![]() |
BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt Hallo, ich bin kein Computer-Profie und hoffe, daß ich hier alles richtig mache. ich habe folgendes Problem: Plötzlich war mein Bildschirm wie eingefrohren. Es war der bekannte "BKA Hinweis" mit den dementsprechenden Zahlungsaufforderungen. Habe dann den Rechner mit Strg und Entf und dann mit dem Taskmanager runtergefahren . Ich habe dann den Rechner neu gestartet und diesen mit Kaspersky-RescueDisc 2010 gescannt (vorher neuestes Kaspersky Update geladen). Es wurde eine Bedrohung angezeigt und diese dann wie von Kaspersky empfohlen in die Quarantäne geschoben. Danach habe ich den Rechner nochmal scannen lassen und Kaspersky hat dann nichts mehr gefunden. Super dachte ich, Kaspersky Disk raus und den Rechner neu gestartet... Windows startet kurz, ca 1 Sekunde und dann bekomm ich einen weissen Bildschirm. Sieht so aus wie eine leehre Firefoxseite. Und nichts geht mehr, genau wie diese "BKA Seite". Kann den Rechner dann nur mit STRg und Entf über den Taskmanager ausmachen. Nun habe ich mir über Euch die OTLPE geladen und auf eine DVD gebrannt. Programm lässt sich auch starten. Nachdem ich den Button OTLPE gedrückt habe, habe ich meinen Windowsordner gesucht und angeklickt "Windows 7 Ultimate (f:)" dann den Ordner "Windows" dann startet OTLPE auch. Wenn ich direkt auf "Windows 7 Ultimate (f:)" gehe erscheint: "Target is not windows 2000 or later". Der erste Text: "Do you wish to load the remote registry" erscheint nicht Der Zweit und Dritte aber und habe beim dritten Text den Haken rausgenommen. OTL startet und ich habe bei "Benutzerdefinierte Scans/Fixes" Euren Text rein kopiert von einem User mit dem gleichen Problem. siehe: http://www.trojaner-board.de/121242-...entfernen.html Ich hoffe ich war jetzt nicht zu voreilig. Packe jetzt den OTL Text und versuche den Euch zu mailen. Bedanke mich jetzt schon einmal für Eure Hilfe. OTL.tex folgt weiter unten. Gruß Ingmar OTL Text:OTL Logfile: Code: OTL logfile created on: 8/13/2012 9:23:58 PM - Run |
:hallo: Fixen mit OTLpe
Code: :OTL
|
Hallo, habe alles so gemacht wie oben beschrieben. Ich konnte den Rechner jetzt voll booten. Ich lass den Rechner jetzt einfach mal an und warte auf weitere Instruktionen. Ich maile jetzt das Logfile Hier das Logfile: ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SearchAnonymizer deleted successfully. F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VcommMgr deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VComm deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Btcsrusb deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BT deleted successfully. Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ deleted successfully. F:\Program Files\Softonic_Deutsch\prxtbSof0.dll moved successfully. HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "Yahoo" removed from browser.search.defaultenginename Prefs.js: "Softonic Deutsch Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" removed from browser.search.defaulturl Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr-cjkt Prefs.js: "Yahoo" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://www.google.de/" removed from browser.startup.homepage Prefs.js: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. F:\Program Files\ConduitEngine\prxConduitEngine.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ not found. File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ not found. File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found. Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}\ not found. File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found. Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE5D279F-081B-4404-994D-C6B60AAEBA6D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE5D279F-081B-4404-994D-C6B60AAEBA6D}\ deleted successfully. File To-Page\EPSON Web-To-Page.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM deleted successfully. F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe moved successfully. Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Run\\wnzhztlwwvwoahc deleted successfully. F:\ProgramData\wnzhztlw.exe moved successfully. Registry value HKEY_USERS\LocalService_ON_F\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. F:\Windows\System32\mctadmin.exe moved successfully. Registry value HKEY_USERS\NetworkService_ON_F\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File F:\Windows\System32\mctadmin.exe not found. F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLinkedConnections deleted successfully. Registry value HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! F:\autoexec.bat moved successfully. File move failed. X:\AUTORUN.INF scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found. File H:\USBAutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found. File E:\AUTORUN.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found. File E:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found. File D:\AUTORUN.