![]() |
|
Plagegeister aller Art und deren Bekämpfung: Mystart incredibar im neuen TabWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mystart incredibar im neuen Tab Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL :reg [-HKEY_CURRENT_USER\Software\incredibar.com] [-HKEY_CURRENT_USER\Software\incredibar.com\incredibar] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\incredibar.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\incredibar.com\incredibar] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com] [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}] [-HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}] :files C:\Users\Daniele Cipriano\AppData\Roaming\Mozilla\Firefox\Profiles\djmzcogf.default\prefs.js C:\Users\Emanuele\AppData\Roaming\Mozilla\Firefox\Profiles\ilhln8u2.default\prefs.js ipconfig /flushdns /c :Commands [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
![]() | #2 |
![]() ![]() ![]() ![]() | ![]() Mystart incredibar im neuen Tab also irgendwas hat es gebracht,
__________________Da Firefox Fenster aufgemacht hat für alle Tabs, die ich habe und eine andere Persona hat... egal... Code:
ATTFilter All processes killed ========== OTL ========== ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\incredibar.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\incredibar.com\incredibar\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\incredibar.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\incredibar.com\incredibar\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-download-now.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimail-hq.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredimailpro.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-download-now.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimail-hq.com\ not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredimailpro.com\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. Registry key HKEY_USERS\S-1-5-21-1242904208-471078349-2963378918-1000\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. ========== FILES ========== C:\Users\Daniele Cipriano\AppData\Roaming\Mozilla\Firefox\Profiles\djmzcogf.default\prefs.js moved successfully. C:\Users\Emanuele\AppData\Roaming\Mozilla\Firefox\Profiles\ilhln8u2.default\prefs.js moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Daniele Cipriano\Desktop\cmd.bat deleted successfully. C:\Users\Daniele Cipriano\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Daniele Cipriano ->Temp folder emptied: 35721841 bytes ->Temporary Internet Files folder emptied: 17406180 bytes ->Java cache emptied: 1664231 bytes ->FireFox cache emptied: 250762475 bytes ->Flash cache emptied: 50323 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Emanuele ->Temp folder emptied: 4560365 bytes ->Temporary Internet Files folder emptied: 27038062 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 665 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1406264 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 9290978450 bytes Total Files Cleaned = 9.184,00 mb OTL by OldTimer - Version 3.2.63.0 log created on 09182012_055442 Files\Folders moved on Reboot... C:\Users\Daniele Cipriano\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Wenn ich jetzt ein neues Fenster öffne erscheint eine WEB.de Seite mit den letzten Websiten, da war vorher schon so auch aber nicht mit WEB.de Unterstützung. Haben wir es jetzt endlich weg.. sicher.. bin mir da nicht so sicher.. |
![]() |
Themen zu Mystart incredibar im neuen Tab |
antivir, avira, bho, bonjour, canon, converter, desktop, document, eraser, error, excel, firefox, flash player, home, incredibar toolbar, install.exe, launch, locker, logfile, mozilla, mp3, mywinlocker, netzwerk, office 2007, plug-in, problem, realtek, registry, safer networking, scan, security, senden, software, svchost.exe, visual studio, windows |