![]() |
|
Log-Analyse und Auswertung: Win 8.1, Mozilla Firefox Startseite wird immer wieder zurückgesetztWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Win 8.1, Mozilla Firefox Startseite wird immer wieder zurückgesetzt Hallo, seit heute will Firefox nicht mehr so wie ich will. Egal ob ich im Firefox selber oder in den Internetoptionen die Startseite ändere, wird sie immer auf "https://www.google.de/?hl=de&gl=de&gws_rd=ssl" zurückgesetzt. Habe zuerst mal den Virenscanner drüber geschickt. Norton Schnellscan hat nichts gefunden. Dann hab ich etwas gegoogelt und hab noch eine Art Tiefenscan von Norton gemacht. Der hat zwei Probleme gefunden, war aber nicht im Stande die Dateien zu löschen oder in die Quarantäne zu verschieben. Dann hab ich Malwarebytes Anti-Malware installiert und suchen lassen. Das hat einiges gefunden und dann wurden die Bedrohungen entfernt. Die darauffolgende Suche brachte dann keine Ergebnisse mehr. Das Problem besteht aber weiterhin. In Vorbereitung hab ich jetzt noch FRST installiert und durchlaufen lassen. MBAM erster Scan Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2016/02/03 14:39:19 +0100</date> <logfile>mbam-log-2016-02-03 (14-39-16).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.0.1024</version> <malware-database>v2016.02.03.03</malware-database> <rootkit-database>v2016.01.20.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <hostname>MROST</hostname> <ip>192.168.2.100</ip> <osversion>Windows 8.1</osversion> <arch>x64</arch> <username>Michael</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>517882</objects> <time>2184</time> <processes>1</processes> <modules>0</modules> <keys>31</keys> <values>5</values> <datas>0</datas> <folders>5</folders> <files>18</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <process><path>C:\Windows\System32\DnsBlockUpdateSvc.exe</path><vendor>PUP.Optional.DNSBlock.BrwsrFlsh</vendor><action>delete-on-reboot</action><pid>2532</pid><hash>4609b6a62e6b3105395a8b58c33e926e</hash></process> <key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DnsBlockUpdateSvc</path><vendor>PUP.Optional.DNSBlock.BrwsrFlsh</vendor><action>success</action><hash>4609b6a62e6b3105395a8b58c33e926e</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect.1</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect.1</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect.1</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}\INPROCSERVER32</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\APPID\DPBHO.DLL</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>75da0755b6e3e94d4c28dc66e91b0af6</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\DPBHO.DLL</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>202f025a1c7dbf77e58f0b379b69de22</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\DPBHO.DLL</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>65eaafadc8d10b2b5b19ed5540c4fd03</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\SmartSaver+ 15</path><vendor>PUP.Optional.SmartSaver</vendor><action>success</action><hash>044bbca07a1f74c2401e19dab251db25</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>d9761a42f9a0072f28355b726c9707f9</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>7ed1bd9fb4e51c1a5a035e6f996ac33d</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY</path><vendor>PUP.Optional.GlobalUpdate</vendor><action>success</action><hash>8fc05dff475296a06b9040968f74e917</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\FFHELPER\SmootherWeb</path><vendor>PUP.Optional.SmootherWeb</vendor><action>success</action><hash>69e6c29ab8e191a51988b43f22e19967</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4377A9A0-62AA-47EC-A8FD-C5E1C364E5D2}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>f35c63f9405900366904d3fbec170000</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{897AF8BD-8A44-4176-86CB-58BBF61DF364}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>3c1392ca9801f442ce9f86484bb849b7</