![]() |
BKA-Trojaner Funde: Spyware.Zbot.DG Trojan.Ransom.Gen Hallo, ich habe mir in meinem Gast-Account den BKA-Trojaner eingehandelt. Danach habe ich malwarebytes installiert und die Suche gab folgende Ergebnisse: C:\Users\Gast\AppData\Local\Temp\g7i0ol_kaz.exe (Spyware.Zbot.DG) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. Was muss ich jetzt noch tun? Vielen Dank im Voraus Martin |
:hallo: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. 2. Schritt Systemscan mit OTL (bebilderte Anleitung) |
Malwarebytes: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.07.28.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Martin :: BILLY [Administrator] Schutz: Aktiviert 28.07.2012 22:27:01 mbam-log-2012-07-28 (22-27-01).txt Art des Suchlaufs: Benutzerdefinierter Suchlauf (C:\Users\Martin\Downloads\OTL.exe|) Aktivierte Suchlaufeinstellungen: Dateisystem | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Heuristiks/Extra | P2P Durchsuchte Objekte: 1 Laufzeit: 4 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
anbei OTL.txt und extras.txt basierend auf den gewünschten Einstellungen, die ich beim ersten Mal nicht hatte...OTL Logfile: Code: OTL logfile created on: 29.07.2012 08:48:39 - Run 2 OTL Logfile: Code: OTL Extras logfile created on: 29.07.2012 08:48:39 - Run 2 |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Danke! All processes killed ========== OTL ========== Service vsmon stopped successfully! Service vsmon deleted successfully! File move failed. C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe scheduled to be moved on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found. HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. Registry key HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. HKU\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "" removed from browser.startup.homepage Prefs.js: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.60 removed from extensions.enabledItems Prefs.js: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.53.4 removed from extensions.enabledItems Prefs.js: firefox@tvunetworks.com:2 removed from extensions.enabledItems Prefs.js: 5 removed from extensions.enabledItems Prefs.js: 3 removed from extensions.enabledItems Prefs.js: 1 removed from extensions.enabledItems Prefs.js: 4 removed from network.proxy.type Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. C:\Users\Martin\AppData\Roaming\mozilla\Firefox\Profiles\7ghyk6wq.default\extensions\firefox@tvunetworks.com\plugins folder moved successfully. C:\Users\Martin\AppData\Roaming\mozilla\Firefox\Profiles\7ghyk6wq.default\extensions\firefox@tvunetworks.com folder moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. C:\Programme\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully. File C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully. File C:\Programme\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. 64bit-Registry value HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found. File C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll not found. Registry value HKEY_USERS\S-1-5-21-1176804968-31653149-3725565380-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found. File C:\Programme\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISW deleted successfully. Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZoneAlarm scheduled to be deleted on reboot. File move failed. C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\An OneNote s&enden\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft &Excel exportieren\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xcel exportieren\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Senden an &Bluetooth\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\An OneNote s&enden\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft &Excel exportieren\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xcel exportieren\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Senden an &Bluetooth\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\Windows\SysNative\drivers\~GLH0020.TMP deleted successfully. C:\ProgramData\zak_lo0i7g.pad moved successfully. ADS C:\ProgramData\Temp:0B9176C0 deleted successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Martin\Desktop\cmd.bat deleted successfully. C:\Users\Martin\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gast ->Temp folder emptied: 13461163 bytes ->Temporary Internet Files folder emptied: 34500325 bytes ->Java cache emptied: 54956 bytes ->FireFox cache emptied: 60363426 bytes ->Flash cache emptied: 20267 bytes User: Martin ->Temp folder emptied: 479947467 bytes ->Temporary Internet Files folder emptied: 11995115 bytes ->Java cache emptied: 2861484 bytes ->FireFox cache emptied: 1103417299 bytes ->Flash cache emptied: 114603 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 403416246 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 102293 bytes RecycleBin emptied: 31288637 bytes Total Files Cleaned = 