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully. F:\Windows\System32\ConduitEngine.tmp deleted successfully. File F:\ProgramData\wnzhztlw.exe not found. F:\ProgramData\Babylon folder moved successfully. F:\Program Files\Common Files\AskToolbarInstaller.exe moved successfully. F:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. F:\Windows\System32\ANIWZCSUSERNAME moved successfully. F:\ProgramData\jqfnlczewmpbtxp folder moved successfully. F:\ProgramData\mijgefhjgbuamsf moved successfully. F:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. F:\ProgramData\0tbpw.pad moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration An internal error occurred: The system cannot find the file specified. Please contact Microsoft Product Support Services for further help. Additional information: Unable to open registry key for tcpip. F:\cmd.bat deleted successfully. F:\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56504 bytes User: Default User User: Ingmar ->Temp folder emptied: 1627344 bytes ->Temporary Internet Files folder emptied: 61910994 bytes ->Java cache emptied: 1253300 bytes ->FireFox cache emptied: 662365457 bytes ->Google Chrome cache emptied: 29693417 bytes ->Flash cache emptied: 2893532 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 67319 bytes Total Files Cleaned = 725.00 mb OTLPE by OldTimer - Version 3.1.48.0 log created on 08142012_210311 |
Sehr gut! :daumenhoc 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Hallo, mit Malwarebytes Anti-Malware den Rechner überprüft (vorher neues Update geladen). 3 Bedrohungen sind gefunden worden und anschließend gelöscht. Danach den AdwCleaner geladen und ausgeführt. Ich lass den Rechner jetzt so laufen und warte auf neue Instruktionen. Es folgen die beiden .tex Dateien von Alwarebytes und AdwCleaner: Hier Malwarebytes Anti-Malware: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.14.02 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 Ingmar :: INGMAR-PC [Administrator] 14.08.2012 12:52:38 mbam-log-2012-08-14 (15-12-20).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 405887 Laufzeit: 53 Minute(n), 38 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Keine Aktion durchgeführt. C:\_OTL\MovedFiles\08142012_210311\F_ProgramData\wnzhztlw.exe (Trojan.Ransom) -> Keine Aktion durchgeführt. C:\Users\Ingmar\ms.exe (Trojan.Ransom) -> Keine Aktion durchgeführt. (Ende) Hier AdwCleaner: # AdwCleaner v1.801 - Logfile created 08/14/2012 at 15:31:02 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Ultimate (32 bits) # User : Ingmar - INGMAR-PC # Boot Mode : Normal # Running from : C:\Users\Ingmar\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Ingmar\AppData\Local\Babylon Folder Found : C:\Users\Ingmar\AppData\Local\Conduit Folder Found : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk Folder Found : C:\Users\Ingmar\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\Ingmar\AppData\LocalLow\Conduit Folder Found : C:\Users\Ingmar\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Ingmar\AppData\LocalLow\PriceGong Folder Found : C:\Users\Ingmar\AppData\LocalLow\Softonic_Deutsch Folder Found : C:\Users\Ingmar\AppData\Roaming\Babylon Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\Conduit Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\ConduitEngine Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\CT1351351 Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com Folder Found : C:\Program Files\AutocompletePro Folder Found : C:\Program Files\BabylonToolbar Folder Found : C:\Program Files\Conduit Folder Found : C:\Program Files\ConduitEngine Folder Found : C:\Program Files\Softonic_Deutsch File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Askcom.xml File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Conduit.xml File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\SweetIm.xml File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1351351 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\AutocompletePro Key Found : HKCU\Software\AutocompleteProBHO Key Found : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro3_is1 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_Deutsch Toolbar Key Found : HKLM\SOFTWARE\Softonic_Deutsch ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED} Key Found : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3} Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7A732C9-B723-41BF-AF97-8C15E35697B7} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF58A471-4933-4904-AA5C-54F1DC0B2EFA} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79E5FE6A-EBEE-4979-94EA-E914A52136C3} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7600.16385 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\prefs.js Found : user_pref("CT1351351.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT1351351.CTID", "CT1351351"); Found : user_pref("CT1351351.DialogsAlignMode", "LTR"); Found : user_pref("CT1351351.EMailNotifierPollDate", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedLastCount4950394486774855536", 480); Found : user_pref("CT1351351.FeedPollDate129255010870695542", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870695548", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870695554", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870695560", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870695566", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851822", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851828", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851834", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851840", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851846", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851852", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851858", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851864", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851870", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851876", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851882", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851888", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851894", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851900", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851906", "Wed