![]() |
Neues Mitglied der Gruppe "my start incredibar" - Ich möchte bitte weg :-) Hallo, ich habe etwas von softronic.com heruntergeladen und installiert und na ja, jetzt muss ich um Hilfe bitten. Das Problem: wenn ich den Browser (Mozilla) öffne muss ich seeeeeeeeehr lange warten bis sich einen neuen Tab öffnet. Bis dahin ist den Browser komplett blockiert. Ich bekomme folgende Nachricht: "Ein Skript auf dieser Seite ist eventuell beschäftigt oder es antwortet nicht mehr. Sie können das Skript jetzt stoppen oder fortsetzen, um zu sehen, ob das Skript fertig wird." Egal, ob ich "Skript stoppen" oder "weiterlaufen" anklicke, den Browser ist blockiert so lange wie den Skript das möchte. Irgendwann bekomme ich einen neuen Tab mit incredibar … ( irgendwas ) und dann kann ich meine Recherchen weiter durchführen. Aber wenn ich in einem geöffneten Tab eine neue Seite eintippe, dann kann ich problemlos (also ohne Warten) mein Ziel erreichen. Schnell öffnet sich auch neuen Tab/Fenster in dem ich die Option „in neuen Tab/Fenster öffnen“ einklicke. Manchmal (selten) zeigt sich jedoch die Nachricht von oben mit der entsprechenden Blockade, beim schon geöffneten Fenster. Zudem - der Laptop ist die ganze Zeit irgendwie selbst am Arbeiten. Die Lüfter hören kaum auf sich stark zu drehen. Nun bis jetzt, nachdem ich euch gefunden habe, bin so wie Sie es beschrieben haben vorgegangen: 1. Den Malwarebytes heruntergeladen und installiert 2. Dann den Scan durchlaufen gelassen 3. Es wurden 2 infizierte Objekte gefunden 4. Ich sehe keinen Bericht, den ich kopieren kann.(?) Ansonsten habe ich Avira, die nichts gesehen hat. Ich benutze Win XP. Danke schön! Liebe Grüße |
:hallo: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. 2. Schritt Systemscan mit OTL (bebilderte Anleitung) |
Hallo, als Erstens bedanke mich für Ihre Antwort. Nun ich habe noch einmal die Scan mit dem Malawarebytes durchgeführt. Diesmal zeigte mir dass ich keine infizierte Objekte habe. Wobei beim ersten Scan hatte zwei böseartigen Objekte gefunden, die ich damals nicht gelöscht habe und auch nicht in die Quarantäne verschoben habe. Die alte Ergebnisse sind: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.14.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: YOUR-8E8F8D6E2D [Administrator] Schutz: Aktiviert 14.08.2012 16:50:32 mbam-log-2012-08-14 (19-50-14).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 349101 Laufzeit: 1 Stunde(n), 49 Minute(n), 50 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Program Files\SoftonicDownloader_for_winx-dvd-player.exe (PUP.ToolbarDownloader) -> Keine Aktion durchgeführt. C:\Program Files\SoftonicDownloader_fuer_avs-media-player.exe (PUP.ToolbarDownloader) -> Keine Aktion durchgeführt. (Ende) Die Ergebnisse vom heute, nach die Aktualisierung: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.22.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: YOUR-8E8F8D6E2D [Administrator] Schutz: Aktiviert 22.08.2012 10:02:16 mbam-log-2012-08-22 (10-02-16).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 348873 Laufzeit: 2 Stunde(n), 45 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Die Ergebnisse vom OTL-Extras.Txt:OTL Logfile: Code: OTL Extras logfile created on: 22.08.2012 18:28:16 - Run 1 Die Ergebnise vom OTL.Txt:OTL Logfile: Code: OTL logfile created on: 22.08.2012 18:28:16 - Run 1 ---- Mit besten Grüßen |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Hallo t'john, ich habe versucht die von dir empfohlene Schritte zu folgen. Zuerst habe ich den OTL vom Ordner "Programme" auf dem Desktop übertragen. Danach habe ich den OTL.exe geöffnet und den Skript rein kopiert. Danach habe ich den Avira deaktieviert und die restliche Fenster geschloßen. Nach dem ich das FIX-Button gedrückt habe, habe ich eine Nachricht bekommen, dass Malwarebytes Anti-Malware stört. Danach habe ich Malwarebytes Anti-Malware ausgeschaltet und erneut den FIX gedrückt. Denn 4 Stunden in der Nacht nichts passierte, wurde den Laptop ausgeschaltet. Heute habe ich wieder versucht - also den Skript rein kopiert und FIX gedrückt. Schon 4 Stunden sehe ich keine Änderung. Es steht, dass OTL "not Responding" und unten ist geschrieben "Killing processes. DO NOT INTERRUPT ..." Also jetzt weiss ich nicht soll ich einfach lange warten, oder läuft bei mir etwas schief. Außerdem in der vorherigen Betrag stand ich solle die Funde von Malwarebytes Anti-Malware löschen. Denn beim zweiten Scan keine Funde vorhanden waren, habe ich die beide böseartigen Objekte nicht gelöscht. Ist so korrekt? Ansonsten mittlerweile habe ich gemerkt, dass meine gespeicherte Passwords nicht mehr gespeichert sind. Wenn ich das Internet-Explorer öffne, dann bekomme ich in der Mitte vom Bildschirm immer irgendwelche kleine Fensterchen mit vershciedenen Werbung, die nicht so leicht weg zu bekommen sind und sofort nach der Schließung öffnet sich eine weitere. Und die Malwarebytes Anti-Malware läuft in 3 Tage aus, falls das von Bedeutung ist. Danke schön für die Unterstüzung! Ich sehe, dass allein kann ich dieses Problem gar nicht lösen ... Schöne Grüße tantan |
