Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Werbe Tabs öffnen sich in Firefox (https://www.trojaner-board.de/145823-werbe-tabs-oeffnen-firefox.html)

aharonov 13.01.2014 19:54

Also ist der Scan nicht durchgelaufen?

ThunderX 13.01.2014 20:16

Doch der ist durchgelaufen, aber erst nach sehr langer Zeit, der Fehler oben ist mehrmals aufgetreten

Code:

Zoek.exe v5.0.0.0 Updated 09-Januari-2014
Tool run by user on 12.01.2014 at 19:58:19,71.
Microsoft Windows 8.1 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\usr1\Downloads\zoek\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

12.01.2014 19:59:16 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\usr2\AppData\Roaming\Mozilla\Firefox\Profiles\20achfvp.default\prefs.js:

Added to C:\Users\usr2\AppData\Roaming\Mozilla\Firefox\Profiles\20achfvp.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\usr1\AppData\Roaming\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\prefs.js:

Added to C:\Users\usr1\AppData\Roaming\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\trk79v17.default\prefs.js:

Added to C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\trk79v17.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\usr3\AppData\Roaming\Mozilla\Firefox\Profiles\x88fm5vb.default\prefs.js:

Added to C:\Users\usr3\AppData\Roaming\Mozilla\Firefox\Profiles\x88fm5vb.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Deleting Files \ Folders ======================

C:\WINDOWS\SysWow64\AI_RecycleBin deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" []

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://acer13.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://acer13.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} Unknown  Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3055901358-908682401-1845398182-1001\Software\Microsoft\Internet Explorer\SearchScopes\{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} deleted successfully
HKEY_USERS\S-1-5-21-3055901358-908682401-1845398182-1002\Software\Microsoft\Internet Explorer\SearchScopes\{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\usr2\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr1\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr1\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr3\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr3\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\usr2\AppData\Local\Mozilla\Firefox\Profiles\20achfvp.default\Cache emptied successfully
C:\Users\usr1\AppData\Local\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\Cache emptied successfully
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\trk79v17.default\Cache emptied successfully
C:\Users\usr3\AppData\Local\Mozilla\Firefox\Profiles\x88fm5vb.default\Cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1 folders=3 77 bytes)

==== Empty Temp Folders ======================

C:\Users\usr2\AppData\Local\Temp emptied successfully
C:\Users\usr1\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\usr3\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\user\AppData\Local\Temp  will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot


aharonov 13.01.2014 20:34

Und die Werbetabs sind immer noch vorhanden?

ThunderX 13.01.2014 20:36

Kann ich im Moment noch nicht sagen, die kommen ab und zu. Trotzdem danke für die Hilfe ;)

aharonov 14.01.2014 00:19

Behalt es mal im Auge und melde dich dann wieder.

ThunderX 23.01.2014 20:56

Es scheinen sich keine Tabs mehr zu öffnen. Vielen Dank für die Hilfe :dankeschoen:


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:43 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131