![]() |
|
Log-Analyse und Auswertung: Neues Mitglied der Gruppe "my start incredibar" - Ich möchte bitte weg :-)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() Neues Mitglied der Gruppe "my start incredibar" - Ich möchte bitte weg :-) Hallo t'john, danke sehr! OTL hat es geschafft. Den Bericht finden Sie unten meine Nachricht. Ich sehe, dass der Compi erstmal normal schnell funktioniert. Aber 1.als Startseite habe ich folgendes: hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc= 2.Ich habe auf der Festplastte noch C:\Program Files\Softonic\Softonic\1.6.7.4 3.Irgendwelche Fensterchen in blau mit Werbung zeigen sich immer noch. 4. Wenn ich einen Tab öffne, habe ich eine Leiste mit "incredibar" mit Suchmöglichkeit sowie irgendwelche Werrbebuttons. Gibt es Möglichkeit diese auch zu löschen? Vielmals Danke !!!! Die Ergebnisse von OTL: All processes killed ========== OTL ========== Service Web Assistant Updater stopped successfully! Service Web Assistant Updater deleted successfully! C:\Program Files\Web Assistant\ExtensionUpdaterService.exe moved successfully. Service WDICA stopped successfully! Service WDICA deleted successfully! File File not found not found. Service PDRFRAME stopped successfully! Service PDRFRAME deleted successfully! File File not found not found. Service PDRELI stopped successfully! Service PDRELI deleted successfully! File File not found not found. Service PDFRAME stopped successfully! Service PDFRAME deleted successfully! File File not found not found. Service PDCOMP stopped successfully! Service PDCOMP deleted successfully! File File not found not found. Service PCIDump stopped successfully! Service PCIDump deleted successfully! File File not found not found. Service lbrtfdc stopped successfully! Service lbrtfdc deleted successfully! File File not found not found. Service i2omgmt stopped successfully! Service i2omgmt deleted successfully! File File not found not found. Service Changer stopped successfully! Service Changer deleted successfully! File File not found not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-3402263254-3905192389-2916328827-500\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ deleted successfully. C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully. HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{27E9840D-D155-4819-BE9F-B4FD3FB68DF6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27E9840D-D155-4819-BE9F-B4FD3FB68DF6}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{B0C4CFAA-90B7-4E4D-92F4-61FFC22D746A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0C4CFAA-90B7-4E4D-92F4-61FFC22D746A}\ not found. Registry key HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found. HKU\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "MyStart Search" removed from browser.search.defaultenginename Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "Search the web (Softonic)" removed from browser.search.selectedEngine Prefs.js: "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q=" removed from keyword.URL Prefs.js: 0 removed from network.proxy.type Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. C:\Program Files\Web Assistant\Firefox\defaults\preferences folder moved successfully. C:\Program Files\Web Assistant\Firefox\defaults folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\skin folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\locale\en-US folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\locale folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content\resources folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content\libraries folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome\content folder moved successfully. C:\Program Files\Web Assistant\Firefox\chrome folder moved successfully. C:\Program Files\Web Assistant\Firefox folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0\resources folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0\libraries folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.467_0 folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. C:\Program Files\Web Assistant\Extension32.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}\ deleted successfully. C:\Program Files\Softonic\Softonic\1.6.7.4\bh\Softonic.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}\ deleted successfully. C:\Program Files\Softonic\Softonic\1.6.7.4\SoftonicTlbr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77}\ deleted successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll moved successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Program Files\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found. Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer not found. Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-21-3402263254-3905192389-2916328827-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTOEXEC.BAT moved successfully. C:\Program Files\SoftonicDownloader_for_winx-dvd-player.exe moved successfully. C:\Program Files\SoftonicDownloader_fuer_avs-media-player.exe moved successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\MediaBA folder moved successfully. C:\Program Files\BetterAds folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Incredibar.com\incredibar folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Incredibar.com folder moved successfully. C:\Program Files\Perion\NewTab folder moved successfully. C:\Program Files\Perion folder moved successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh folder moved successfully. C:\Program Files\Incredibar.com\incredibar\1.5.11.14 folder moved successfully. C:\Program Files\Incredibar.com\incredibar folder moved successfully. C:\Program Files\Incredibar.com folder moved successfully. C:\Program Files\Web Assistant\resources folder moved successfully. C:\Program Files\Web Assistant\libraries folder moved successfully. C:\Program Files\Web Assistant folder moved successfully. C:\user.js moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe\Acrobat\10.0 folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe\Acrobat folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp\Adobe folder moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp folder moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration An internal error occurred: The request is not supported. Please contact Microsoft Product Support Services for further help. Additional information: Unable to query host name. C:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 173321930 bytes ->Temporary Internet Files folder emptied: 44006134 bytes ->FireFox cache emptied: 459976934 bytes ->Google Chrome cache emptied: 7581174 bytes ->Flash cache emptied: 59310 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 56478 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33043 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Photohop %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 12541725 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 144597176 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 970338927 bytes Total Files Cleaned = 1.729,00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08262012_073518 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF90DC.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF90E9.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9143.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9150.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9256.tmp not found! File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\~DF9263.tmp not found! C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
![]() |
Themen zu Neues Mitglied der Gruppe "my start incredibar" - Ich möchte bitte weg :-) |
"my start incredibar" entfernen, avira, bericht, browser, folge, gruppe, infizierte, installiert, klicke, komplett, kopieren, laptop, lüfter, malwarebytes, mozilla, neue, neue seite, neuen, neues, nichts, problem, scan, schnell, seite, softronic, start, tab, virus, win |