Bitte mal im abgesicherten Starten und dort probieren. |
Ich habe den abgesicherten Modus gestartet. So habe ich keine Internetverbindung. Aber auch kann ich durch Copy-Paste den Text in OTL nicht einfügen. Spielt eine Rolle, dass mein Windows in Englisch ist? Grüße tantan |
Du kannst dir den Fix in eine Text-Datei kopieren. Start - Programme - Zubehoer - Editor |
Hallo t'john, danke sehr! OTL hat es geschafft. Den Bericht finden Sie unten meine Nachricht. Ich sehe, dass der Compi erstmal normal schnell funktioniert. Aber 1.als Startseite habe ich folgendes: hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc= 2.Ich habe auf der Festplastte noch C:\Program Files\Softonic\Softonic\1.6.7.4 3.Irgendwelche Fensterchen in blau mit Werbung zeigen sich immer noch. 4. Wenn ich einen Tab öffne, habe ich eine Leiste mit "incredibar" mit Suchmöglichkeit sowie irgendwelche Werrbebuttons. Gibt es Möglichkeit diese auch zu löschen? Vielmals Danke !!!! Die Ergebnisse von OTL: All processes killed ========== OTL ========== Service Web Assistant Updater stopped successfully! Service Web Assistant Updater deleted successfully! C:\Program Files\Web Assistant\ExtensionUpdaterService.exe moved successfully. Service WDICA stopped successfully! Service WDICA deleted successfully! File File not found not found. Service PDRFRAME stopped successfully! Service PDRFRAME deleted successfully! File File not found not found. Service PDRELI stopped successfully! Service PDRELI deleted successfully! File File not found not found. Service PDFRAME stopped successfully! Service PDFRAME deleted successfully! File File not found not found. Service PDCOMP stopped successfully! Service PDCOMP deleted successfully! File File not found not found. Service PCIDump stopped successfully! Service PCIDump deleted successfully! File File not found not found. Service lbrtfdc stopped successfully! Service lbrtfdc deleted successfully! File File not found not found. Service i2omgmt stopped successfully! Service i2omgmt deleted successfully! File File not found not found. Service Changer stopped successfully! Service Changer deleted successfully! File File not found not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-3402263254-3905192389-2916328827-500\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ deleted successfully. C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully. HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{27E9840D-D155-4819-BE9F-B4FD3FB68DF6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27E9840D-D155-4819-BE9F-B4FD3FB68DF6}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{B0C4CFAA-90B7-4E4D-92F4-61FFC22D746A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0C4CFAA-90B7-4E4D-92F4-61FFC22D746A}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found. HKU\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "MyStart Search" removed from browser.search.defaultenginename Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "Search the web (Softonic)" removed from browser.search.selectedEngine Prefs.js: "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q=" removed from keyword.URL Prefs.js: 0 removed from network.proxy.type Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. C:\Program Files\Web Assistant\Firefox\defaults\preferences folder moved successfully. C:\Program Files\Web Assistant\Firefox\defaults folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\skin folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\locale\en-US folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\locale folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content\resources folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content\libraries folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome folder moved successfully. C:\Program Files\Web Assistant\Firefox folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0\resources folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0\libraries folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0 folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. C:\Program Files\Web Assistant\Extension32.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}\ deleted successfully. C:\Program Files\Softonic\Softonic\1.6.7.4\bh\Softonic.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}\ deleted successfully. C:\Program Files\Softonic\Softonic\1.6.7.4\SoftonicTlbr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77}\ deleted successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll moved successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Program Files\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found. Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer not found. Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTOEXEC.BAT moved successfully. C:\Program Files\SoftonicDownloader_for_winx-dvd-player.exe moved successfully. C:\Program Files\SoftonicDownloader_fuer_avs-media-player.exe moved successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\MediaBA folder moved successfully. C:\Program Files\BetterAds folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Incredibar.com\incredibar folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Incredibar.com folder moved successfully. C:\Program Files\Perion\NewTab folder moved successfully. C:\Program Files\Perion folder moved successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh folder moved successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14 folder moved successfully. C:\Program Files\Incredibar.com\incredibar folder moved successfully. C:\Program Files\Incredibar.com folder moved successfully. C:\Program Files\Web Assistant\resources folder moved successfully. C:\Program Files\Web Assistant\libraries folder moved successfully. C:\Program Files\Web Assistant folder moved successfully. C:\user.js moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe\Acrobat\10.0 folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe\Acrobat folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp folder moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration An internal error occurred: The request is not supported. Please contact Microsoft Product Support Services for further help. Additional information: Unable to query host name. C:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 173321930 bytes ->Temporary Internet Files folder emptied: 44006134 bytes ->FireFox cache emptied: 459976934 bytes ->Google Chrome cache emptied: 7581174 bytes ->Flash cache emptied: 59310 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 56478 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33043 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Photohop %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 12541725 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 144597176 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 970338927 bytes Total Files Cleaned = 1.729,00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08262012_073518 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF90DC.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF90E9.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9143.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9150.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9256.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9263.tmp not found! C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Sehr gut! :daumenhoc 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Hallo t'john, ja, für dich mehrere daumenhoch :-) Heute habe ich die nächste Schritte schon erledigt und unten finde bitte die beiden Berichte. Nun leider gestern hatte ich weiter Probleme mit Mozzila. Irgendwelche Seiten öffnen sich ab und zu und blockieren den Browser. Heute: Die blaue Fensterchen springen immer noch und hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc= öffnet sich immer noch als favorite. Beim Internet Explorer ist alles sauber, sogar habe diese Seite als erste, die ich mir wünsche. Vom Herzen vielen Dank! Ich fühle mich geretet :-) :applaus: Und die Malwarebytes kann ich nur noch 1 Tag nutzen. Schöne Grüße tantan Nun die Berichte vom Schritt 1: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.27.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: YOUR-8E8F8D6E2D [Administrator] Schutz: Aktiviert 27.08.2012 09:53:07 mbam-log-2012-08-27 (09-53-07).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 341020 Laufzeit: 2 Stunde(n), 44 Minute(n), 44 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Vom Schritt 2 # AdwCleaner v1.801 - Logfile created 08/27/2012 at 18:36:17 # Updated 14/08/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Administrator - YOUR-8E8F8D6E2D # Boot Mode : Normal # Running from : C:\Documents and Settings\Administrator\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Documents and Settings\Administrator\Local Settings\Application Data\AskToolbar Folder Found : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Folder Found : C:\Documents and Settings\Administrator\Application Data\AskToolbar Folder Found : C:\Documents and Settings\Administrator\Application Data\Softonic Folder Found : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\extensions\ffxtlbr@incredibar.com Folder Found : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\extensions\ffxtlbra@softonic.com Folder Found : C:\Program Files\Ask.com Folder Found : C:\Program Files\Softonic Folder Found : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Found : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\searchplugins\MyStart Search.xml File Found : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\searchplugins\softonic.xml