2.042,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Gast ->Flash cache emptied: 0 bytes User: Martin ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.55.0 log created on 07302012_192840 Files\Folders moved on Reboot... File move failed. C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe scheduled to be moved on reboot. File move failed. C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe scheduled to be moved on reboot. C:\Users\Martin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Martin\AppData\Local\Temp\WILSAP-2011 - Sales not found! PendingFileRenameOperations files... [2012.06.21 15:58:50 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe : MD5=F8780B0311C09B7F4853B9A5710EF0E3 [2012.06.21 15:29:14 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe : MD5=1E6C3B13181A5E08553AE5D5C9BF889E File C:\Users\Martin\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\Martin\AppData\Local\Temp\WILSAP-2011 - Sales not found! Registry entries deleted on Reboot... Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZoneAlarm scheduled to be deleted on reboot. |
Sehr gut! :daumenhoc 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.07.30.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Martin :: BILLY [Administrator] Schutz: Aktiviert 30.07.2012 20:10:55 mbam-log-2012-07-30 (20-10-55).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 373229 Laufzeit: 1 Stunde(n), 32 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) Adwcleaner # AdwCleaner v1.703 - Logfile created 07/30/2012 at 22:10:48 # Updated 20/07/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Martin - BILLY # Running from : C:\Users\Martin\Installationsprogramme\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Martin\AppData\Local\Conduit Folder Found : C:\Users\Martin\AppData\LocalLow\Conduit Folder Found : C:\Users\Martin\AppData\Roaming\OpenCandy Folder Found : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7ghyk6wq.default\ConduitCommon Folder Found : C:\Program Files (x86)\Conduit ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm-Sicherheit Toolbar [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Found : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v13.0.1 (de) Profile name : default File : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7ghyk6wq.default\prefs.js Found : user_pref("CT2613550..clientLogIsEnabled", false); Found : user_pref("CT2613550..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2613550..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2613550.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2613550.AppTrackingLastCheckTime", "Tue Jun 05 2012 22:37:00 GMT+0200"); Found : user_pref("CT2613550.CTID", "CT2613550"); Found : user_pref("CT2613550.CurrentServerDate", "24-6-2012"); Found : user_pref("CT2613550.DSInstall", false); Found : user_pref("CT2613550.DialogsAlignMode", "LTR"); Found : user_pref("CT2613550.DialogsGetterLastCheckTime", "Sun Jun 24 2012 18:34:44 GMT+0200"); Found : user_pref("CT2613550.DownloadReferralCookieData", ""); Found : user_pref("CT2613550.EMailNotifierPollDate", "Mon Apr 23 2012 18:23:43 GMT+0200"); Found : user_pref("CT2613550.FirstServerDate", "22-11-2011"); Found : user_pref("CT2613550.FirstTime", true); Found : user_pref("CT2613550.FirstTimeFF3", true); Found : user_pref("CT2613550.FixPageNotFoundErrors", true); Found : user_pref("CT2613550.GroupingServerCheckInterval", 1440); Found : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2613550.HPInstall", false); Found : user_pref("CT2613550.HasUserGlobalKeys", true); Found : user_pref("CT2613550.HomePageProtectorEnabled", false); Found : user_pref("CT2613550.HomepageBeforeUnload", ""); Found : user_pref("CT2613550.Initialize", true); Found : user_pref("CT2613550.InitializeCommonPrefs", true); Found : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2613550.InstallationId", "CT2613550_ZoneAlarm-Sicherheit.exe"); Found : user_pref("CT2613550.InstallationType", "ConduitIntegration"); Found : user_pref("CT2613550.InstalledDate", "Tue Nov 22 2011 16:31:53 GMT+0100"); Found : user_pref("CT2613550.IsAlertDBUpdated", true); Found : user_pref("CT2613550.IsGrouping", false); Found : user_pref("CT2613550.IsInitSetupIni", true); Found : user_pref("CT2613550.IsMulticommunity", false); Found : user_pref("CT2613550.IsOpenThankYouPage", false); Found : user_pref("CT2613550.IsOpenUninstallPage", false); Found : user_pref("CT2613550.LanguagePackLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2613550.LastLogin_3.10.0.1", "Thu Apr 19 2012 15:13:38 GMT+0200"); Found : user_pref("CT2613550.LastLogin_3.12.0.7", "Thu Apr 26 2012 21:25:23 GMT+0200"); Found : user_pref("CT2613550.LastLogin_3.12.2.3", "Sat Jun 02 2012 12:03:48 GMT+0200"); Found : user_pref("CT2613550.LastLogin_3.13.0.6", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.LastLogin_3.8.0.8", "Mon Dec 05 2011 19:31:20 GMT+0100"); Found : user_pref("CT2613550.LastLogin_3.8.1.0", "Sun Jan 15 2012 18:58:50 GMT+0100"); Found : user_pref("CT2613550.LastLogin_3.9.0.3", "Thu Mar 08 2012 19:18:42 GMT+0100"); Found : user_pref("CT2613550.LatestVersion", "3.13.0.6"); Found : user_pref("CT2613550.Locale", "de-de"); Found : user_pref("CT2613550.MCDetectTooltipHeight", "83"); Found : user_pref("CT2613550.MCDetectTooltipShow", false); Found : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2613550.MCDetectTooltipWidth", "295"); Found : user_pref("CT2613550.MyStuffEnabledAtInstallation", false); Found : user_pref("CT2613550.OriginalFirstVersion", "3.8.0.8"); Found : user_pref("CT2613550.SearchCaption", "ZoneAlarm-Sicherheit Customized Web Search"); Found : user_pref("CT2613550.