Nov 17 2010 16:32:17 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851912", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851918", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851924", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851930", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851936", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedPollDate129255010870851942", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.FeedTTL129255010870695554", 5); Found : user_pref("CT1351351.FeedTTL129255010870695560", 5); Found : user_pref("CT1351351.FeedTTL129255010870851840", 2); Found : user_pref("CT1351351.FeedTTL129255010870851870", 5); Found : user_pref("CT1351351.FeedTTL129255010870851882", 30); Found : user_pref("CT1351351.FirstTime", true); Found : user_pref("CT1351351.FirstTimeFF3", true); Found : user_pref("CT1351351.FixPageNotFoundErrors", true); Found : user_pref("CT1351351.GroupingServerCheckInterval", 1440); Found : user_pref("CT1351351.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT1351351.Initialize", true); Found : user_pref("CT1351351.InitializeCommonPrefs", true); Found : user_pref("CT1351351.InstalledDate", "Wed Nov 17 2010 16:32:15 GMT+0100"); Found : user_pref("CT1351351.InvalidateCache", false); Found : user_pref("CT1351351.IsGrouping", false); Found : user_pref("CT1351351.IsMulticommunity", false); Found : user_pref("CT1351351.IsOpenThankYouPage", true); Found : user_pref("CT1351351.IsOpenUninstallPage", true); Found : user_pref("CT1351351.LanguagePackLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100"); Found : user_pref("CT1351351.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT1351351.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT1351351.LastLogin_2.4.0.4", "Wed Nov 17 2010 16:33:06 GMT+0100"); Found : user_pref("CT1351351.LatestVersion", "2.7.2.0"); Found : user_pref("CT1351351.Locale", "de-de"); Found : user_pref("CT1351351.LoginCache", 4); Found : user_pref("CT1351351.MCDetectTooltipHeight", "83"); Found : user_pref("CT1351351.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT1351351.MCDetectTooltipWidth", "295"); Found : user_pref("CT1351351.RadioIsPodcast", false); Found : user_pref("CT1351351.RadioLastCheckTime", "Wed Nov 17 2010 16:32:16 GMT+0100"); Found : user_pref("CT1351351.RadioLastUpdateIPServer", "3"); Found : user_pref("CT1351351.RadioLastUpdateServer", "128929877726170000"); Found : user_pref("CT1351351.RadioMediaID", "10531746"); Found : user_pref("CT1351351.RadioMediaType", "Media Player"); Found : user_pref("CT1351351.RadioMenuSelectedID", "EBRadioMenu_CT135135110531746"); Found : user_pref("CT1351351.RadioStationName", "Antenne%20Bayern%20Top%2040"); Found : user_pref("CT1351351.RadioStationURL", "hxxp://channels.webradio.antenne.de/top-40"); Found : user_pref("CT1351351.SHRINK_TOOLBAR", 1); Found : user_pref("CT1351351.SearchEngine", "Websuche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_T[...] Found : user_pref("CT1351351.SearchFromAddressBarIsInit", true); Found : user_pref("CT1351351.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT135[...] Found : user_pref("CT1351351.SearchInNewTabEnabled", true); Found : user_pref("CT1351351.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT1351351.SearchInNewTabLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100"); Found : user_pref("CT1351351.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT1351351.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT1351351.SettingsCheckIntervalMin", 120); Found : user_pref("CT1351351.SettingsLastCheckTime", "Wed Nov 17 2010 16:32:10 GMT+0100"); Found : user_pref("CT1351351.SettingsLastUpdate", "1289939422"); Found : user_pref("CT1351351.ThirdPartyComponentsInterval", 504); Found : user_pref("CT1351351.ThirdPartyComponentsLastCheck", "Wed Nov 17 2010 16:32:10 GMT+0100"); Found : user_pref("CT1351351.ThirdPartyComponentsLastUpdate", "1255348257"); Found : user_pref("CT1351351.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...] Found : user_pref("CT1351351.UserID", "UN33001363855390975"); Found : user_pref("CT1351351.ValidationData_Toolbar", 2); Found : user_pref("CT1351351.WeatherNetwork", ""); Found : user_pref("CT1351351.WeatherPollDate", "Wed Nov 17 2010 16:32:18 GMT+0100"); Found : user_pref("CT1351351.WeatherUnit", "C"); Found : user_pref("CT1351351.alertChannelId", "669"); Found : user_pref("CT1351351.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Found : user_pref("CT1351351.clientLogIsEnabled", false); Found : user_pref("CT1351351.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...] Found : user_pref("CT1351351.myStuffEnabled", true); Found : user_pref("CT1351351.myStuffPublihserMinWidth", 400); Found : user_pref("CT1351351.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT1351351.myStuffServiceIntervalMM", 1440); Found : user_pref("CT1351351.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT1351351.