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFD79D32-127A-4201-8C37-E832DCE01BCC}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>d17e7ddf41588bab7eef8549946f8779</hash></key> <key><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002_Classes\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APPCONTAINER\STORAGE\WINDOWS_IE_AC_001\SOFTWARE\Crossrider</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>a1ae4715d2c7b1856a11e5540df78779</hash></key> <value><path>HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS</path><valuename>{98061C88-1849-4433-B251-A56FB6856055}</valuename><vendor>PUP.Optional.DownloadProtectExtension</vendor><action>success</action><valuedata>C:\WINDOWS\Installer\{F8FBA45D-2789-4DAA-8E18-FDB0A559B0CD}\{98061C88-1849-4433-B251-A56FB6856055}.xpi</valuedata><hash>72ddc3992772db5b6ab62aa7e12226da</hash></value> <value><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY</path><valuename>source</valuename><vendor>PUP.Optional.GlobalUpdate</vendor><action>success</action><valuedata>Firefox</valuedata><hash>8fc05dff475296a06b9040968f74e917</hash></value> <value><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4377A9A0-62AA-47EC-A8FD-C5E1C364E5D2}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>e34e2d9c-4069-4852-b92d-9b43435e2191-2.exe-buttonutil.exe</valuedata><hash>f35c63f9405900366904d3fbec170000</hash></value> <value><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{897AF8BD-8A44-4176-86CB-58BBF61DF364}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>e34e2d9c-4069-4852-b92d-9b43435e2191-2.exe-buttonutil.exe</valuedata><hash>3c1392ca9801f442ce9f86484bb849b7</hash></value> <value><path>HKU\S-1-5-21-3695500385-1387106-2215658511-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFD79D32-127A-4201-8C37-E832DCE01BCC}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>e34e2d9c-4069-4852-b92d-9b43435e2191-2.exe-buttonutil.exe</valuedata><hash>d17e7ddf41588bab7eef8549946f8779</hash></value> <folder><path>C:\Windows\Installer\{A054FB0B-6A0F-4925-BA8F-A14876E1E889}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>242bb1ab683104327a92874a60a324dc</hash></folder> <folder><path>C:\Windows\Installer\{F8FBA45D-2789-4DAA-8E18-FDB0A559B0CD}</path><vendor>PUP.Optional.DownloadProtect.ChrPRST</vendor><action>success</action><hash>d37c14486435251184affc4a36ced927</hash></folder> <folder><path>C:\Users\Michael\AppData\Local\DnsBlock</path><vendor>PUP.Optional.DNSBlock.BrwsrFlsh</vendor><action>success</action><hash>410e520a4455201615d5ad0535cdb24e</hash></folder> <folder><path>C:\Program Files (x86)\{513904E0-FEA3-4CF0-8799-3D773D9C898D}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>63ec213be4b5ee4830db996649bbe21e</hash></folder> <folder><path>C:\Program Files\{C9295C4B-5313-4998-B8C6-5284B2BA66C1}</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>5df2d18b6930b2840902609f986c8e72</hash></folder> <file><path>C:\Windows\System32\DnsBlockUpdateSvc.exe</path><vendor>PUP.Optional.DNSBlock.BrwsrFlsh</vendor><action>delete-on-reboot</action><hash>4609b6a62e6b3105395a8b58c33e926e</hash></file> <file><path>C:\Program Files\{C9295C4B-5313-4998-B8C6-5284B2BA66C1}\{FE5DD34C-10CE-4342-9F34-C52159997049}.bin</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></file> <file><path>C:\Program Files (x86)\{513904E0-FEA3-4CF0-8799-3D773D9C898D}\{D1979E1E-943F-4BAE-BCB3-1BCAAA041D39}.bin</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>d17e5903445552e4e1bf53d9f40cd12f</hash></file> <file><path>C:\Users\Michael\AppData\Local\Temp\nsb5C2A.tmp</path><vendor>PUP.Optional.Somoto</vendor><action>success</action><hash>b897f765bddc0c2ac47139be897bb749</hash></file> <file><path>C:\Users\Michael\AppData\Local\Temp\bitool.dll</path><vendor>PUP.Optional.Somoto</vendor><action>success</action><hash>d37c570575241620dc8862bbe71b4cb4</hash></file> <file><path>C:\Users\Michael\AppData\Local\Temp\setup.exe</path><vendor>PUP.Optional.DNSBlock.BrwsrFlsh</vendor><action>success</action><hash>