![]() |
GVU-Trojaner mit Webcam, Bundespolizei-Trojaner Hallo, ich habe mir den GVU-Trojaner eingefangen. Über die dann aufgesuchte GVU-Seite (mit einem anderen Rechner), bin ich auf Euch gestoßen. Ich scheine das Grundproblem anhand Eurer Anleitung (Malwarebytes-Nutzung) gelöst zu haben (dafür schon mal vielen Dank!!) Zumindest sind die Symptome behoben und der Rechner verhält sich ruhig. Anbei mein Report von Malwarebytes Anti-Malware, wie in eurer Anleitung beschrieben: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.19.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 *** :: ***-PC [Administrator] Schutz: Aktiviert 19.08.2012 19:25:35 mbam-log-2012-08-19 (19-25-35).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 377055 Laufzeit: 3 Stunde(n), 47 Minute(n), 47 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\***\AppData\Local\Temp\install_0_msi.exe (Trojan.FakeMS) -> Löschen bei Neustart. C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Ich wäre sehr dankbar, wenn mir jemand sagen könnte, ob weitere Schritte notwendig sind?! Vielen Dank! |
:hallo: CustomScan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code: netsvcs
|
Hallo, vielen Dank!!! Hier der Text aus OTL.txt:OTL Logfile: Code: OTL logfile created on: 23.08.2012 16:08:45 - Run 1 --- Als Datei war es zu groß zum Anhängen. Ich hoffe das verheißt nichts Schlechtes?? Grüße! |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Hallo, danke noch mal! Habs durchgeführt: All processes killed ========== OTL ========== Service USBCCID stopped successfully! Service USBCCID deleted successfully! File system32\DRIVERS\RtsUCcid.sys not found. Service RtsUIR stopped successfully! Service RtsUIR deleted successfully! File system32\DRIVERS\Rts516xIR.sys not found. Service RSUSBSTOR stopped successfully! Service RSUSBSTOR deleted successfully! File System32\Drivers\RtsUStor.sys not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ deleted successfully. C:\Programme\ZoneAlarm-Sicherheit\tbZone.dll moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{27BAB4C9-FF78-428E-85AB-2DBA4C7ECF8D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27BAB4C9-FF78-428E-85AB-2DBA4C7ECF8D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found. File C:\Programme\ZoneAlarm-Sicherheit\tbZone.dll not found. HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{27BAB4C9-FF78-428E-85AB-2DBA4C7ECF8D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27BAB4C9-FF78-428E-85AB-2DBA4C7ECF8D}\ not found. Registry key HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{41E10320-1BA8-4561-BEBA-614DB5708588}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41E10320-1BA8-4561-BEBA-614DB5708588}\ not found. Registry key HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{74DF069E-A615-42FB-9629-F9B954D53338}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74DF069E-A615-42FB-9629-F9B954D53338}\ not found. HKU\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "Google" removed from browser.search.defaultenginename Prefs.js: "hxxp://www.gmx.net/" removed from browser.startup.homepage Prefs.js: "hxxp://www.google.com/search?sourceid=navclient&hl=de&q=" removed from keyword.URL Prefs.js: "*.local" removed from network.proxy.no_proxies_on Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully. C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}\ deleted successfully. C:\Programme\Windows Live\Companion\companioncore.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully. File C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found. File Sicherheit\tbZone.dll not found. Registry value HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}\ not found. Registry value HKEY_USERS\S-1-5-21-687101163-2738533743-2004884906-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found. File C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Programme\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISW deleted successfully. Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZoneAlarm scheduled to be deleted on reboot. File move failed. C:\Programme\CheckPoint\ZoneAlarm\zatray.