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); Found : user_pref("CT2613550.SearchFromAddressBarIsInit", true); Found : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Found : user_pref("CT2613550.SearchInNewTabEnabled", true); Found : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2613550.SearchInNewTabLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Found : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Found : user_pref("CT2613550.SearchProtectorEnabled", false); Found : user_pref("CT2613550.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2613550.SendProtectorDataViaLogin", true); Found : user_pref("CT2613550.ServiceMapLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.SettingsLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Found : user_pref("CT2613550.SettingsLastUpdate", "1337169810"); Found : user_pref("CT2613550.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2613550&SearchSource=13"); Found : user_pref("CT2613550.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Sun Jun 24 2012 18:34:39 GMT+0200"); Found : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1331806000"); Found : user_pref("CT2613550.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2613550.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2613550"); Found : user_pref("CT2613550.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2613550.UserID", "UN27419138681094946"); Found : user_pref("CT2613550.ValidationData_Search", 0); Found : user_pref("CT2613550.ValidationData_Toolbar", 2); Found : user_pref("CT2613550.alertChannelId", "1006347"); Found : user_pref("CT2613550.approveUntrustedApps", true); Found : user_pref("CT2613550.backendstorage.facebook_mode", "32"); Found : user_pref("CT2613550.backendstorage.facebook_user_locale", "6465"); Found : user_pref("CT2613550.components.1000034", false); Found : user_pref("CT2613550.components.129791240633491387", false); Found : user_pref("CT2613550.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2613550.globalFirstTimeInfoLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.homepageProtectorEnableByLogin", true); Found : user_pref("CT2613550.initDone", true); Found : user_pref("CT2613550.isAppTrackingManagerOn", true); Found : user_pref("CT2613550.myStuffEnabled", true); Found : user_pref("CT2613550.myStuffPublihserMinWidth", 400); Found : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2613550.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2613550.oldAppsList", "129171076488700693,129171076488856944,111,129171076488856945,129[...] Found : user_pref("CT2613550.revertSettingsEnabled", true); Found : user_pref("CT2613550.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2613550.searchProtectorEnableByLogin", true); Found : user_pref("CT2613550.testingCtid", ""); Found : user_pref("CT2613550.toolbarAppMetaDataLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.toolbarContextMenuLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Found : user_pref("CT2613550.usagesFlag", 2); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2613550/CT2613550[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1006347/1002062/DE", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2613550", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2613550",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2613550&octid=[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/50/261/CT2613550/Images/6340849712463612[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Martin\\AppData\\Roaming\\Mozilla\\[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); Found : user_pref("CommunityToolbar.ToolbarsList", "CT2613550"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2613550"); Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Apr 19 2012 15:13:35 GMT+0200"); Found : user_pref("CommunityToolbar.globalUserId", "9e68f5ad-e60f-440d-b04e-3fda3552fc88"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jun 24 2012 18:34:4[...] Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Jun 24 2012 18:34:47 GMT+020[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "3e8bed8d-f398-4bb9-8c28-b188c03d2d63"); Found : user_pref("CommunityToolbar.originalHomepage", ""); Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...] Profile name : default File : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\43yhi5nc.default\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [14327 octets] - [30/07/2012 22:10:48] ########## EOF - C:\AdwCleaner[R1].txt - [14456 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