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] Found : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine"); Found : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com"); Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine"); Found : user_pref("CommunityToolbar.IsEngineShown", true); Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Found : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine"); Found : user_pref("CommunityToolbar.ToolbarsList", "CT1351351,ConduitEngine"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1351351"); Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Jun 05 2011 11:00:47 GMT+02[...] Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jul 03 2011 11:58:05 GMT+0200"); Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.alert.locale", "en"); Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jul 06 2011 17:34:35 GMT+0200"); Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.alert.userId", "4bbe4652-9509-4515-b7de-abe86693c26f"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1351351"); Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sun Jul 03 2011 11:58:07 GMT+0200"); Found : user_pref("ConduitEngine.CTID", "ConduitEngine"); Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jul 06 2011 11:57:55 GMT+0200"); Found : user_pref("ConduitEngine.FirstServerDate", "06/05/2011 12"); Found : user_pref("ConduitEngine.FirstTime", true); Found : user_pref("ConduitEngine.FirstTimeFF3", true); Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Found : user_pref("ConduitEngine.Initialize", true); Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Found : user_pref("ConduitEngine.InstalledDate", "Sun Jun 05 2011 11:00:51 GMT+0200"); Found : user_pref("ConduitEngine.IsMulticommunity", false); Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Found : user_pref("ConduitEngine.IsOpenUninstallPage", true); Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jul 06 2011 17:34:42 GMT+0200"); Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jul 06 2011 14:42:01 GMT+0200"); Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jul 06 2011 14:42:01 GMT+0200"); Found : user_pref("ConduitEngine.UserID", "UN52334012069164096"); Found : user_pref("ConduitEngine.componentAlertEnabled", false); Found : user_pref("ConduitEngine.engineLocale", "de"); Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jul 06 2011 17:34:41 GMT+0200"); Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 16:42:03 GMT+0200"); Found : user_pref("ConduitEngine.initDone", true); Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Found : user_pref("ConduitEngine.usagesFlag", 1); -\\ Google Chrome v21.0.1180.77 File : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "description": "AutocompletePro - Speed up your search with your personal search sugg[...] Found : "name": "AutocompletePro plugin for chrome", ************************* AdwCleaner[R1].txt - [19063 octets] - [14/08/2012 15:31:02] ########## EOF - C:\AdwCleaner[R1].txt - [19192 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Hallo, Rechner mit adwcleaner.exe gescannt und Delite ausgeführt. Unten folgt die Textdatei welche bei Neustart sich öffnete. Emsisoft Anti-Malware konnte ich runterladen aber nicht installieren. Fehlermeldung: "Für den Betrieb auf Windows 7 oder Windowsserver 2008 R2 ist das Service Pack 1 erforderlich" Was nun? Ich habe das Programm SUPERAntiSpyware 5.5.1012. Nützt das ggf. etwas? Hier erstmal die Textdatei nach dem Neustart: # AdwCleaner v1.801 - Logfile created 08/14/2012 at 16:16:00 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Ultimate (32 bits) # User : Ingmar - INGMAR-PC # Boot Mode : Normal # Running from : C:\Users\Ingmar\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Ingmar\AppData\Local\Babylon Folder Deleted : C:\Users\Ingmar\AppData\Local\Conduit Folder Deleted : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\Softonic_Deutsch Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Babylon Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\Conduit Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\ConduitEngine Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\CT1351351 Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com Folder Deleted : C:\Program Files\AutocompletePro Folder Deleted : C:\Program Files\BabylonToolbar Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\ConduitEngine Folder Deleted : C:\Program Files\Softonic_Deutsch File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Askcom.xml File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Conduit.xml File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\SweetIm.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1351351 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AutocompletePro Key Deleted : HKCU\Software\AutocompleteProBHO Key Deleted : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1 Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\conduitEngine Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro3_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_Deutsch Toolbar Key Deleted : HKLM\SOFTWARE\Softonic_Deutsch ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7A732C9-B723-41BF-AF97-8C15E35697B7} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF58A471-4933-4904-AA5C-54F1DC0B2EFA} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79E5FE6A-EBEE-4979-94EA-E914A52136C3} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7600.16385 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\prefs.js C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\user.js ... Deleted ! Deleted : user_pref("CT1351351.