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0000036B-C524-4050-81A0-243669A86B9F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000036B-C524-4050-81A0-243669A86B9F}\ not found. File C:\Programme\Windows Live\Companion\companioncore.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{76577871-04EC-495E-A12B-91F7C3600AFA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb4d342c-d1f4-11df-aead-001e33ddfdc2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cb4d342c-d1f4-11df-aead-001e33ddfdc2}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb4d342c-d1f4-11df-aead-001e33ddfdc2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cb4d342c-d1f4-11df-aead-001e33ddfdc2}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb4d342f-d1f4-11df-aead-001e33ddfdc2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cb4d342f-d1f4-11df-aead-001e33ddfdc2}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb4d342f-d1f4-11df-aead-001e33ddfdc2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cb4d342f-d1f4-11df-aead-001e33ddfdc2}\ not found. File F:\AutoRun.exe not found. C:\ProgramData\ism_0_llatsni.pad moved successfully. ========== FILES ========== < ipconfig /flushdns /c > No captured output from command... C:\Users\***\Desktop\cmd.bat deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: *** ->Temp folder emptied: 6448580834 bytes ->Temporary Internet Files folder emptied: 1852560192 bytes ->Java cache emptied: 2528454 bytes ->FireFox cache emptied: 345558081 bytes ->Flash cache emptied: 1152 bytes User: R13DD~1~KNN ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2469888 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 457826237 bytes RecycleBin emptied: 122347 bytes Total Files Cleaned = 8.688,00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08242012_084735 Files\Folders moved on Reboot... File move failed. C:\Programme\CheckPoint\ZoneAlarm\zatray.exe scheduled to be moved on reboot. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. C:\Users\***\AppData\Local\Temp\~DF70F2490348F88C3F.TMP moved successfully. C:\Windows\temp\ZLT031e6.TMP moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZoneAlarm scheduled to be deleted on reboot. -- Habe einen Neustart durchgeführt! Vielen Dank! Viele Grüße! |
Sehr gut! :daumenhoc Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Hallo, danke!!! Der Computer verhält sich ruhig, wenn er das soll. Nichts Auffälliges. Alles so wie immer. Hier die aktuellen Ergebnisse: (Die Laufzeit von Malwarebytes ist so lange, weil der Laptop über Nacht lief und nach einer Weile ausging, da ich vergaß das Netzkabel ran zu hängen. Morgens ging’s dann weiter.) Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.24.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 *** ::***-PC [Administrator] Schutz: Aktiviert 24.08.2012 23:44:20 mbam-log-2012-08-24 (23-44-20).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 368224 Laufzeit: 12 Stunde(n), 19 Minute(n), 32 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) --- Dann mit AdwCleaner: # AdwCleaner v1.801 - Logfile created 08/25/2012 at 12:40:20 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (32 bits) # User : *** - ***-PC # Boot Mode : Normal # Running from : C:\Users\***\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\***\AppData\LocalLow\boost_interprocess Folder Found : C:\Users\***\AppData\LocalLow\Conduit Folder Found : C:\ProgramData\Partner File Found : C:\Users\RA457~1.KNN\AppData\Local\Temp\Uninstall.exe File Found : C:\Program Files\Uninstall.exe ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\Softonic ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\o6s67300.default\prefs.js Found : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2613550.CTID", "ct2613550"); Found : user_pref("CT2613550.CurrentServerDate", "8-1-2011"); Found : user_pref("CT2613550.DialogsAlignMode", "LTR"); Found : user_pref("CT2613550.DownloadReferralCookieData", ""); Found : user_pref("CT2613550.EMailNotifierPollDate", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602533", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602539", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602545", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602551", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602557", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602563", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602569", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602575", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602581", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602587", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602593", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602599", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602605", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602611", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602617", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602623", "Sat Jan 08 2011 12:15:13 GMT+0100"); Found : user_pref("CT2613550.FeedPollDate129254982599602629", "Sat Jan 08 2011 12:15:13 GMT+0100"); Found : user_pref("CT2613550.FeedTTL129254982599602545", 5); Found : user_pref("CT2613550.FeedTTL129254982599602551", 5); Found : user_pref("CT2613550.FeedTTL129254982599602575", 2); Found : user_pref("CT2613550.FeedTTL129254982599602605", 5); Found : user_pref("CT2613550.FeedTTL129254982599602617", 30); Found : user_pref("CT2613550.FirstServerDate", "15-8-2010"); Found : user_pref("CT2613550.FirstTime", true); Found : user_pref("CT2613550.FirstTimeFF3", true); Found : user_pref("CT2613550.FirstTimeSettingsDone", true); Found : user_pref("CT2613550.FixPageNotFoundErrors", true); Found : user_pref("CT2613550.GroupingServerCheckInterval", 1440); Found : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2613550.Initialize", true); Found : user_pref("CT2613550.InitializeCommonPrefs", true); Found : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2613550.InstallationType", "UnknownIntegration"); Found : user_pref("CT2613550.InstalledDate", "Sun Aug 15 2010 22:39:47 GMT+0200"); Found : user_pref("CT2613550.IsGrouping", false); Found : user_pref("CT2613550.IsMulticommunity", false); Found : user_pref("CT2613550.IsOpenThankYouPage", false); Found : user_pref("CT2613550.IsOpenUninstallPage", true); Found : user_pref("CT2613550.LanguagePackLastCheckTime", "Sun Aug 15 2010 22:39:50 GMT+0200"); Found : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2613550.LastLogin_2.6.0.15", "Sun Sep 12 2010 16:17:23 GMT+0200"); Found : user_pref("CT2613550.LastLogin_2.7.1.3", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.LatestVersion", "2.7.1.3"); Found : user_pref("CT2613550.Locale", "de-de"); Found : user_pref("CT2613550.LoginCache", 4); Found : user_pref("CT2613550.MCDetectTooltipHeight", "83"); Found : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2613550.MCDetectTooltipWidth", "295"); Found : user_pref("CT2613550.RadioIsPodcast", false); Found : user_pref("CT2613550.RadioMediaID", "8546"); Found : user_pref("CT2613550.RadioMediaType", "Media Player"); Found : user_pref("CT2613550.RadioMenuSelectedID", "EBRadioMenu_CT26135508546"); Found : user_pref("CT2613550.RadioStationName", "Radio%208"); Found : user_pref("CT2613550.RadioStationURL", "hxxp://stream.radio8.de:8000/live.m3u"); Found : user_pref("CT2613550.SHRINK_TOOLBAR", 1); Found : user_pref("CT2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...] Found : user_pref("CT2613550.SearchFromAddressBarIsInit", true); Found : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Found : user_pref("CT2613550.SearchInNewTabEnabled", true); Found : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT2613550.SettingsCheckIntervalMin", 120); Found : user_pref("CT2613550.SettingsLastCheckTime", "Sun Aug 15 2010 22:39:47 GMT+0200"); Found : user_pref("CT2613550.SettingsLastUpdate", "1281567207"); Found : user_pref("CT2613550.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Sat Aug 07 2010 11:02:19 GMT+0200"); Found : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1255348257"); Found : user_pref("CT2613550.