C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat not found! File C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGMSDLZK\afr[1].htm not found! File C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L066NMO0\120150-polizeivirus-osterreich[1].htm not found! File C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L066NMO0\ads[4].htm not found! File C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IRHE9VK2\affilinet_tpage[1].htm not found! Registry entries deleted on Reboot... |
23.07.2012, 17:07 | #4 |
/// Helfer-Team | Polizeivirus Österreich Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
23.07.2012, 19:14 | #5 |
| Polizeivirus Österreich Vielen vielen dank bislang ! Computer läuft super . Malwarebytes LOG Code:
ATTFilter Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.23.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Thomas :: THOMAS-VAIO [administrator] Protection: Enabled 23.07.2012 19:09:53 mbam-log-2012-07-23 (20-02-13).txt Scan type: Full scan (C:\|D:\|E:\|Q:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 374470 Time elapsed: 49 minute(s), 20 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33524C00-63FB-43DB-A6BF-0A4E14B24649} (Adware.Zwangi) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Thomas\AppData\Local\RavenBleuSA\bin\1.0.13.0\RavenBleuSACB.exe (Adware.HotBar.Gen) -> No action taken. (end) Code:
ATTFilter # AdwCleaner v1.703 - Logfile created 07/23/2012 at 20:10:09 # Updated 20/07/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Thomas - THOMAS-VAIO # Running from : C:\Users\Thomas\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\ConduitCommon Folder Found : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\extensions\ffxtlbr@funmoods.com Folder Found : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\extensions\plugin@yontoo.com File Found : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\searchplugins\SweetIm.xml ***** [Registry] ***** Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Funmoods Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Web Search Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\SweetIm Key Found : HKLM\SOFTWARE\DT Soft [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes [x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong [x64] Key Found : HKCU\Software\AppDataLow\Software\SmartBar [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\Funmoods [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Web Search [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKCU\Software\SweetIm ***** [Registre - GUID] ***** Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v11.0 (de) Profile name : default File : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\prefs.js Found : user_pref("CT2849855..clientLogIsEnabled", false); Found : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true); Found : user_pref("CT2849855.CTID", "CT2849855"); Found : user_pref("CT2849855.CurrentServerDate", "12-7-2012"); Found : user_pref("CT2849855.DSInstall", false); Found : user_pref("CT2849855.DialogsAlignMode", "LTR"); Found : user_pref("CT2849855.DialogsGetterLastCheckTime", "Thu Jul 12 2012 17:43:44 GMT+0200"); Found : user_pref("CT2849855.DownloadReferralCookieData", ""); Found : user_pref("CT2849855.EMailNotifierPollDate", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.FeedLastCount129349796701375473", 352); Found : user_pref("CT2849855.FeedPollDate129313974171006416", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313975698350231", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313976370850190", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313976648818968", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313977444757117", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313980389131455", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313980655381977", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313980886163259", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313981234756535", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313983226631720", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedPollDate129313983607725691", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.FeedTTL129313974171006416", 10); Found : user_pref("CT2849855.FeedTTL129313977444757117", 15); Found : user_pref("CT2849855.FeedTTL129313980655381977", 5); Found : user_pref("CT2849855.FeedTTL129313981234756535", 5); Found : user_pref("CT2849855.FirstServerDate", "25-6-2012"); Found : user_pref("CT2849855.FirstTime", true); Found : user_pref("CT2849855.FirstTimeFF3", true); Found : user_pref("CT2849855.FirstTimeHiddenVer", true); Found : user_pref("CT2849855.FixPageNotFoundErrors", true); Found : user_pref("CT2849855.GroupingServerCheckInterval", 1440); Found : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2849855.HPInstall", false); Found : user_pref("CT2849855.HasUserGlobalKeys", true); Found : user_pref("CT2849855.HomePageProtectorEnabled", false); Found : user_pref("CT2849855.HomepageBeforeUnload", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutA[...] Found : user_pref("CT2849855.Initialize", true); Found : user_pref("CT2849855.InitializeCommonPrefs", true); Found : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2849855.InstallationId", "fft8D92.tmp.exe"); Found : user_pref("CT2849855.InstallationType", "XPE"); Found : user_pref("CT2849855.InstalledDate", "Mon Jun 25 2012 21:35:01 GMT+0200"); Found : user_pref("CT2849855.IsAlertDBUpdated", true); Found : user_pref("CT2849855.IsGrouping", false); Found : user_pref("CT2849855.IsInitSetupIni", true); Found : user_pref("CT2849855.IsMulticommunity", false); Found : user_pref("CT2849855.IsOpenThankYouPage", true); Found : user_pref("CT2849855.IsOpenUninstallPage", false); Found : user_pref("CT2849855.LanguagePackLastCheckTime", "Thu Jul 12 2012 17:43:45 GMT+0200"); Found : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2849855.LastLogin_3.13.0.6", "Thu Jul 12 2012 17:43:46 GMT+0200"); Found : user_pref("CT2849855.LatestVersion", "3.13.0.6"); Found : user_pref("CT2849855.Locale", "de"); Found : user_pref("CT2849855.MCDetectTooltipHeight", "83"); Found : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2849855.MCDetectTooltipWidth", "295"); Found : user_pref("CT2849855.MyStuffEnabledAtInstallation", true); Found : user_pref("CT2849855.OriginalFirstVersion", "3.13.0.6"); Found : user_pref("CT2849855.SearchCaption", "BittorrentBar_DE Customized Web Search"); Found : user_pref("CT2849855.SearchEngineBeforeUnload", "Search"); Found : user_pref("CT2849855.SearchFromAddressBarIsInit", true); Found : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...] Found : user_pref("CT2849855.SearchInNewTabEnabled", true); Found : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Thu Jul 12 2012 17:43:38 GMT+0200"); Found : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2849855.SearchProtectorEnabled", false); Found : user_pref("CT2849855.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2849855.SendProtectorDataViaLogin", true); Found : user_pref("CT2849855.ServiceMapLastCheckTime", "Thu Jul 12 2012 17:43:42 GMT+0200"); Found : user_pref("CT2849855.SettingsLastCheckTime", "Thu Jul 12 2012 17:43:37 GMT+0200"); Found : user_pref("CT2849855.SettingsLastUpdate", "1337169810"); Found : user_pref("CT2849855.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2849855&SearchSource=13"); Found : user_pref("CT2849855.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Mon Jun 25 2012 21:35:00 GMT+0200"); Found : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1331806000"); Found : user_pref("CT2849855.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855"); Found : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2849855.UserID", "UN34272293393319106"); Found : user_pref("CT2849855.WeatherNetwork", ""); Found : user_pref("CT2849855.WeatherPollDate", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CT2849855.WeatherUnit", "C"); Found : user_pref("CT2849855.alertChannelId", "1241896"); Found : user_pref("CT2849855.autoDisableScopes", 0); Found : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] Found : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] Found : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] Found : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...] Found : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] Found : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] Found : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6D7072746E6E7377"); Found : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737376787A7474797D242F4B4947[...] Found : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] Found : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] Found : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] Found : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] Found : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] Found : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] Found : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] Found : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] Found : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] Found : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] Found : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] Found : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] Found : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] Found : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] Found : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] Found : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] Found : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] Found : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] Found : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Found : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] Found : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] Found : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] Found : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] Found : user_pref("CT2849855.backendstorage./9b-0?3g>d", "3A68406F6D3F6E447A42487746207B4C4A7D2520217C542A24[...] Found : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", ""); Found : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Found : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); Found : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484779213F3E484F4E4D464[...] Found : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "663A6A69717475767A6F71777B7A744A202120237E"); Found : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D7072746E6E7477787578"); Found : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A"); Found : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E"); Found : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443"); Found : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Found : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D"); Found : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Found : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2849855.globalFirstTimeInfoLastCheckTime", "Sun Jul 08 2012 08:53:37 GMT+0200"); Found : user_pref("CT2849855.homepageProtectorEnableByLogin", true); Found : user_pref("CT2849855.initDone", true); Found : user_pref("CT2849855.isAppTrackingManagerOn", true); Found : user_pref("CT2849855.myStuffEnabled", true); Found : user_pref("CT2849855.myStuffPublihserMinWidth", 400); Found : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2849855.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2849855.navigateToUrlOnSearch", false); Found : user_pref("CT2849855.revertSettingsEnabled", true); Found : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2849855.searchProtectorEnableByLogin", true); Found : user_pref("CT2849855.testingCtid", ""); Found : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Thu Jul 12 2012 17:43:45 GMT+0200"); Found : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Thu Jul 12 2012 17:43:44 GMT+0200"); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"b57[...] Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Thomas\\AppData\\Roaming\\Mozilla\\[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.babylon.com/?affID=112555&[...] Found : user_pref("CommunityToolbar.ToolbarsList", "CT2849855"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2849855"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2849855"); Found : user_pref("CommunityToolbar.globalUserId", "8a1d7155-6756-4a12-9f0b-fda345736bdb"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2849855"); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Jul 12 2012 17:43:4[...] Found : user_pref("CommunityToolbar.notifications.alertEnabled", false); Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Jul 12 2012 17:43:39 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "950b7dd4-f9e1-441f-b25f-5d7014166a07"); Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2Xz[...] Found : user_pref("CommunityToolbar.originalSearchEngine", "Search"); Found : user_pref("backup.old.browser.search.defaultenginename", "SweetIM Search"); Found : user_pref("backup.old.browser.search.selectedEngine", "SweetIM Search"); Found : user_pref("backup.old.browser.startup.homepage", "hxxp://home.sweetim.com/?crg=3.1010000&st=10"); Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Found : user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); Found : user_pref("browser.search.order.1", "Search the web (Babylon)"); Found : user_pref("browser.startup.homepage", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L[...] Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=112555&tt=060612_8_"); Found : user_pref("extensions.BabylonToolbar_i.hardId", "6662ef86000000000000a639e5a44825"); Found : user_pref("extensions.BabylonToolbar_i.id", "6662ef86000000000000a639e5a44825"); Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15516"); Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar_i.newTab", true); Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=112555&tt=06061[...] Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base"); Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1721:34:47"); Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Found : user_pref("extensions.enabledAddons", "OneClickDownload@OneClickDownload.com:1.0,plugin@yontoo.com:1[...] Found : user_pref("extensions.funmoods.aflt", "nv1"); Found : user_pref("extensions.funmoods.autoRvrt", false); Found : user_pref("extensions.funmoods.cntry", "AT"); Found : user_pref("extensions.funmoods.dfltLng", ""); Found : user_pref("extensions.funmoods.dfltSrch", true); Found : user_pref("extensions.funmoods.dnsErr", true); Found : user_pref("extensions.funmoods.envrmnt", "production"); Found : user_pref("extensions.funmoods.excTlbr", false); Found : user_pref("extensions.funmoods.hdrMd5", "C557C6F03B6BD234B8D9DAAC215952A6"); Found : user_pref("extensions.funmoods.hmpg", true); Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2[...] Found : user_pref("extensions.funmoods.id", "6662ef86000000000000a639e5a44825"); Found : user_pref("extensions.funmoods.instlDay", "15514"); Found : user_pref("extensions.funmoods.instlRef", "nv1"); Found : user_pref("extensions.funmoods.isdcmntcmplt", true); Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2222:43:56"); Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Found : user_pref("extensions.funmoods.newTab", true); Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=nv1&chnl=nv1&cd=2XzutAt[...] Found : user_pref("extensions.funmoods.prdct", "funmoods"); Found : user_pref("extensions.funmoods.prtnrId", "funmoods"); Found : user_pref("extensions.funmoods.sg", "none"); Found : user_pref("extensions.funmoods.smplGrp", "none"); Found : user_pref("extensions.funmoods.srchPrvdr", "Search"); Found : user_pref("extensions.funmoods.tlbrId", "base"); Found : user_pref("extensions.funmoods.tlbrSrchUrl", ""); Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2222:43:56"); Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Found : user_pref("extensions.funmoods_i.newTab", true); Found : user_pref("extensions.funmoods_i.smplGrp", "none"); Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2222:43:56"); Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2849855&SearchSource=2&q=[...] Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Found : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?crg=3.1010000&st=10"); Profile name : default File : C:\Users\Valerie\AppData\Roaming\Mozilla\Firefox\Profiles\z9c16o70.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Secure\AppData\Roaming\Mozilla\Firefox\Profiles\b7fzas7v.default\prefs.js [OK] File is clean. -\\ Google Chrome v20.0.1132.57 File : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "homepage": "hxxp://search.babylon.com/?affID=112555&tt=060612_8_&babsrc=HP_ss&mntrId=6662ef86000[...] Found : "name": "Web Search", Found : "search_url": "hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2Xz[...] Found : "homepage": "hxxp://home.sweetim.com/?crg=3.1010000&st=10", Found : "urls_to_restore_on_startup": ["hxxp://search.babylon.com/?affID=112555&tt=060612_8_&babsrc=HP_ss[...] ************************* AdwCleaner[R1].txt - [15516 octets] - [18/07/2012 20:18:08] AdwCleaner[S1].txt - [12744 octets] - [18/07/2012 20:18:24] AdwCleaner[R2].txt - [25127 octets] - [23/07/2012 17:51:59] AdwCleaner[R3].txt - [24863 octets] - [23/07/2012 20:10:09] ########## EOF - C:\AdwCleaner[R3].txt - [24992 octets] ########## |
23.07.2012, 22:16 | #6 |
/// Helfer-Team | Polizeivirus Österreich Warum wurden die Funde in MBAM nicht geloescht? Neues MBAM-Log!
__________________ --> Polizeivirus Österreich |
24.07.2012, 16:20 | #7 |
| Polizeivirus ÖsterreichCode:
ATTFilter alwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.24.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Thomas :: THOMAS-VAIO [administrator] Protection: Enabled 24.07.2012 16:12:55 mbam-log-2012-07-24 (16-12-55).txt Scan type: Full scan (C:\|Q:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 376187 Time elapsed: 46 minute(s), 51 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) |
24.07.2012, 23:42 | #8 |
/// Helfer-Team | Polizeivirus Österreich Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
25.07.2012, 19:11 | #9 |
| Polizeivirus Österreich 0 Code:
ATTFilter # AdwCleaner v1.703 - Logfile created 07/25/2012 at 17:38:25 # Updated 20/07/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Thomas - THOMAS-VAIO # Running from : C:\Users\Thomas\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\ConduitCommon Folder Deleted : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\extensions\ffxtlbr@funmoods.com Folder Deleted : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\extensions\plugin@yontoo.com File Deleted : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\searchplugins\SweetIm.xml ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Funmoods Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Web Search Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\SweetIm Key Deleted : HKLM\SOFTWARE\DT Soft ***** [Registre - GUID] ***** Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v11.0 (de) Profile name : default File : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\prefs.js C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\tdoscjxb.default\user.js ... Deleted ! Deleted : user_pref("CT2849855..clientLogIsEnabled", false); Deleted : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true); Deleted : user_pref("CT2849855.CTID", "CT2849855"); Deleted : user_pref("CT2849855.CurrentServerDate", "12-7-2012"); Deleted : user_pref("CT2849855.DSInstall", false); Deleted : user_pref("CT2849855.