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT1351351.CTID", "CT1351351"); Deleted : user_pref("CT1351351.DialogsAlignMode", "LTR"); Deleted : user_pref("CT1351351.EMailNotifierPollDate", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedLastCount4950394486774855536", 480); Deleted : user_pref("CT1351351.FeedPollDate129255010870695542", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870695548", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870695554", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870695560", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870695566", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851822", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851828", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851834", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851840", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851846", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851852", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851858", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851864", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851870", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851876", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851882", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851888", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851894", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851900", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851906", "Wed Nov 17 2010 16:32:17 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851912", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851918", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851924", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851930", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851936", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedPollDate129255010870851942", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.FeedTTL129255010870695554", 5); Deleted : user_pref("CT1351351.FeedTTL129255010870695560", 5); Deleted : user_pref("CT1351351.FeedTTL129255010870851840", 2); Deleted : user_pref("CT1351351.FeedTTL129255010870851870", 5); Deleted : user_pref("CT1351351.FeedTTL129255010870851882", 30); Deleted : user_pref("CT1351351.FirstTime", true); Deleted : user_pref("CT1351351.FirstTimeFF3", true); Deleted : user_pref("CT1351351.FixPageNotFoundErrors", true); Deleted : user_pref("CT1351351.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT1351351.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT1351351.Initialize", true); Deleted : user_pref("CT1351351.InitializeCommonPrefs", true); Deleted : user_pref("CT1351351.InstalledDate", "Wed Nov 17 2010 16:32:15 GMT+0100"); Deleted : user_pref("CT1351351.InvalidateCache", false); Deleted : user_pref("CT1351351.IsGrouping", false); Deleted : user_pref("CT1351351.IsMulticommunity", false); Deleted : user_pref("CT1351351.IsOpenThankYouPage", true); Deleted : user_pref("CT1351351.IsOpenUninstallPage", true); Deleted : user_pref("CT1351351.LanguagePackLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100"); Deleted : user_pref("CT1351351.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT1351351.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT1351351.LastLogin_2.4.0.4", "Wed Nov 17 2010 16:33:06 GMT+0100"); Deleted : user_pref("CT1351351.LatestVersion", "2.7.2.0"); Deleted : user_pref("CT1351351.Locale", "de-de"); Deleted : user_pref("CT1351351.LoginCache", 4); Deleted : user_pref("CT1351351.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT1351351.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT1351351.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT1351351.RadioIsPodcast", false); Deleted : user_pref("CT1351351.RadioLastCheckTime", "Wed Nov 17 2010 16:32:16 GMT+0100"); Deleted : user_pref("CT1351351.RadioLastUpdateIPServer", "3"); Deleted : user_pref("CT1351351.RadioLastUpdateServer", "128929877726170000"); Deleted : user_pref("CT1351351.RadioMediaID", "10531746"); Deleted : user_pref("CT1351351.RadioMediaType", "Media Player"); Deleted : user_pref("CT1351351.RadioMenuSelectedID", "EBRadioMenu_CT135135110531746"); Deleted : user_pref("CT1351351.RadioStationName", "Antenne%20Bayern%20Top%2040"); Deleted : user_pref("CT1351351.RadioStationURL", "hxxp://channels.webradio.antenne.de/top-40"); Deleted : user_pref("CT1351351.SHRINK_TOOLBAR", 1); Deleted : user_pref("CT1351351.SearchEngine", "Websuche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_T[...] Deleted : user_pref("CT1351351.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT1351351.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT135[...] Deleted : user_pref("CT1351351.SearchInNewTabEnabled", true); Deleted : user_pref("CT1351351.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT1351351.SearchInNewTabLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100"); Deleted : user_pref("CT1351351.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT1351351.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Deleted : user_pref("CT1351351.SettingsCheckIntervalMin", 120); Deleted : user_pref("CT1351351.SettingsLastCheckTime", "Wed Nov 17 2010 16:32:10 GMT+0100"); Deleted : user_pref("CT1351351.SettingsLastUpdate", "1289939422"); Deleted : user_pref("CT1351351.