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...] Found : user_pref("CT2613550.UserID", "UN04912917337126887"); Found : user_pref("CT2613550.ValidationData_Search", 0); Found : user_pref("CT2613550.ValidationData_Toolbar", 2); Found : user_pref("CT2613550.WeatherNetwork", ""); Found : user_pref("CT2613550.WeatherPollDate", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.WeatherUnit", "C"); Found : user_pref("CT2613550.alertChannelId", "1006347"); Found : user_pref("CT2613550.clientLogIsEnabled", false); Found : user_pref("CT2613550.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...] Found : user_pref("CT2613550.components.1000082", true); Found : user_pref("CT2613550.components.1000234", true); Found : user_pref("CT2613550.ct2613550.DialogsAlignMode", "LTR"); Found : user_pref("CT2613550.ct2613550.FeedLastCount3082739963941193807", 850); Found : user_pref("CT2613550.ct2613550.FirstTimeSettingsDone", true); Found : user_pref("CT2613550.ct2613550.InvalidateCache", false); Found : user_pref("CT2613550.ct2613550.LanguagePackLastCheckTime", "Sat Jan 08 2011 12:15:12 GMT+0100"); Found : user_pref("CT2613550.ct2613550.Locale", "de-de"); Found : user_pref("CT2613550.ct2613550.RadioLastCheckTime", "Sat Jan 08 2011 12:15:11 GMT+0100"); Found : user_pref("CT2613550.ct2613550.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2613550.ct2613550.RadioLastUpdateServer", "0"); Found : user_pref("CT2613550.ct2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_[...] Found : user_pref("CT2613550.ct2613550.SearchInNewTabLastCheckTime", "Sat Jan 08 2011 12:15:10 GMT+0100"); Found : user_pref("CT2613550.ct2613550.SettingsCheckIntervalMin", 120); Found : user_pref("CT2613550.ct2613550.SettingsLastCheckTime", "Sat Jan 08 2011 12:15:10 GMT+0100"); Found : user_pref("CT2613550.ct2613550.SettingsLastUpdate", "1291812328"); Found : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastCheck", "Mon Dec 20 2010 15:33:15 GMT+0100"); Found : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastUpdate", "1255348257"); Found : user_pref("CT2613550.myStuffEnabled", true); Found : user_pref("CT2613550.myStuffPublihserMinWidth", 400); Found : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2613550.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2613550.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...] Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Found : user_pref("CommunityToolbar.ToolbarsList", "CT2613550"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550"); Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jan 08 2011 12:15:11 GMT+0100"); ************************* AdwCleaner[R1].txt - [10301 octets] - [25/08/2012 12:40:20] ########## EOF - C:\AdwCleaner[R1].txt - [10430 octets] ########## Ich habe nichts gelöscht! Vielen Dank noch mal! |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Hallo! Vielen Dank!! Hier der erste Teil: # AdwCleaner v1.801 - Logfile created 08/27/2012 at 11:16:42 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (32 bits) # User : *** - ***-PC # Boot Mode : Normal # Running from : C:\Users\***\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\***\AppData\LocalLow\boost_interprocess Folder Deleted : C:\Users\***\AppData\LocalLow\Conduit Folder Deleted : C:\ProgramData\Partner File Deleted : C:\Users\RA457~1.KNN\AppData\Local\Temp\Uninstall.exe File Deleted : C:\Program Files\Uninstall.exe ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\Softonic ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\o6s67300.default\prefs.js Deleted : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2613550.CTID", "ct2613550"); Deleted : user_pref("CT2613550.CurrentServerDate", "8-1-2011"); Deleted : user_pref("CT2613550.