a2ad0f4d2277290d7f329d9453aeb14f</hash></file> <file><path>C:\Windows\System32\dns.block</path><vendor>PUP.Optional.DNSBlocker.BrwsrFlsh</vendor><action>success</action><hash>a7a892ca7f1a6cca9e459c21d2317b85</hash></file> <file><path>C:\Windows\SysWOW64\dns.block</path><vendor>PUP.Optional.DNSBlocker.BrwsrFlsh</vendor><action>success</action><hash>cb84312b0d8cac8aeef50ab334cfde22</hash></file> <file><path>C:\Windows\Tasks\temp_e34e2d9c-4069-4852-b92d-9b43435e2191-2.job</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>62ed4c10cbce52e4bc85b815ed163ec2</hash></file> <file><path>C:\Windows\Installer\{A054FB0B-6A0F-4925-BA8F-A14876E1E889}\ccmdibcbjbnnheeokencimnofpmhhhailrx</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>242bb1ab683104327a92874a60a324dc</hash></file> <file><path>C:\Windows\Installer\{A054FB0B-6A0F-4925-BA8F-A14876E1E889}\xcmdibcbjbnnheeokencimnofpmhhhailml</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>242bb1ab683104327a92874a60a324dc</hash></file> <file><path>C:\Windows\Installer\{F8FBA45D-2789-4DAA-8E18-FDB0A559B0CD}\{98061C88-1849-4433-B251-A56FB6856055}.xpi</path><vendor>PUP.Optional.DownloadProtect.ChrPRST</vendor><action>success</action><hash>d37c14486435251184affc4a36ced927</hash></file> <file><path>C:\Program Files (x86)\{513904E0-FEA3-4CF0-8799-3D773D9C898D}\config.json</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>63ec213be4b5ee4830db996649bbe21e</hash></file> <file><path>C:\Program Files (x86)\{513904E0-FEA3-4CF0-8799-3D773D9C898D}\def.bin</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>63ec213be4b5ee4830db996649bbe21e</hash></file> <file><path>C:\Program Files\{C9295C4B-5313-4998-B8C6-5284B2BA66C1}\config.json</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>5df2d18b6930b2840902609f986c8e72</hash></file> <file><path>C:\Program Files\{C9295C4B-5313-4998-B8C6-5284B2BA66C1}\def.bin</path><vendor>PUP.Optional.DownloadProtect</vendor><action>success</action><hash>5df2d18b6930b2840902609f986c8e72</hash></file> <file><path>C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2wscxqt7.default\prefs.js</path><vendor>PUP.Optional.CrossRider</vendor><action>replaced</action><baddata>user_pref("extensions.crossrider.bic", "1491a4ed22b74ae62bbff68ebe160f61");</baddata><gooddata></gooddata><hash>331c55079cfd3ef8dc1b5c9c0103669a</hash></file> <file><path>C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2wscxqt7.default\prefs.js</path><vendor>PUP.Optional.Trovi</vendor><action>replaced</action><baddata>user_pref("searchreset.backup.browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3330189&octid=EB_ORIGINAL_CTID&ISID=M8A41461E-65F2-48FA-B33D-E8FFA489B141&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP9322786B-3572-47BF-A0AC-F372804C7DDC&D=040615");</baddata><gooddata></gooddata><hash>0c4361fb5a3f7fb7022a56a445bfbc44</hash></file> </items> </mbam-log> Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2016/02/03 15:29:37 +0100</date> <logfile>mbam-log-2016-02-03 (15-28-34).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.0.1024</version> <malware-database>v2016.02.03.03</malware-database> <rootkit-database>v2016.01.20.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <hostname>MROST</hostname> <ip>192.168.2.100</ip> <osversion>Windows 8.1</osversion> <arch>x64</arch> <username>Michael</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>515388</objects> <time>2493</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>0</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> </items> </mbam-log> Wie ich logfiles aus Norton rausbekomme hab ich noch nicht rausgefunden. Hoffe ihr könnt mir helfen. Danke und Grüße rosti |
Themen zu Win 8.1, Mozilla Firefox Startseite wird immer wieder zurückgesetzt |
browser, dateien, explorer, firefox, free, google, helper, ics, internet explorer, logfile, logfiles, löschen, malwarebytes, microsoft, mozilla, probleme, proxy, rootkits, scan, seite, software, startseite, suche, system, system32, temp, windows |