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT1351351.ThirdPartyComponentsLastCheck", "Wed Nov 17 2010 16:32:10 GMT+0100"); Deleted : user_pref("CT1351351.ThirdPartyComponentsLastUpdate", "1255348257"); Deleted : user_pref("CT1351351.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...] Deleted : user_pref("CT1351351.UserID", "UN33001363855390975"); Deleted : user_pref("CT1351351.ValidationData_Toolbar", 2); Deleted : user_pref("CT1351351.WeatherNetwork", ""); Deleted : user_pref("CT1351351.WeatherPollDate", "Wed Nov 17 2010 16:32:18 GMT+0100"); Deleted : user_pref("CT1351351.WeatherUnit", "C"); Deleted : user_pref("CT1351351.alertChannelId", "669"); Deleted : user_pref("CT1351351.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Deleted : user_pref("CT1351351.clientLogIsEnabled", false); Deleted : user_pref("CT1351351.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...] Deleted : user_pref("CT1351351.myStuffEnabled", true); Deleted : user_pref("CT1351351.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT1351351.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT1351351.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT1351351.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT1351351.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine"); Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com"); Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine"); Deleted : user_pref("CommunityToolbar.IsEngineShown", true); Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine"); Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1351351,ConduitEngine"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1351351"); Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Jun 05 2011 11:00:47 GMT+02[...] Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jul 03 2011 11:58:05 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.locale", "en"); Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jul 06 2011 17:34:35 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.alert.userId", "4bbe4652-9509-4515-b7de-abe86693c26f"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1351351"); Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sun Jul 03 2011 11:58:07 GMT+0200"); Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine"); Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jul 06 2011 11:57:55 GMT+0200"); Deleted : user_pref("ConduitEngine.FirstServerDate", "06/05/2011 12"); Deleted : user_pref("ConduitEngine.FirstTime", true); Deleted : user_pref("ConduitEngine.FirstTimeFF3", true); Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true); Deleted : user_pref("ConduitEngine.Initialize", true); Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true); Deleted : user_pref("ConduitEngine.InstalledDate", "Sun Jun 05 2011 11:00:51 GMT+0200"); Deleted : user_pref("ConduitEngine.IsMulticommunity", false); Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false); Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true); Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jul 06 2011 17:34:42 GMT+0200"); Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jul 06 2011 14:42:01 GMT+0200"); Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jul 06 2011 14:42:01 GMT+0200"); Deleted : user_pref("ConduitEngine.UserID", "UN52334012069164096"); Deleted : user_pref("ConduitEngine.componentAlertEnabled", false); Deleted : user_pref("ConduitEngine.engineLocale", "de"); Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jul 06 2011 17:34:41 GMT+0200"); Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 16:42:03 GMT+0200"); Deleted : user_pref("ConduitEngine.initDone", true); Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Deleted : user_pref("ConduitEngine.usagesFlag", 1); -\\ Google Chrome v21.0.1180.77 File : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "description": "AutocompletePro - Speed up your search with your personal search sugg[...] Deleted : "name": "AutocompletePro plugin for chrome", ************************* AdwCleaner[R1].txt - [19194 octets] - [14/08/2012 15:31:02] AdwCleaner[R2].txt - [19255 octets] - [14/08/2012 16:15:47] AdwCleaner[S1].txt - [19687 octets] - [14/08/2012 16:16:00] ########## EOF - C:\AdwCleaner[S1].txt - [19816 octets] ########## |
Alle Updates, inkl SP1 einspielen! |
Hallo ich habe mehrfach versucht Windows Updates bzw. das Sp1 runterzuladen. Leider vergebens, es liegt wohl an meiner lahmen Internetverbindung. Bei größeren Datein bricht diese anscheinend den Download ab... Wie sieht es aus, wenn ich eine neue Windows Version installiere, wären dann auch alle Schädlinge vernichtet, da die Festplatte formatiert wird? Bzw. habe ich noch eine Acronis Image von dem Rechner als dieser neu war. Wenn ich die wieder Installiere, werden die Schädlinge dann vernichtet? Auch da wird ja die Festplatte formatiert? Für einen Tip wäre ich dankbar. Gruß Ingmar |
Ja, das waeren sie. Aber wenn du dein Rechner nicht aktuell haelst wird du dieses Problem (oder ein groesseres) sofort wieder haben! |
Hallo, aktuell halten, bedeutet das, das ich immer alle Windows Updates machen soll bzw. alle verfügbaren Sp`s installiere? Welches Antivirenprogramm ist das beste? Ich hatte bislang das von AVG Free Edition, aber das scheint ja nicht so gut zu sein. Gruß Ingmar |
Zitat:
Zitat:
Alle die Hilfe suchen haben einen Virenscanner. Es nützt nichts. |
Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 04:40 Uhr. |
Copyright ©2000-2025, Trojaner-Board