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2613550.DownloadReferralCookieData", ""); Deleted : user_pref("CT2613550.EMailNotifierPollDate", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602533", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602539", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602545", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602551", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602557", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602563", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602569", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602575", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602581", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602587", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602593", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602599", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602605", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602611", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602617", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602623", "Sat Jan 08 2011 12:15:13 GMT+0100"); Deleted : user_pref("CT2613550.FeedPollDate129254982599602629", "Sat Jan 08 2011 12:15:13 GMT+0100"); Deleted : user_pref("CT2613550.FeedTTL129254982599602545", 5); Deleted : user_pref("CT2613550.FeedTTL129254982599602551", 5); Deleted : user_pref("CT2613550.FeedTTL129254982599602575", 2); Deleted : user_pref("CT2613550.FeedTTL129254982599602605", 5); Deleted : user_pref("CT2613550.FeedTTL129254982599602617", 30); Deleted : user_pref("CT2613550.FirstServerDate", "15-8-2010"); Deleted : user_pref("CT2613550.FirstTime", true); Deleted : user_pref("CT2613550.FirstTimeFF3", true); Deleted : user_pref("CT2613550.FirstTimeSettingsDone", true); Deleted : user_pref("CT2613550.FixPageNotFoundErrors", true); Deleted : user_pref("CT2613550.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2613550.Initialize", true); Deleted : user_pref("CT2613550.InitializeCommonPrefs", true); Deleted : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2613550.InstallationType", "UnknownIntegration"); Deleted : user_pref("CT2613550.InstalledDate", "Sun Aug 15 2010 22:39:47 GMT+0200"); Deleted : user_pref("CT2613550.IsGrouping", false); Deleted : user_pref("CT2613550.IsMulticommunity", false); Deleted : user_pref("CT2613550.IsOpenThankYouPage", false); Deleted : user_pref("CT2613550.IsOpenUninstallPage", true); Deleted : user_pref("CT2613550.LanguagePackLastCheckTime", "Sun Aug 15 2010 22:39:50 GMT+0200"); Deleted : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2613550.LastLogin_2.6.0.15", "Sun Sep 12 2010 16:17:23 GMT+0200"); Deleted : user_pref("CT2613550.LastLogin_2.7.1.3", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.LatestVersion", "2.7.1.3"); Deleted : user_pref("CT2613550.Locale", "de-de"); Deleted : user_pref("CT2613550.LoginCache", 4); Deleted : user_pref("CT2613550.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2613550.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2613550.RadioIsPodcast", false); Deleted : user_pref("CT2613550.RadioMediaID", "8546"); Deleted : user_pref("CT2613550.RadioMediaType", "Media Player"); Deleted : user_pref("CT2613550.RadioMenuSelectedID", "EBRadioMenu_CT26135508546"); Deleted : user_pref("CT2613550.RadioStationName", "Radio%208"); Deleted : user_pref("CT2613550.RadioStationURL", "hxxp://stream.radio8.de:8000/live.m3u"); Deleted : user_pref("CT2613550.SHRINK_TOOLBAR", 1); Deleted : user_pref("CT2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...] Deleted : user_pref("CT2613550.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Deleted : user_pref("CT2613550.SearchInNewTabEnabled", true); Deleted : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Deleted : user_pref("CT2613550.SettingsCheckIntervalMin", 120); Deleted : user_pref("CT2613550.SettingsLastCheckTime", "Sun Aug 15 2010 22:39:47 GMT+0200"); Deleted : user_pref("CT2613550.SettingsLastUpdate", "1281567207"); Deleted : user_pref("CT2613550.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Sat Aug 07 2010 11:02:19 GMT+0200"); Deleted : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1255348257"); Deleted : user_pref("CT2613550.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...] Deleted : user_pref("CT2613550.UserID", "UN04912917337126887"); Deleted : user_pref("CT2613550.ValidationData_Search", 0); Deleted : user_pref("CT2613550.ValidationData_Toolbar", 2); Deleted : user_pref("CT2613550.WeatherNetwork", ""); Deleted : user_pref("CT2613550.WeatherPollDate", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.WeatherUnit", "C"); Deleted : user_pref("CT2613550.alertChannelId", "1006347"); Deleted : user_pref("CT2613550.clientLogIsEnabled", false); Deleted : user_pref("CT2613550.