File Found : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job ***** [Registry] ***** Key Found : HKCU\Software\APN Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\Ask.com.tmp Key Found : HKCU\Software\AskToolbar Key Found : HKCU\Software\IM Key Found : HKCU\Software\ImInstaller Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\Web Assistant Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Found : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc Key Found : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1 Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\I Key Found : HKLM\SOFTWARE\Classes\Incredibar.dskBnd Key Found : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr Key Found : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1 Key Found : HKLM\SOFTWARE\Classes\IncredibarApp.appCore Key Found : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\S Key Found : HKLM\SOFTWARE\Classes\Softonic.dskBnd Key Found : HKLM\SOFTWARE\Classes\Softonic.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr Key Found : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr.1 Key Found : HKLM\SOFTWARE\Classes\SoftonicApp.appCore Key Found : HKLM\SOFTWARE\Classes\SoftonicApp.appCore.1 Key Found : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc Key Found : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc.1 Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar Key Found : HKLM\SOFTWARE\Web Assistant ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE} Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Key Found : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Found : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E} Key Found : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Key Found : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Key Found : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Key Found : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Key Found : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Key Found : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Key Found : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Key Found : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Key Found : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Key Found : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Key Found : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Key Found : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Key Found : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Key Found : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Key Found : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Key Found : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Found : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Key Found : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Key Found : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Key Found : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Key Found : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Key Found : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Key Found : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Key Found : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Key Found : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc= -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\prefs.js Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&loc=FF_NT"); Found : user_pref("extensions.Softonic.admin", false); Found : user_pref("extensions.Softonic.aflt", "SD"); Found : user_pref("extensions.Softonic.autoRvrt", "false"); Found : user_pref("extensions.Softonic.cntry", "DE"); Found : user_pref("extensions.Softonic.cv", "cv5"); Found : user_pref("extensions.Softonic.dfltLng", "de"); Found : user_pref("extensions.Softonic.dfltSrch", true); Found : user_pref("extensions.Softonic.dfltlng", "de"); Found : user_pref("extensions.Softonic.dfltsrch", true); Found : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); Found : user_pref("extensions.Softonic.dspOld", "Ask.com"); Found : user_pref("extensions.Softonic.envrmnt", "production"); Found : user_pref("extensions.Softonic.excTlbr", false); Found : user_pref("extensions.Softonic.hdrMd5", "44E6943E13884C59062D01287B6BB8E2"); Found : user_pref("extensions.Softonic.hmpg", true); Found : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=1[...] Found : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=13&[...] Found : user_pref("extensions.Softonic.hpOld", "hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&local[...] Found : user_pref("extensions.Softonic.hrdid", "84d8779c000000000000002306d95d81"); Found : user_pref("extensions.Softonic.id", "84d8779c000000000000002306d95d81"); Found : user_pref("extensions.Softonic.instlDay", "15560"); Found : user_pref("extensions.Softonic.instlRef", "INF1205T01"); Found : user_pref("extensions.Softonic.instlday", "15560"); Found : user_pref("extensions.Softonic.instlref", "INF1205T01"); Found : user_pref("extensions.Softonic.isdcmntcmplt", "false"); Found : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSourc[...] Found : user_pref("extensions.Softonic.keywordurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSourc[...] Found : user_pref("extensions.Softonic.lastVrsnTs", "1.6.7.412:59:45"); Found : user_pref("extensions.Softonic.mntrvrsn", "1.3.0"); Found : user_pref("extensions.Softonic.newTab", true); Found : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource[...] Found : user_pref("extensions.Softonic.newtab", true); Found : user_pref("extensions.Softonic.newtaburl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource[...] Found : user_pref("extensions.Softonic.prdct", "Softonic"); Found : user_pref("extensions.Softonic.prtnrId", "softonic"); Found : user_pref("extensions.Softonic.prtnrid", "softonic"); Found : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...] Found : user_pref("extensions.Softonic.sg", "cz"); Found : user_pref("extensions.Softonic.smplGrp", "none"); Found : user_pref("extensions.Softonic.smplgrp", "none"); Found : user_pref("extensions.Softonic.srch", ""); Found : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Found : user_pref("extensions.Softonic.srchprvdr", "Search the web (Softonic)"); Found : user_pref("extensions.Softonic.tlbrId", "base"); Found : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSour[...] Found : user_pref("extensions.Softonic.tlbrid", "base"); Found : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSour[...] Found : user_pref("extensions.Softonic.vrsn", "1.6.7.4"); Found : user_pref("extensions.Softonic.vrsnTs", "1.6.7.412:59:45"); Found : user_pref("extensions.Softonic.vrsni", "1.6.7.4"); Found : user_pref("extensions.Softonic.vrsnts", "1.6.7.412:59:45"); Found : user_pref("extensions.Softonic_i.dnsErr", true); Found : user_pref("extensions.Softonic_i.hmpg", true); Found : user_pref("extensions.Softonic_i.newTab", true); Found : user_pref("extensions.Softonic_i.smplGrp", "none"); Found : user_pref("extensions.Softonic_i.vrsnTs", "1.6.7.412:59:45"); Found : user_pref("extensions.asktb.ff-original-keyword-url", ""); Found : user_pref("extensions.enabledAddons", "ffxtlbr@incredibar.com:1.5.0,ffxtlbra@softonic.com:1.6.0,bett[...] Found : user_pref("extensions.incredibar.actvtyRptTime", "1345671063867"); Found : user_pref("extensions.incredibar.aflt", "orgnl"); Found : user_pref("extensions.incredibar.afterInstallRpt", "sent"); Found : user_pref("extensions.incredibar.cntry", "DE"); Found : user_pref("extensions.incredibar.dfltLng", "EN"); Found : user_pref("extensions.incredibar.dfltlng", "EN"); Found : user_pref("extensions.incredibar.dfltsrch", "false"); Found : user_pref("extensions.incredibar.did", "10665"); Found : user_pref("extensions.incredibar.envrmnt", "production"); Found : user_pref("extensions.incredibar.hdrMd5", ""); Found : user_pref("extensions.incredibar.hmpg", false); Found : user_pref("extensions.incredibar.hrdid", "0"); Found : user_pref("extensions.incredibar.id", ""); Found : user_pref("extensions.incredibar.installerproductid", "26"); Found : user_pref("extensions.incredibar.instlday", ""); Found : user_pref("extensions.incredibar.instlref", ""); Found : user_pref("extensions.incredibar.isDcmntCmplt", false); Found : user_pref("extensions.incredibar.isdcmntcmplt", "false"); Found : user_pref("extensions.incredibar.keywordurl", ""); Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1413:04:29"); Found : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Found : user_pref("extensions.incredibar.newTab", false); Found : user_pref("extensions.incredibar.newtab", "false"); Found : user_pref("extensions.incredibar.newtaburl", ""); Found : user_pref("extensions.incredibar.ppd", ""); Found : user_pref("extensions.incredibar.prdct", "incredibar"); Found : user_pref("extensions.incredibar.productid", "26"); Found : user_pref("extensions.incredibar.prtnrid", ""); Found : user_pref("extensions.incredibar.sg", "none"); Found : user_pref("extensions.incredibar.smplGrp", "none"); Found : user_pref("extensions.incredibar.smplgrp", "none"); Found : user_pref("extensions.incredibar.srch", ""); Found : user_pref("extensions.incredibar.srchprvdr", ""); Found : user_pref("extensions.incredibar.tlbrid", "base"); Found : user_pref("extensions.incredibar.tlbrsrchurl", ""); Found : user_pref("extensions.incredibar.upn2", "6OyKoS8qxA"); Found : user_pref("extensions.incredibar.upn2n", "92261895051392810"); Found : user_pref("extensions.incredibar.vrsn", ""); Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1413:04:29"); Found : user_pref("extensions.incredibar.vrsnts", "1.5.11.1413:04:29"); Found : user_pref("extensions.incredibar_i.aflt", "orgnl"); Found : user_pref("extensions.incredibar_i.dfltLng", ""); Found : user_pref("extensions.incredibar_i.did", "10665"); Found : user_pref("extensions.incredibar_i.excTlbr", false); Found : user_pref("extensions.incredibar_i.id", "84d8779c000000000000002306d95d81"); Found : user_pref("extensions.incredibar_i.installerproductid", "26"); Found : user_pref("extensions.incredibar_i.instlDay", "15560"); Found : user_pref("extensions.incredibar_i.instlRef", ""); Found : user_pref("extensions.incredibar_i.ms_url_id", ""); Found : user_pref("extensions.incredibar_i.newTab", false); Found : user_pref("extensions.incredibar_i.ppd", ""); Found : user_pref("extensions.incredibar_i.prdct", "incredibar"); Found : user_pref("extensions.incredibar_i.productid", "26"); Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Found : user_pref("extensions.incredibar_i.smplGrp", "none"); Found : user_pref("extensions.incredibar_i.tlbrId", "base"); Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyKoS8qxA&loc=IB[...] Found : user_pref("extensions.incredibar_i.upn2", "6OyKoS8qxA"); Found : user_pref("extensions.incredibar_i.upn2n", "92261895051392810"); Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1413:04:29"); Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Found : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://search.softonic.[...] Found : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://search.softo[...] Found : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] -\\ Google Chrome v21.0.1180.83 File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Found : "urls_to_restore_on_startup": [ "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&i=26" ] Found : "urls_to_restore_on_startup": [ "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&i=26" ] ************************* AdwCleaner[R1].txt - [20755 octets] - [27/08/2012 18:36:17] ########## EOF - C:\AdwCleaner[R1].txt - [20884 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Das gibt es nicht!!! Ich habe noch 3 Trojaner :crazy: Soll ich die in die Quaranäne verschieben? Na ja ohne Deine/Eure Hilfe will ich nicht mal denken wie ich mich befreien könnte. Mittlerweile funktioniert die Mozzila Firefox schon normal und ich sehe keine blaue Fensterchen. Mit noch Milliarden Mal DANKE sende ich die nächste Berichte tantan 1. Schritt # AdwCleaner v1.801 - Logfile created 08/28/2012 at 16:57:06 # Updated 14/08/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Administrator - YOUR-8E8F8D6E2D # Boot Mode : Normal # Running from : C:\Documents and Settings\Administrator\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Administrator\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Softonic Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\extensions\ffxtlbr@incredibar.com Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\extensions\ffxtlbra@softonic.com Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\Program Files\Softonic Folder Deleted : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\searchplugins\MyStart Search.xml File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\searchplugins\softonic.xml File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job ***** [Registry] ***** Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\Web Assistant Key Deleted : HKLM\SOFTWARE\APN Key Deleted : HKLM\SOFTWARE\AskToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\I Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\S Key Deleted : HKLM\SOFTWARE\Classes\Softonic.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\Softonic.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr Key Deleted : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\SoftonicApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\SoftonicApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc Key Deleted : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc.1 Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar Key Deleted : HKLM\SOFTWARE\Web Assistant ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc= --> hxxp://www.google.com -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\prefs.js C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\la8iggyg.default\user.js ... Deleted ! Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&loc=FF_NT"); Deleted : user_pref("extensions.Softonic.admin", false); Deleted : user_pref("extensions.Softonic.aflt", "SD"); Deleted : user_pref("extensions.Softonic.autoRvrt", "false"); Deleted : user_pref("extensions.Softonic.cntry", "DE"); Deleted : user_pref("extensions.Softonic.cv", "cv5"); Deleted : user_pref("extensions.Softonic.dfltLng", "de"); Deleted : user_pref("extensions.Softonic.dfltSrch", true); Deleted : user_pref("extensions.Softonic.dfltlng", "de"); Deleted : user_pref("extensions.Softonic.dfltsrch", true); Deleted : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); Deleted : user_pref("extensions.Softonic.dspOld", "Ask.com"); Deleted : user_pref("extensions.Softonic.envrmnt", "production"); Deleted : user_pref("extensions.Softonic.excTlbr", false); Deleted : user_pref("extensions.Softonic.hdrMd5", "3C0F1FCFF3186AFEFBE33E2BB484A809"); Deleted : user_pref("extensions.Softonic.hmpg", true); Deleted : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=1[...] Deleted : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=13&[...] Deleted : user_pref("extensions.Softonic.hpOld", "hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&local[...] Deleted : user_pref("extensions.Softonic.hrdid", "84d8779c000000000000002306d95d81"); Deleted : user_pref("extensions.Softonic.id", "84d8779c000000000000002306d95d81"); Deleted : user_pref("extensions.Softonic.instlDay", "15560"); Deleted : user_pref("extensions.Softonic.instlRef", "INF1205T01"); Deleted : user_pref("extensions.Softonic.instlday", "15560"); Deleted : user_pref("extensions.Softonic.instlref", "INF1205T01"); Deleted : user_pref("extensions.Softonic.isdcmntcmplt", "false"); Deleted : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSourc[...] Deleted : user_pref("extensions.Softonic.keywordurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSourc[...] Deleted : user_pref("extensions.Softonic.lastVrsnTs", "1.6.7.412:59:45"); Deleted : user_pref("extensions.Softonic.mntrvrsn", "1.3.0"); Deleted : user_pref("extensions.Softonic.newTab", true); Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource[...] Deleted : user_pref("extensions.Softonic.newtab", true); Deleted : user_pref("extensions.Softonic.newtaburl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource[...] Deleted : user_pref("extensions.Softonic.prdct", "Softonic"); Deleted : user_pref("extensions.Softonic.prtnrId", "softonic"); Deleted : user_pref("extensions.Softonic.prtnrid", "softonic"); Deleted : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...] Deleted : user_pref("extensions.Softonic.sg", "az"); Deleted : user_pref("extensions.Softonic.smplGrp", "none"); Deleted : user_pref("extensions.Softonic.smplgrp", "none"); Deleted : user_pref("extensions.Softonic.srch", ""); Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Deleted : user_pref("extensions.Softonic.srchprvdr", "Search the web (Softonic)"); Deleted : user_pref("extensions.Softonic.tlbrId", "base"); Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSour[...] Deleted : user_pref("extensions.Softonic.tlbrid", "base"); Deleted : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSour[...] Deleted : user_pref("extensions.Softonic.vrsn", "1.6.7.4"); Deleted : user_pref("extensions.Softonic.vrsnTs", "1.6.7.412:59:45"); Deleted : user_pref("extensions.Softonic.vrsni", "1.6.7.4"); Deleted : user_pref("extensions.Softonic.vrsnts", "1.6.7.412:59:45"); Deleted : user_pref("extensions.Softonic_i.dnsErr", true); Deleted : user_pref("extensions.Softonic_i.hmpg", true); Deleted : user_pref("extensions.Softonic_i.newTab", true); Deleted : user_pref("extensions.Softonic_i.smplGrp", "none"); Deleted : user_pref("extensions.Softonic_i.vrsnTs", "1.6.7.412:59:45"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("extensions.enabledAddons", "ffxtlbr@incredibar.com:1.5.0,ffxtlbra@softonic.com:1.6.0,bett[...] Deleted : user_pref("extensions.incredibar.actvtyRptTime", "1346085424638"); Deleted : user_pref("extensions.incredibar.aflt", "orgnl"); Deleted : user_pref("extensions.incredibar.afterInstallRpt", "sent"); Deleted : user_pref("extensions.incredibar.cntry", "DE"); Deleted : user_pref("extensions.incredibar.dfltLng", "EN"); Deleted : user_pref("extensions.incredibar.dfltlng", "EN"); Deleted : user_pref("extensions.incredibar.dfltsrch", "false"); Deleted : user_pref("extensions.incredibar.did", "10665"); Deleted : user_pref("extensions.incredibar.envrmnt", "production"); Deleted : user_pref("extensions.incredibar.hdrMd5", ""); Deleted : user_pref("extensions.incredibar.hmpg", false); Deleted : user_pref("extensions.incredibar.hrdid", "0"); Deleted : user_pref("extensions.incredibar.id", ""); Deleted : user_pref("extensions.incredibar.installerproductid", "26"); Deleted : user_pref("extensions.incredibar.instlday", ""); Deleted : user_pref("extensions.incredibar.instlref", ""); Deleted : user_pref("extensions.incredibar.isDcmntCmplt", false); Deleted : user_pref("extensions.incredibar.isdcmntcmplt", "false"); Deleted : user_pref("extensions.incredibar.keywordurl", ""); Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1413:04:29"); Deleted : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Deleted : user_pref("extensions.incredibar.newTab", false); Deleted : user_pref("extensions.incredibar.newtab", "false"); Deleted : user_pref("extensions.incredibar.newtaburl", ""); Deleted : user_pref("extensions.incredibar.ppd", ""); Deleted : user_pref("extensions.incredibar.prdct", "incredibar"); Deleted : user_pref("extensions.incredibar.productid", "26"); Deleted : user_pref("extensions.incredibar.prtnrid", ""); Deleted : user_pref("extensions.incredibar.sg", "none"); Deleted : user_pref("extensions.incredibar.smplGrp", "none"); Deleted : user_pref("extensions.incredibar.smplgrp", "none"); Deleted : user_pref("extensions.incredibar.srch", ""); Deleted : user_pref("extensions.incredibar.srchprvdr", ""); Deleted : user_pref("extensions.incredibar.tlbrid", "base"); Deleted : user_pref("extensions.incredibar.tlbrsrchurl", ""); Deleted : user_pref("extensions.incredibar.upn2", "6OyKoS8qxA"); Deleted : user_pref("extensions.incredibar.upn2n", "92261895051392810"); Deleted : user_pref("extensions.incredibar.vrsn", ""); Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1413:04:29"); Deleted : user_pref("extensions.incredibar.vrsnts", "1.5.11.1413:04:29"); Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl"); Deleted : user_pref("extensions.incredibar_i.dfltLng", ""); Deleted : user_pref("extensions.incredibar_i.did", "10665"); Deleted : user_pref("extensions.incredibar_i.excTlbr", false); Deleted : user_pref("extensions.incredibar_i.id", "84d8779c000000000000002306d95d81"); Deleted : user_pref("extensions.incredibar_i.installerproductid", "26"); Deleted : user_pref("extensions.incredibar_i.instlDay", "15560"); Deleted : user_pref("extensions.incredibar_i.instlRef", ""); Deleted : user_pref("extensions.incredibar_i.ms_url_id", ""); Deleted : user_pref("extensions.incredibar_i.newTab", false); Deleted : user_pref("extensions.incredibar_i.ppd", ""); Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar"); Deleted : user_pref("extensions.incredibar_i.productid", "26"); Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Deleted : user_pref("extensions.incredibar_i.smplGrp", "none"); Deleted : user_pref("extensions.incredibar_i.tlbrId", "base"); Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyKoS8qxA&loc=IB[...] Deleted : user_pref("extensions.incredibar_i.upn2", "6OyKoS8qxA"); Deleted : user_pref("extensions.incredibar_i.upn2n", "92261895051392810"); Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1413:04:29"); Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://search.softonic.[...] Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://search.softo[...] Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted : "urls_to_restore_on_startup": [ "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&i=26" ] Deleted : "urls_to_restore_on_startup": [ "hxxp://mystart.incredibar.com/mb165?a=6OyKoS8qxA&i=26" ] ************************* AdwCleaner[R1].txt - [20886 octets] - [27/08/2012 18:36:17] AdwCleaner[S1].txt - [21308 octets] - [28/08/2012 16:57:06] ########## EOF - C:\AdwCleaner[S1].txt - [21437 octets] ########## 2. Schritt Emsisoft Anti-Malware - Version 6.6 Letztes Update: 28.08.2012 17:40:23 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 28.08.2012 18:06:08 C:\§SNIMKI\mama\Christmas.exe gefunden: Trojan.Win32.XmasAds.AMN!E1 C:\§SNIMKI\LidMi\Christmas.exe gefunden: Trojan.Win32.XmasAds.AMN!E1 C:\Documents and Settings\Administrator\Desktop\snimki\mama\Christmas.exe gefunden: Trojan.Win32.XmasAds.AMN!E1 Gescannt 635336 Gefunden 3 Scan Ende: 28.08.2012 20:00:17 Scan Zeit: 1:54:09 |
Sehr gut! :daumenhoc Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
:taenzer: :taenzer: :taenzer: D A N K E!!! Super Helfer :-) --------------- ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=4c7bfa88d9b50945b0c7f116a6107d44 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-29 03:01:33 # local_time=2012-08-29 05:01:33 (+0100, W. Europe Daylight Time) # country="Germany" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777191 100 0 6385494 6385494 0 0 # compatibility_mode=8192 67108863 100 0 186 186 0 0 # scanned=320369 # found=8 # cleaned=8 # scan_time=7497 C:\_OTL\MovedFiles\08262012_073518\C_Program Files\SoftonicDownloader_for_winx-dvd-player.exe a variant of Win32/SoftonicDownloader.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08262012_073518\C_Program Files\SoftonicDownloader_fuer_avs-media-player.exe a variant of Win32/SoftonicDownloader.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\snimki\mama\Christmas.exe a variant of Win32/XmasAds.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\snimki\snimki\mama\Christmas.exe a variant of Win32/XmasAds.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\snimki\snimki\Lid\Christmas.exe a variant of Win32/XmasAds.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\E von compi\Externe Festplatte\Sept. 2010\Downloads\AVI.Codec.Pack.Pro.V2.2.0.Setup.exe Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\E von compi\Externe Festplatte\Sept. 2010\Downloads\HSS-1.51-install-anchorfree-76-conduit.exe a variant of Win32/HotSpotShield application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\E von compi\Externe Festplatte\Juli 2011\Laptop Dell Juli 2011 außer Fotos!!!\Downloads\AVI.Codec.Pack.Pro.V2.2.0.Setup.exe Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C |
Alle Zeitangaben in WEZ +1. Es ist jetzt 10:18 Uhr. |
Copyright ©2000-2025, Trojaner-Board