# AdwCleaner v1.703 - Logfile created 08/04/2012 at 10:49:37 # Updated 20/07/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Martin - BILLY # Running from : C:\Users\Martin\Installationsprogramme\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Martin\AppData\Local\Conduit Folder Deleted : C:\Users\Martin\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Martin\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7ghyk6wq.default\ConduitCommon Folder Deleted : C:\Program Files (x86)\Conduit ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm-Sicherheit Toolbar ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v13.0.1 (de) Profile name : default File : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7ghyk6wq.default\prefs.js Deleted : user_pref("CT2613550..clientLogIsEnabled", false); Deleted : user_pref("CT2613550..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2613550..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2613550.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2613550.AppTrackingLastCheckTime", "Tue Jun 05 2012 22:37:00 GMT+0200"); Deleted : user_pref("CT2613550.CTID", "CT2613550"); Deleted : user_pref("CT2613550.CurrentServerDate", "24-6-2012"); Deleted : user_pref("CT2613550.DSInstall", false); Deleted : user_pref("CT2613550.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2613550.DialogsGetterLastCheckTime", "Sun Jun 24 2012 18:34:44 GMT+0200"); Deleted : user_pref("CT2613550.DownloadReferralCookieData", ""); Deleted : user_pref("CT2613550.EMailNotifierPollDate", "Mon Apr 23 2012 18:23:43 GMT+0200"); Deleted : user_pref("CT2613550.FirstServerDate", "22-11-2011"); Deleted : user_pref("CT2613550.FirstTime", true); Deleted : user_pref("CT2613550.FirstTimeFF3", true); Deleted : user_pref("CT2613550.FixPageNotFoundErrors", true); Deleted : user_pref("CT2613550.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2613550.HPInstall", false); Deleted : user_pref("CT2613550.HasUserGlobalKeys", true); Deleted : user_pref("CT2613550.HomePageProtectorEnabled", false); Deleted : user_pref("CT2613550.HomepageBeforeUnload", ""); Deleted : user_pref("CT2613550.Initialize", true); Deleted : user_pref("CT2613550.InitializeCommonPrefs", true); Deleted : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2613550.InstallationId", "CT2613550_ZoneAlarm-Sicherheit.exe"); Deleted : user_pref("CT2613550.InstallationType", "ConduitIntegration"); Deleted : user_pref("CT2613550.InstalledDate", "Tue Nov 22 2011 16:31:53 GMT+0100"); Deleted : user_pref("CT2613550.IsAlertDBUpdated", true); Deleted : user_pref("CT2613550.IsGrouping", false); Deleted : user_pref("CT2613550.IsInitSetupIni", true); Deleted : user_pref("CT2613550.IsMulticommunity", false); Deleted : user_pref("CT2613550.IsOpenThankYouPage", false); Deleted : user_pref("CT2613550.IsOpenUninstallPage", false); Deleted : user_pref("CT2613550.LanguagePackLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2613550.LastLogin_3.10.0.1", "Thu Apr 19 2012 15:13:38 GMT+0200"); Deleted : user_pref("CT2613550.LastLogin_3.12.0.7", "Thu Apr 26 2012 21:25:23 GMT+0200"); Deleted : user_pref("CT2613550.LastLogin_3.12.2.3", "Sat Jun 02 2012 12:03:48 GMT+0200"); Deleted : user_pref("CT2613550.LastLogin_3.13.0.6", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.LastLogin_3.8.0.8", "Mon Dec 05 2011 19:31:20 GMT+0100"); Deleted : user_pref("CT2613550.LastLogin_3.8.1.0", "Sun Jan 15 2012 18:58:50 GMT+0100"); Deleted : user_pref("CT2613550.LastLogin_3.9.0.3", "Thu Mar 08 2012 19:18:42 GMT+0100"); Deleted : user_pref("CT2613550.LatestVersion", "3.13.0.6"); Deleted : user_pref("CT2613550.Locale", "de-de"); Deleted : user_pref("CT2613550.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2613550.MCDetectTooltipShow", false); Deleted : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2613550.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2613550.MyStuffEnabledAtInstallation", false); Deleted : user_pref("CT2613550.OriginalFirstVersion", "3.8.0.8"); Deleted : user_pref("CT2613550.SearchCaption", "ZoneAlarm-Sicherheit Customized Web Search"); Deleted : user_pref("CT2613550.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); Deleted : user_pref("CT2613550.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Deleted : user_pref("CT2613550.SearchInNewTabEnabled", true); Deleted : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2613550.SearchInNewTabLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Deleted : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Deleted : user_pref("CT2613550.SearchProtectorEnabled", false); Deleted : user_pref("CT2613550.