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2849855.DialogsGetterLastCheckTime", "Thu Jul 12 2012 17:43:44 GMT+0200"); Deleted : user_pref("CT2849855.DownloadReferralCookieData", ""); Deleted : user_pref("CT2849855.EMailNotifierPollDate", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.FeedLastCount129349796701375473", 352); Deleted : user_pref("CT2849855.FeedPollDate129313974171006416", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313975698350231", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313976370850190", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313976648818968", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313977444757117", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313980389131455", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313980655381977", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313980886163259", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313981234756535", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313983226631720", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedPollDate129313983607725691", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.FeedTTL129313974171006416", 10); Deleted : user_pref("CT2849855.FeedTTL129313977444757117", 15); Deleted : user_pref("CT2849855.FeedTTL129313980655381977", 5); Deleted : user_pref("CT2849855.FeedTTL129313981234756535", 5); Deleted : user_pref("CT2849855.FirstServerDate", "25-6-2012"); Deleted : user_pref("CT2849855.FirstTime", true); Deleted : user_pref("CT2849855.FirstTimeFF3", true); Deleted : user_pref("CT2849855.FirstTimeHiddenVer", true); Deleted : user_pref("CT2849855.FixPageNotFoundErrors", true); Deleted : user_pref("CT2849855.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2849855.HPInstall", false); Deleted : user_pref("CT2849855.HasUserGlobalKeys", true); Deleted : user_pref("CT2849855.HomePageProtectorEnabled", false); Deleted : user_pref("CT2849855.HomepageBeforeUnload", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutA[...] Deleted : user_pref("CT2849855.Initialize", true); Deleted : user_pref("CT2849855.InitializeCommonPrefs", true); Deleted : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2849855.InstallationId", "fft8D92.tmp.exe"); Deleted : user_pref("CT2849855.InstallationType", "XPE"); Deleted : user_pref("CT2849855.InstalledDate", "Mon Jun 25 2012 21:35:01 GMT+0200"); Deleted : user_pref("CT2849855.IsAlertDBUpdated", true); Deleted : user_pref("CT2849855.IsGrouping", false); Deleted : user_pref("CT2849855.IsInitSetupIni", true); Deleted : user_pref("CT2849855.IsMulticommunity", false); Deleted : user_pref("CT2849855.IsOpenThankYouPage", true); Deleted : user_pref("CT2849855.IsOpenUninstallPage", false); Deleted : user_pref("CT2849855.LanguagePackLastCheckTime", "Thu Jul 12 2012 17:43:45 GMT+0200"); Deleted : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2849855.LastLogin_3.13.0.6", "Thu Jul 12 2012 17:43:46 GMT+0200"); Deleted : user_pref("CT2849855.LatestVersion", "3.13.0.6"); Deleted : user_pref("CT2849855.Locale", "de"); Deleted : user_pref("CT2849855.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2849855.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2849855.MyStuffEnabledAtInstallation", true); Deleted : user_pref("CT2849855.OriginalFirstVersion", "3.13.0.6"); Deleted : user_pref("CT2849855.SearchCaption", "BittorrentBar_DE Customized Web Search"); Deleted : user_pref("CT2849855.SearchEngineBeforeUnload", "Search"); Deleted : user_pref("CT2849855.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...] Deleted : user_pref("CT2849855.SearchInNewTabEnabled", true); Deleted : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Thu Jul 12 2012 17:43:38 GMT+0200"); Deleted : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2849855.SearchProtectorEnabled", false); Deleted : user_pref("CT2849855.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT2849855.SendProtectorDataViaLogin", true); Deleted : user_pref("CT2849855.ServiceMapLastCheckTime", "Thu Jul 12 2012 17:43:42 GMT+0200"); Deleted : user_pref("CT2849855.SettingsLastCheckTime", "Thu Jul 12 2012 17:43:37 GMT+0200"); Deleted : user_pref("CT2849855.SettingsLastUpdate", "1337169810"); Deleted : user_pref("CT2849855.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2849855&SearchSource=13"); Deleted : user_pref("CT2849855.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Mon Jun 25 2012 21:35:00 GMT+0200"); Deleted : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1331806000"); Deleted : user_pref("CT2849855.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855"); Deleted : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Deleted : user_pref("CT2849855.UserID", "UN34272293393319106"); Deleted : user_pref("CT2849855.WeatherNetwork", ""); Deleted : user_pref("CT2849855.WeatherPollDate", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CT2849855.WeatherUnit", "C"); Deleted : user_pref("CT2849855.alertChannelId", "1241896"); Deleted : user_pref("CT2849855.autoDisableScopes", 0); Deleted : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6D7072746E6E7377"); Deleted : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737376787A7474797D242F4B4947[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] Deleted : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] Deleted : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] Deleted : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Deleted : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] Deleted : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] Deleted : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] Deleted : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] Deleted : user_pref("CT2849855.backendstorage./9b-0?3g>d", "3A68406F6D3F6E447A42487746207B4C4A7D2520217C542A24[...] Deleted : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", ""); Deleted : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Deleted : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); Deleted : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484779213F3E484F4E4D464[...] Deleted : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "663A6A69717475767A6F71777B7A744A202120237E"); Deleted : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D7072746E6E7477787578"); Deleted : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A"); Deleted : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E"); Deleted : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443"); Deleted : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Deleted : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D"); Deleted : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Deleted : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Deleted : user_pref("CT2849855.globalFirstTimeInfoLastCheckTime", "Sun Jul 08 2012 08:53:37 GMT+0200"); Deleted : user_pref("CT2849855.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT2849855.initDone", true); Deleted : user_pref("CT2849855.isAppTrackingManagerOn", true); Deleted : user_pref("CT2849855.myStuffEnabled", true); Deleted : user_pref("CT2849855.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2849855.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2849855.navigateToUrlOnSearch", false); Deleted : user_pref("CT2849855.revertSettingsEnabled", true); Deleted : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT2849855.searchProtectorEnableByLogin", true); Deleted : user_pref("CT2849855.testingCtid", ""); Deleted : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Thu Jul 12 2012 17:43:45 GMT+0200"); Deleted : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Thu Jul 12 2012 17:43:44 GMT+0200"); Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"b57[...] Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Thomas\\AppData\\Roaming\\Mozilla\\[...] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.babylon.com/?affID=112555&[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2849855"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2849855"); Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2849855"); Deleted : user_pref("CommunityToolbar.globalUserId", "8a1d7155-6756-4a12-9f0b-fda345736bdb"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2849855"); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Jul 12 2012 17:43:4[...] Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", false); Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Jul 12 2012 17:43:39 GMT+0200"); Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "950b7dd4-f9e1-441f-b25f-5d7014166a07"); Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2Xz[...] Deleted : user_pref("CommunityToolbar.originalSearchEngine", "Search"); Deleted : user_pref("backup.old.browser.search.defaultenginename", "SweetIM Search"); Deleted : user_pref("backup.old.browser.search.selectedEngine", "SweetIM Search"); Deleted : user_pref("backup.old.browser.startup.homepage", "hxxp://home.sweetim.com/?crg=3.1010000&st=10"); Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Deleted : user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); Deleted : user_pref("browser.search.order.1", "Search the web (Babylon)"); Deleted : user_pref("browser.startup.homepage", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L[...] Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=112555&tt=060612_8_"); Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "6662ef86000000000000a639e5a44825"); Deleted : user_pref("extensions.BabylonToolbar_i.id", "6662ef86000000000000a639e5a44825"); Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15516"); Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar_i.newTab", true); Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=112555&tt=06061[...] Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1721:34:47"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Deleted : user_pref("extensions.enabledAddons", "OneClickDownload@OneClickDownload.com:1.0,plugin@yontoo.com:1[...] Deleted : user_pref("extensions.funmoods.aflt", "nv1"); Deleted : user_pref("extensions.funmoods.autoRvrt", false); Deleted : user_pref("extensions.funmoods.cntry", "AT"); Deleted : user_pref("extensions.funmoods.dfltLng", ""); Deleted : user_pref("extensions.funmoods.dfltSrch", true); Deleted : user_pref("extensions.funmoods.dnsErr", true); Deleted : user_pref("extensions.funmoods.envrmnt", "production"); Deleted : user_pref("extensions.funmoods.excTlbr", false); Deleted : user_pref("extensions.funmoods.hdrMd5", "C557C6F03B6BD234B8D9DAAC215952A6"); Deleted : user_pref("extensions.funmoods.hmpg", true); Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2[...] Deleted : user_pref("extensions.funmoods.id", "6662ef86000000000000a639e5a44825"); Deleted : user_pref("extensions.funmoods.instlDay", "15514"); Deleted : user_pref("extensions.funmoods.instlRef", "nv1"); Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true); Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2222:43:56"); Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Deleted : user_pref("extensions.funmoods.newTab", true); Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=nv1&chnl=nv1&cd=2XzutAt[...] Deleted : user_pref("extensions.funmoods.prdct", "funmoods"); Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods"); Deleted : user_pref("extensions.funmoods.sg", "none"); Deleted : user_pref("extensions.funmoods.smplGrp", "none"); Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search"); Deleted : user_pref("extensions.funmoods.tlbrId", "base"); Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", ""); Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2222:43:56"); Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Deleted : user_pref("extensions.funmoods_i.newTab", true); Deleted : user_pref("extensions.funmoods_i.smplGrp", "none"); Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2222:43:56"); Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2849855&SearchSource=2&q=[...] Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?crg=3.1010000&st=10"); Profile name : default File : C:\Users\Valerie\AppData\Roaming\Mozilla\Firefox\Profiles\z9c16o70.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Secure\AppData\Roaming\Mozilla\Firefox\Profiles\b7fzas7v.default\prefs.js [OK] File is clean. -\\ Google Chrome v20.0.1132.57 File : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "homepage": "hxxp://search.babylon.com/?affID=112555&tt=060612_8_&babsrc=HP_ss&mntrId=6662ef86000[...] Deleted : "name": "Web Search", Deleted : "search_url": "hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2Xz[...] Deleted : "homepage": "hxxp://home.sweetim.com/?crg=3.1010000&st=10", Deleted : "urls_to_restore_on_startup": ["hxxp://search.babylon.com/?affID=112555&tt=060612_8_&babsrc=HP_ss[...] ************************* AdwCleaner[R1].txt - [15516 octets] - [18/07/2012 20:18:08] AdwCleaner[S1].txt - [12744 octets] - [18/07/2012 20:18:24] AdwCleaner[R2].txt - [25127 octets] - [23/07/2012 17:51:59] AdwCleaner[R3].txt - [24968 octets] - [23/07/2012 20:10:09] AdwCleaner[S2].txt - [24541 octets] - [25/07/2012 17:38:25] ########## EOF - C:\AdwCleaner[S2].txt - [24670 octets] ########## Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 25.07.2012 17:46:37 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, Q:\ Archiv Scan: An ADS Scan: An Scan Beginn: 25.07.2012 19:21:20 C:\Users\Thomas\Documents\cs1.5\hlds.exe gefunden: Win32.Malware!E2 C:\Users\Thomas\Documents\cs1.5\Half Life CDkeygen.exe gefunden: Riskware.Keygen.halflife!E2 C:\Users\Thomas\Desktop\Thomas\cs1.5\Half Life CDkeygen.exe gefunden: Riskware.Keygen.halflife!E2 C:\Users\Thomas\Desktop\Thomas\cs1.5\hlds.exe gefunden: Win32.Malware!E2 Gescannt 598500 Gefunden 4 Scan Ende: 25.07.2012 19:57:24 Scan Zeit: 0:36:04 |
25.07.2012, 19:31 | #10 |
/// Helfer-Team | Polizeivirus Österreich Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
29.07.2012, 18:05 | #11 |
| Polizeivirus ÖsterreichCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=cce46db0ef4cfc4799fc486e049e95cb # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-27 04:37:38 # local_time=2012-07-27 06:37:38 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 106447 94967810 0 0 # compatibility_mode=8192 67108863 100 0 2553 2553 0 0 # scanned=165892 # found=2 # cleaned=2 # scan_time=25899 C:\Program Files (x86)\intellidownload\torrent.exe Win32/BundleInstaller application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Thomas\Downloads\Verified_3d_darts_professional.exe Win32/BundleInstaller application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=cce46db0ef4cfc4799fc486e049e95cb # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-29 04:08:53 # local_time=2012-07-29 06:08:53 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 82490 95201737 0 0 # compatibility_mode=8192 67108863 100 0 236480 236480 0 0 # scanned=168008 # found=0 # cleaned=0 # scan_time=6245 |
29.07.2012, 18:16 | #12 |
/// Helfer-Team | Polizeivirus Österreich Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
19.08.2012, 18:53 | #13 |
/// Helfer-Team | Polizeivirus Österreich Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Themen zu Polizeivirus Österreich |
.dll, adobe, adobe flash player, bho, bingbar, bonjour, conduit, error, explorer, firefox, flash player, format, home, logfile, löschen, malwarebytes, microsoft, origin, plug-in, programme, realtek, registry, scan, searchscopes, secure, symantec, wichtige daten, windows, winlogon, wlan |