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...] Deleted : user_pref("CT2613550.components.1000082", true); Deleted : user_pref("CT2613550.components.1000234", true); Deleted : user_pref("CT2613550.ct2613550.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2613550.ct2613550.FeedLastCount3082739963941193807", 850); Deleted : user_pref("CT2613550.ct2613550.FirstTimeSettingsDone", true); Deleted : user_pref("CT2613550.ct2613550.InvalidateCache", false); Deleted : user_pref("CT2613550.ct2613550.LanguagePackLastCheckTime", "Sat Jan 08 2011 12:15:12 GMT+0100"); Deleted : user_pref("CT2613550.ct2613550.Locale", "de-de"); Deleted : user_pref("CT2613550.ct2613550.RadioLastCheckTime", "Sat Jan 08 2011 12:15:11 GMT+0100"); Deleted : user_pref("CT2613550.ct2613550.RadioLastUpdateIPServer", "3"); Deleted : user_pref("CT2613550.ct2613550.RadioLastUpdateServer", "0"); Deleted : user_pref("CT2613550.ct2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_[...] Deleted : user_pref("CT2613550.ct2613550.SearchInNewTabLastCheckTime", "Sat Jan 08 2011 12:15:10 GMT+0100"); Deleted : user_pref("CT2613550.ct2613550.SettingsCheckIntervalMin", 120); Deleted : user_pref("CT2613550.ct2613550.SettingsLastCheckTime", "Sat Jan 08 2011 12:15:10 GMT+0100"); Deleted : user_pref("CT2613550.ct2613550.SettingsLastUpdate", "1291812328"); Deleted : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastCheck", "Mon Dec 20 2010 15:33:15 GMT+0100"); Deleted : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastUpdate", "1255348257"); Deleted : user_pref("CT2613550.myStuffEnabled", true); Deleted : user_pref("CT2613550.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2613550.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2613550.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...] Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2613550"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550"); Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jan 08 2011 12:15:11 GMT+0100"); ************************* AdwCleaner[R1].txt - [10432 octets] - [25/08/2012 12:40:20] AdwCleaner[S1].txt - [10608 octets] - [27/08/2012 11:16:42] ########## EOF - C:\AdwCleaner[S1].txt - [10737 octets] ########## Hallo, und hier der zweite Schritt mit Emsisoft Anti-Malware: Hat leider noch was gefunden. Habs in Quarantäne verschoben! (War nur ein Objekt, obwohl 4 gefunden wurden.) Emsisoft Anti-Malware - Version 6.6 Letztes Update: 27.08.2012 11:43:46 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, E:\ Archiv Scan: An ADS Scan: An Scan Beginn: 27.08.2012 11:44:05 C:\Windows\SoftwareDistribution\Download\1650a534e5a53449be6d6a726b1c50af3a3b2703 -> hpzsetup.exe gefunden: Virus.Win32.Malware!E2 C:\Windows\SoftwareDistribution\Download\1650a534e5a53449be6d6a726b1c50af3a3b2703 -> HPZstub.exe gefunden: Virus.Win32.Malware!E2 C:\Windows\SoftwareDistribution\Download\1650a534e5a53449be6d6a726b1c50af3a3b2703 -> setup\HPZmsi01.exe gefunden: Virus.Win32.Malware!E2 C:\Windows\SoftwareDistribution\Download\1650a534e5a53449be6d6a726b1c50af3a3b2703 -> setup\HPZprl01.exe gefunden: Virus.Win32.Malware!E2 Gescannt 615821 Gefunden 4 Scan Ende: 27.08.2012 14:28:00 Scan Zeit: 2:43:55 C:\Windows\SoftwareDistribution\Download\1650a534e5a53449be6d6a726b1c50af3a3b2703 -> hpzsetup.exe Quarantäne Virus.Win32.Malware!E2 Quarantäne 1 -- Vielen Dank noch mal! |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
Hallo! Ich denke dies sieht ganz gut aus: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=2adba55864445f47a71981c79025882b # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-28 12:17:54 # local_time=2012-08-28 02:17:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 27376454 27376454 0 0 # compatibility_mode=5893 16776573 100 94 245 97776278 0 0 # compatibility_mode=8192 67108863 100 0 218 218 0 0 # compatibility_mode=9217 16776893 100 13 346673 2156613 0 0 # scanned=180115 # found=0 # cleaned=0 # scan_time=11187 -- Nach dem Wiedereinschalten von Firewall und Virenschutzprogramm ist der Rechner in die Knie gegangen. Keine Ahnung warun, hatte aber parallel noch Musik mit iTunes laufen und wollte die Log-Datei auslesen. Vielleicht zu viel auf einmal?? Jetzt läufts aber gut und ruhig. Der Taskmanager sagt, dass CSRSS.exe, WINLOGON.exe und ATIECLEXX.exe sehr aktiv sind. Ist das ein Problem? Vielen Dank noch mal! Grüße! |