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT2613550.SendProtectorDataViaLogin", true); Deleted : user_pref("CT2613550.ServiceMapLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.SettingsLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Deleted : user_pref("CT2613550.SettingsLastUpdate", "1337169810"); Deleted : user_pref("CT2613550.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2613550&SearchSource=13"); Deleted : user_pref("CT2613550.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Sun Jun 24 2012 18:34:39 GMT+0200"); Deleted : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1331806000"); Deleted : user_pref("CT2613550.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT2613550.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2613550"); Deleted : user_pref("CT2613550.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Deleted : user_pref("CT2613550.UserID", "UN27419138681094946"); Deleted : user_pref("CT2613550.ValidationData_Search", 0); Deleted : user_pref("CT2613550.ValidationData_Toolbar", 2); Deleted : user_pref("CT2613550.alertChannelId", "1006347"); Deleted : user_pref("CT2613550.approveUntrustedApps", true); Deleted : user_pref("CT2613550.backendstorage.facebook_mode", "32"); Deleted : user_pref("CT2613550.backendstorage.facebook_user_locale", "6465"); Deleted : user_pref("CT2613550.components.1000034", false); Deleted : user_pref("CT2613550.components.129791240633491387", false); Deleted : user_pref("CT2613550.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Deleted : user_pref("CT2613550.globalFirstTimeInfoLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT2613550.initDone", true); Deleted : user_pref("CT2613550.isAppTrackingManagerOn", true); Deleted : user_pref("CT2613550.myStuffEnabled", true); Deleted : user_pref("CT2613550.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2613550.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2613550.oldAppsList", "129171076488700693,129171076488856944,111,129171076488856945,129[...] Deleted : user_pref("CT2613550.revertSettingsEnabled", true); Deleted : user_pref("CT2613550.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT2613550.searchProtectorEnableByLogin", true); Deleted : user_pref("CT2613550.testingCtid", ""); Deleted : user_pref("CT2613550.toolbarAppMetaDataLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.toolbarContextMenuLastCheckTime", "Sun Jun 24 2012 18:34:42 GMT+0200"); Deleted : user_pref("CT2613550.usagesFlag", 2); Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2613550/CT2613550[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1006347/1002062/DE", "\"0\"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2613550", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2613550",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2613550&octid=[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/50/261/CT2613550/Images/6340849712463612[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Martin\\AppData\\Roaming\\Mozilla\\[...] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2613550"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550"); Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2613550"); Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Apr 19 2012 15:13:35 GMT+0200"); Deleted : user_pref("CommunityToolbar.globalUserId", "9e68f5ad-e60f-440d-b04e-3fda3552fc88"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jun 24 2012 18:34:4[...] Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Jun 24 2012 18:34:47 GMT+020[...] Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jun 24 2012 18:34:39 GMT+0200"); Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "3e8bed8d-f398-4bb9-8c28-b188c03d2d63"); Deleted : user_pref("CommunityToolbar.originalHomepage", ""); Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...] Profile name : default File : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\43yhi5nc.default\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [14452 octets] - [30/07/2012 22:10:48] AdwCleaner[S1].txt - [14524 octets] - [04/08/2012 10:49:37] ########## EOF - C:\AdwCleaner[S1].txt - [14653 octets] ########## Emsisoft Anti-Malware - Version 6.6 Letztes Update: 04.08.2012 11:06:01 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 04.08.2012 11:08:21 Gescannt 612535 Gefunden 0 Scan Ende: 04.08.2012 12:38:42 Scan Zeit: 1:30:21 |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
Hi, ich habe das Programm anscheinend blöderweise sofort wieder deinstalliert. Daher(?) finde ich auch kein Log. Es gab einen Fund einer Toolbar, aber sonst nix... |
OK Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
erledigt. Danke!!! Es gab unter Programme noch ein JAVA Fx2.11. Das ist etwas anderes, oder? Das habe ich nicht deinstalliert. Hast Du noch Tipps für eine andere Firewall oder anderen Virenscanner? |
Sehr gut! :daumenhoc Windows Firewall und Microsoft Security Essentials - Kostenloser Virenschutz für Windows damit bist Du sauber und entlassen! :) adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:29 Uhr. |
Copyright ©2000-2025, Trojaner-Board