![]() |
|
Plagegeister aller Art und deren Bekämpfung: Windows7 Home- Feven und awesomehp.com ...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #11 |
![]() | ![]() Windows7 Home- Feven und awesomehp.com ... Hi, Matthias, dauerte etwas - erstmals viiielen Dank für deine Geduld und deine Hilfe!!! Laptop läuft bereits viel besser! Hier das letzte ... ich hab keine Ahnung, ob ich das richti eingefügt habe Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 02-March-2014 Tool run by Barbara on 03.03.2014 at 22:11:06,30. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Barbara\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 03.03.2014 22:18:02 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1984625836-208992553-353456307-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_start@gmail.com deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.de/"); user_pref("browser.search.defaultengine", "Ask.com"); user_pref("browser.search.useDBForOrder", true); Added to C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- FireFox user.js and prefs.js backups ---- prefs__2242_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~2\DVDVideoSoftTB_DE deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~3\Yahoo! deleted C:\PROGRA~3\Allmyapps deleted C:\Users\Barbara\AppData\LocalLow\DVDVideoSoftTB_DE deleted C:\Users\Barbara\AppData\LocalLow\Yahoo! deleted C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\CT2625848 deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default - Star Stable Online - %ProfilePath%\extensions\plugin@starstable.com - HP Detect - %ProfilePath%\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default D775FA6F1E88B3B99E69E8A0D6C3A819 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll - Shockwave Flash 6B6E59354DB3977E03B67F7FB9A61F70 - C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\extensions\plugin@starstable.com\plugins\npstudioruntime.dll - Star Stable Online ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {460C3D19-B3D4-4964-A550-77D263B0CCCB} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox" {5968ED80-05F8-4DF9-9DB7-DFC78C18C914} eBay Url="hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}" {67AD9B8D-C3BD-4D71-B7E0-6A8662F4AF03} Amazon Url="hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== Nothing found to reset ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Barbara\AppData\Local\Mozilla\Firefox\Profiles\qhhqn0mj.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=71 folders=6 1428779 bytes) ==== Empty Temp Folders ====================== C:\Users\Barbara\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Barbara\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 03.03.2014 at 22:54:39,09 ====================== erstmal vielen Dank für deine Geduld und vor allem für deine Hilfe!! Hier das letzte : Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 02-March-2014 Tool run by Barbara on 03.03.2014 at 22:11:06,30. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Barbara\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 03.03.2014 22:18:02 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1984625836-208992553-353456307-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_start@gmail.com deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.de/"); user_pref("browser.search.defaultengine", "Ask.com"); user_pref("browser.search.useDBForOrder", true); Added to C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- FireFox user.js and prefs.js backups ---- prefs__2242_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~2\DVDVideoSoftTB_DE deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~3\Yahoo! deleted C:\PROGRA~3\Allmyapps deleted C:\Users\Barbara\AppData\LocalLow\DVDVideoSoftTB_DE deleted C:\Users\Barbara\AppData\LocalLow\Yahoo! deleted C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\CT2625848 deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default - Star Stable Online - %ProfilePath%\extensions\plugin@starstable.com - HP Detect - %ProfilePath%\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default D775FA6F1E88B3B99E69E8A0D6C3A819 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll - Shockwave Flash 6B6E59354DB3977E03B67F7FB9A61F70 - C:\Users\Barbara\AppData\Roaming\Mozilla\Firefox\Profiles\qhhqn0mj.default\extensions\plugin@starstable.com\plugins\npstudioruntime.dll - Star Stable Online ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {460C3D19-B3D4-4964-A550-77D263B0CCCB} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox" {5968ED80-05F8-4DF9-9DB7-DFC78C18C914} eBay Url="hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}" {67AD9B8D-C3BD-4D71-B7E0-6A8662F4AF03} Amazon Url="hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== Nothing found to reset ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Barbara\AppData\Local\Mozilla\Firefox\Profiles\qhhqn0mj.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=71 folders=6 1428779 bytes) ==== Empty Temp Folders ====================== C:\Users\Barbara\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Barbara\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 03.03.2014 at 22:54:39,09 ====================== werde den Laptop runterfahren - muss ins Bett :-) Bin morgen nochmal online! Gute Nacht! VG Barbara Guten Morgen, es scheint, der 'Spuk ist vorbei! Vielen Dank! Bitte gib mir doch bitte noch Bescheid, ob ich die runtergeladenen Programme löschen)deinstallieren soll.Mein Virenscanner meckert etwas! VG Barbara |
Themen zu Windows7 Home- Feven und awesomehp.com ... |
avira, awesomehp, awesomehp entfernen, exploit.drop.gsa, gen, helft, laptop, media player, pup.optional.awesomehp.a, sache, scanner, trojan.delf, virenscan, virenscanner, werbung, windows |