Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   SafeFinder, nicht sicher ob komplett entfernt (https://www.trojaner-board.de/169331-safefinder-sicher-ob-komplett-entfernt.html)

schrauber 19.08.2015 17:09

Davon brauchst eigentlich nix löschen. Mach bitte mal die Registry Suche mit FRST.

Rhea 20.08.2015 16:19

Okay, danke.

Hier das Ergebnis der Registry Suche.

Code:

Farbar Recovery Scan Tool (x64) Version:13-08-2015
durchgeführt von Andrea (2015-08-20 17:17:19)
Gestartet von C:\Users\Andrea\Desktop
Start-Modus: Normal

================== Registry-Suche: "Firefox" ===========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\44870A0846AC4ED4BA163DD7BD8E70F4]
"IntegrFirefox"="Complete"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]
""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe,1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\firefox.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\44870A0846AC4ED4BA163DD7BD8E70F4\Features]
"IntegrFirefox"="6RC{0f8Vr95b!RnHQ-$DKC96Z6`es?J2c$]h'zBv=thhN})nA9P[kY3`tW18Y9qh6*(Z4=%u}+(_5FHVComplete"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"SIGN.IE=07D3DD0 Firefox%20Setup%203.6.2.exe"="VISTARTM"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Synaptics\SynTP\Defaults\AppProfiles\Mozilla Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Synaptics\SynTPEnh\OSD\TouchPad\AppProfiles\Mozilla Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Synaptics\SynTPEnh\OSD\TouchPad\AppProfiles\Mozilla Firefox]
"AppExe"="firefox.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Synaptics\SynTPEnh\OSD\TouchPad\AppProfiles\Mozilla Firefox]
"AppFriendlyName"="Mozilla Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Synaptics\SynTPEnh\PlugInConfig\TouchPad\AppProfiles\Mozilla Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Shared\HTML]
"KnownIDs"="htmlfile;FirefoxHTML"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\firefox_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\firefox_RASMANCS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3]
"ProductName"="Microsoft Office Live Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"ProductName"="Microsoft Office Live Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"ProductName"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0\MimeTypes\application/x-sharepoint]
"Description"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin\MimeTypes\application/firefox-interactwithclient-plugin]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"="Handles PDFs in-place in Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"ProductName"="Adobe Reader Plugin for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Safer Networking Limited\PortableSupport]
"Firefox"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]
""="C:\Program Files (x86)\Mozilla Firefox\firefox.exe,1"
[HKEY_USERS\.DEFAULT\Software\Safer Networking Limited\Localization]
"C:\Program Files (x86)\Mozilla Firefox\"=""
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\AVAST Software\Avast Browser Cleanup]
"firefox_SP"="8D26A3F9454C05783CD0BC4FE15F13A616ED9877DC910BC9968F0869AB297C86"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Clients\StartMenuInternet]
""="FIREFOX.EXE"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Google\Update\proxy]
"source"="Firefox"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Mail.Ru\Guard]
"firefox.exe"="0"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Mail.Ru\Guard]
"firefox.exe.delay"="3"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\15ab5e1_0]
""="{0.0.0.00000000}.{961b0bb0-66b2-4c6a-aee2-fa3f89441c16}|\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\a284f2ad_0]
""="{0.0.0.00000000}.{961b0bb0-66b2-4c6a-aee2-fa3f89441c16}|\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\b40c19e4_0]
""="{0.0.0.00000000}.{961b0bb0-66b2-4c6a-aee2-fa3f89441c16}|\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\updated\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aup\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CATDrawing\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithList]
"e"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids]
"FirefoxHTML"=""
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids]
"FirefoxHTML"=""
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ica\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ics\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jar\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jnlp\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.part\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcf\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids]
"FirefoxHTML"=""
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tar\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Firefox]
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Firefox\WWW_OpenURL]
"ProcessName"="firefox.exe"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Andrea\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N2HMOI6X\Firefox_Setup_3.6.2[1].exe"="1"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"SIGN.IE=07D3DD0 Firefox%20Setup%203.6.2.exe"="1"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Andrea\Downloads\Firefox Setup 4.0.1.exe"="1"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Andrea\Downloads\Firefox Setup Stub 39.0.exe"="1"
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Safer Networking Limited\Localization]
"C:\Program Files (x86)\Mozilla Firefox\"=""
[HKEY_USERS\S-1-5-21-864334625-1213360965-2481295583-1001\Software\Safer Networking Limited\PortableSupport]
"Firefox"=""
[HKEY_USERS\S-1-5-18\Software\Safer Networking Limited\Localization]
"C:\Program Files (x86)\Mozilla Firefox\"=""

====== Ende von Suche ======


schrauber 21.08.2015 07:19

Versuch es mal so:
https://support.mozilla.org/de/kb/Ad...alliert-werden

Rhea 21.08.2015 10:45

Also soll ich Firefox jetzt erst mal wieder installieren, um es dann wieder zu deinstallieren?
Versteh ich das richtig?
Weil im Moment ist Firefox nicht installiert.

schrauber 22.08.2015 09:53

Installieren, dann den Profile Ordner bearbeiten bzw im FF Safe Mode das Addon löschen.

Rhea 24.08.2015 07:30

Moin schrauber,

starten im abgesicherten Modus ergibt keine Veränderung. Ich kann die Plugins immer noch nicht löschen.

Manuekk geht auch nicht, da der Ordner extensions nicht existiert, obwohl die Plugins ja da sind. :wtf:


Ich würde es an dieser Stelle aufgeben, da ich meinen Laptop diese Woche zwingend mit funktionierendem Internet brauchte. Bzw. nicht auf einen anderen ausweichen kann.
Vielen Dank für die Hilfe soweit.

schrauber 24.08.2015 15:29

Es ist schon extrem merkwürdig das Ganze...


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:11 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132