Malware mit Combofix beseitigen Lade Combofix von einem der folgenden Download-Spiegel herunter: BleepingComputer.com - ForoSpyware.com und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig! Beachte die ausführliche Original-Anleitung. Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
Vorbereitung und wichtige Hinweise
Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen! |
Hallo und danke! Hier die beiden Log-Dateien: Combofix Logfile: Code: ComboFix 12-08-28.03 - *** 28.08.2012 22:31:17.1.2 - x86 Und: Update for Microsoft Office 2007 (KB2508958) Activation Assistant for the 2007 Microsoft Office suites Adobe Download Manager Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.2 - Deutsch Amazon MP3-Downloader 1.0.15 Apple Application Support Apple Mobile Device Support Apple Software Update ATI Catalyst Install Manager Avira Free Antivirus Bonjour Camera Assistant Software for Toshiba Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CD/DVD Drive Acoustic Silencer Compatibility Pack für 2007 Office System D3DX10 DivX-Setup Dropbox DSL Connection Manager EasyBits GO ElsterFormular Google Earth Google Update Helper Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) Intel® Matrix Storage Manager iTunes Java Auto Updater Java(TM) 6 Update 29 Junk Mail filter update Malwarebytes Anti-Malware Version 1.62.0.1300 Mesh Runtime Messenger Companion Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (German) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (German) 2007 Microsoft Office PowerPoint MUI (German) 2007 Microsoft Office PowerPoint Viewer 2007 (German) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (Italian) 2007 Microsoft Office Proofing (German) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (German) 2007 Microsoft Office Word MUI (German) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Works Mozilla Firefox 12.0 (x86 de) Mozilla Maintenance Service MSVCRT MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) myphotobook 3.65 Picasa 2 QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek 8136 8168 8169 Ethernet Driver Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Realtek WiFi Protected Setup Library Realtek WLAN Driver RealUpgrade 1.1 Samsung Kies SAMSUNG USB Driver for Mobile Phones Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition Skype™ 5.5 Synaptics Pointing Device Driver System Requirements Lab for Intel TOSHIBA Assist TOSHIBA Benutzerhandbücher TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Face Recognition TOSHIBA Hardware Setup Toshiba Online Product Information TOSHIBA Recovery Disc Creator TOSHIBA Recovery Disk Creator Reminder TOSHIBA Service Station TOSHIBA Supervisor Password TOSHIBA Value Added Package TRORDCLauncher Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) VC 9.0 Runtime VC80CRTRedist - 8.0.50727.6195 VLC media player 1.1.5 web'n'walk Manager WildTangent-Spiele Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Fotogalerie Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX control for remote connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinRAR ZoneAlarm Antivirus ZoneAlarm Firewall ZoneAlarm Free Antivirus + Firewall ZoneAlarm LTD Toolbar ZoneAlarm Security Grüße! |
Zonealarm deinstallieren! danach: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. |
Hallo, hier der aktuelle Suchlauf: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.29.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 *** :: ***-PC [Administrator] 29.08.2012 10:21:12 mbam-log-2012-08-29 (10-21-12).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 367748 Laufzeit: 3 Stunde(n), 30 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) -- Wieso musste ich Zonealarm deinstallieren? Kann ich es wieder raufspielen? Danke und Grüße! |
Alle Zeitangaben in WEZ +1. Es ist jetzt 16:34 Uhr. |
Copyright ©2000-2025, Trojaner-Board