![]() |
MyStart Trojaner in jedem neuen Tab (Mozilla) Hallo, ich hab seit gestern den Trojaner MyStart und bekomme ihn nicht mehr weg. Auch McAfee hat ihn nicht beseitigen können. Könnt ihr mir bitte helfen den Trojaner zu beseitigen? MfGOTL Logfile: Code: OTL logfile created on: 28.08.2012 11:33:44 - Run 1 OTL Logfile: Code: OTL Extras logfile created on: 28.08.2012 11:33:44 - Run 1 |
:hallo: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
DANKE schonmal!! # AdwCleaner v1.801 - Logfile created 08/29/2012 at 20:52:17 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : tobi - TOBI-PC # Boot Mode : Normal # Running from : C:\Users\tobi\Downloads\adwCleaner1801.exe # Option [Search] ***** [Services] ***** Found : Bandoo Coordinator ***** [Files / Folders] ***** Folder Found : C:\Users\tobi\AppData\Local\Ilivid Player Folder Found : C:\Users\tobi\AppData\Local\Temp\avg@toolbar Folder Found : C:\Users\tobi\AppData\LocalLow\Bandoo Folder Found : C:\Users\tobi\AppData\LocalLow\boost_interprocess Folder Found : C:\Users\tobi\AppData\Roaming\Babylon Folder Found : C:\Users\tobi\AppData\Roaming\Bandoo Folder Found : C:\Users\tobi\AppData\Roaming\OpenCandy Folder Found : C:\Users\tobi\AppData\Roaming\pdfforge Folder Found : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\extensions\ffox@bandoo.com Folder Found : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\extensions\plugin@yontoo.com Folder Found : C:\ProgramData\Babylon Folder Found : C:\ProgramData\Bandoo Folder Found : C:\ProgramData\Tarma Installer Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandoo Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Found : C:\Program Files (x86)\Bandoo Folder Found : C:\Program Files (x86)\DealPly Folder Found : C:\Program Files (x86)\Ilivid Folder Found : C:\Program Files (x86)\Yontoo File Found : C:\Users\tobi\AppData\Local\Temp\Searchqu.ini File Found : C:\Users\tobi\AppData\Local\Temp\SetupDataMngr_Searchqu.exe File Found : C:\Users\tobi\AppData\Local\Temp\Uninstall.exe File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml File Found : C:\user.js ***** [Registry] ***** Key Found : HKCU\Software\DealPly Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKCU\Software\IGearSettings Key Found : HKCU\Software\IM Key Found : HKCU\Software\ImInstaller Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Babylon Key Found : HKLM\SOFTWARE\bandoo Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\DealPly Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dloejdefkancmfajekobpfoacecnhpgp Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandoo Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Found : HKLM\SOFTWARE\Web Assistant Value Found : HKCU\Software\Mozilla\Firefox\Extensions [ffox@bandoo.com] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] [x64] Key Found : HKCU\Software\DealPly [x64] Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje [x64] Key Found : HKCU\Software\IGearSettings [x64] Key Found : HKCU\Software\IM [x64] Key Found : HKCU\Software\ImInstaller [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin [x64] Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl [x64] Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl [x64] Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 [x64] Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Found : HKLM\SOFTWARE\Tarma Installer [x64] Key Found : HKLM\SOFTWARE\Web Assistant [x64] Value Found : HKCU\Software\Mozilla\Firefox\Extensions [ffox@bandoo.com] [x64] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Found : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Found : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{074E4EFE-81BB-4EA4-866E-082CB0E01070} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0CE5B352-9D9C-41E1-9551-FCCD92820217} Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\CLSID\{167B2B5F-2757-434A-BBDA-2FDB2003F14F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531} Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF2B6317-C367-401B-83B8-80302D6588A7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F5379B4B-24D8-432A-9A96-BE75EE5117DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Found : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Found : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Found : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=114351&tt=201208_mnt_n_3512_3&babsrc=HP_ss&mntrId=e4a73a82000000000000206a8a34f794 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=114351&tt=201208_mnt_n_3512_3&babsrc=NT_ss&mntrId=e4a73a82000000000000206a8a34f794 -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\prefs.js Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb155?a=6R8DmV1zuD&loc=FF_NT"); Found : user_pref("browser.search.defaultenginename", "MyStart Search"); Found : user_pref("extensions.BabylonToolbar.admin", false); Found : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); Found : user_pref("extensions.BabylonToolbar.autoRvrt", "false"); Found : user_pref("extensions.BabylonToolbar.babExt", ""); Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=114351&tt=201208_mnt_n_3512_3"); Found : user_pref("extensions.BabylonToolbar.cntry", "DE"); Found : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Found : user_pref("extensions.BabylonToolbar.dp_alert", "newBlk"); Found : user_pref("extensions.BabylonToolbar.envrmnt", "production"); Found : user_pref("extensions.BabylonToolbar.excTlbr", false); Found : user_pref("extensions.BabylonToolbar.hdrMd5", "475C53185168DA8963B0934BC3F44F88"); Found : user_pref("extensions.BabylonToolbar.hmpg", false); Found : user_pref("extensions.BabylonToolbar.id", "e4a73a82000000000000206a8a34f794"); Found : user_pref("extensions.BabylonToolbar.instlDay", "15579"); Found : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar.isdcmntcmplt", true); Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.6.9.1219:04:08"); Found : user_pref("extensions.BabylonToolbar.mntrvrsn", "1.3.1"); Found : user_pref("extensions.BabylonToolbar.newTab", false); Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar.sg", "none"); Found : user_pref("extensions.BabylonToolbar.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar.tlbrId", "base"); Found : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...] Found : user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12"); Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.6.9.1219:04:08"); Found : user_pref("extensions.BabylonToolbar.vrsni", "1.6.9.12"); Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=114351&tt=201208_mnt_n_3512_3"); Found : user_pref("extensions.BabylonToolbar_i.newTab", false); Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1219:04:08"); Found : user_pref("extensions.incredibar.cntry", "DE"); Found : user_pref("extensions.incredibar.did", "10657"); Found : user_pref("extensions.incredibar.envrmnt", "production"); Found : user_pref("extensions.incredibar.hdrMd5", ""); Found : user_pref("extensions.incredibar.hmpg", false); Found : user_pref("extensions.incredibar.installerproductid", "26"); Found : user_pref("extensions.incredibar.isDcmntCmplt", true); Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1419:02:49"); Found : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Found : user_pref("extensions.incredibar.newTab", false); Found : user_pref("extensions.incredibar.ppd", ""); Found : user_pref("extensions.incredibar.productid", "26"); Found : user_pref("extensions.incredibar.sg", "none"); Found : user_pref("extensions.incredibar.smplGrp", "none"); Found : user_pref("extensions.incredibar.upn2", "6R8DmV1zuD"); Found : user_pref("extensions.incredibar.upn2n", "92824953997166463"); Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1419:02:49"); Found : user_pref("extensions.incredibar_i.aflt", "orgnl"); Found : user_pref("extensions.incredibar_i.dfltLng", ""); Found : user_pref("extensions.incredibar_i.did", "10657"); Found : user_pref("extensions.incredibar_i.excTlbr", false); Found : user_pref("extensions.incredibar_i.id", "e4a73a82000000000000206a8a34f794"); Found : user_pref("extensions.incredibar_i.installerproductid", "26"); Found : user_pref("extensions.incredibar_i.instlDay", "15579"); Found : user_pref("extensions.incredibar_i.instlRef", ""); Found : user_pref("extensions.incredibar_i.ms_url_id", ""); Found : user_pref("extensions.incredibar_i.newTab", false); Found : user_pref("extensions.incredibar_i.ppd", ""); Found : user_pref("extensions.incredibar_i.prdct", "incredibar"); Found : user_pref("extensions.incredibar_i.productid", "26"); Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Found : user_pref("extensions.incredibar_i.smplGrp", "none"); Found : user_pref("extensions.incredibar_i.tlbrId", "base"); Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8DmV1zuD&loc=IB[...] Found : user_pref("extensions.incredibar_i.upn2", "6R8DmV1zuD"); Found : user_pref("extensions.incredibar_i.upn2n", "92824953997166463"); Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1419:02:49"); Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Found : user_pref("keyword.URL", "hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=e4a73a82000000000000206a8a3[...] Found : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] ************************* AdwCleaner[R1].txt - [25330 octets] - [29/08/2012 20:52:17] ########## EOF - C:\AdwCleaner[R1].txt - [25459 octets] ########## |
Bitte das Malwarebytes Logfile posten! (Reiter Logberichte) |
Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.28.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 tobi :: TOBI-PC [Administrator] Schutz: Aktiviert 28.08.2012 21:58:37 mbam-log-2012-08-28 (21-58-37).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 468533 Laufzeit: 2 Stunde(n), 59 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FoxTab Video Converter (Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Users\tobi\Downloads\setup(1).exe (PUP.BundleInstaller.VG) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\tobi\Downloads\setup.exe (PUP.BundleInstaller.VG) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\tobi\Downloads\VideoConverterSetup.exe (Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\tobi\FoxTabVideoConverter\Uninstall\Uninstall.exe (Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) 2012/08/28 21:57:13 +0200 TOBI-PC tobi MESSAGE Starting protection 2012/08/28 21:57:15 +0200 TOBI-PC tobi MESSAGE Protection started successfully 2012/08/28 21:57:18 +0200 TOBI-PC tobi MESSAGE Starting IP protection 2012/08/28 21:57:21 +0200 TOBI-PC tobi MESSAGE IP Protection started successfully 2012/08/28 21:57:34 +0200 TOBI-PC tobi MESSAGE Starting database refresh 2012/08/28 21:57:34 +0200 TOBI-PC tobi MESSAGE Stopping IP protection 2012/08/28 21:59:36 +0200 TOBI-PC tobi MESSAGE IP Protection stopped 2012/08/28 21:59:38 +0200 TOBI-PC tobi MESSAGE Database refreshed successfully 2012/08/28 21:59:38 +0200 TOBI-PC tobi MESSAGE Starting IP protection 2012/08/28 21:59:39 +0200 TOBI-PC tobi MESSAGE IP Protection started successfully 2012/08/28 22:11:37 +0200 TOBI-PC tobi MESSAGE Executing scheduled update: Daily 2012/08/28 22:11:54 +0200 TOBI-PC tobi MESSAGE Database already up-to-date 2012/08/28 23:49:37 +0200 TOBI-PC tobi IP-BLOCK 173.241.240.153 (Type: outgoing, Port: 51218, Process: firefox.exe) 2012/08/29 00:30:54 +0200 TOBI-PC tobi IP-BLOCK 66.152.78.239 (Type: outgoing, Port: 51972, Process: firefox.exe) 2012/08/29 00:31:06 +0200 TOBI-PC tobi IP-BLOCK 66.152.78.239 (Type: outgoing, Port: 51998, Process: firefox.exe) 2012/08/29 01:23:30 +0200 TOBI-PC tobi IP-BLOCK 80.77.81.45 (Type: outgoing, Port: 54379, Process: firefox.exe) 2012/08/29 01:36:26 +0200 TOBI-PC tobi MESSAGE Starting protection 2012/08/29 01:36:30 +0200 TOBI-PC tobi MESSAGE Protection started successfully 2012/08/29 01:36:33 +0200 TOBI-PC tobi MESSAGE Starting IP protection 2012/08/29 01:36:35 +0200 TOBI-PC tobi MESSAGE IP Protection started successfully 2012/08/29 20:59:33 +0200 TOBI-PC tobi MESSAGE Starting protection 2012/08/29 20:59:35 +0200 TOBI-PC tobi MESSAGE Protection started successfully 2012/08/29 20:59:38 +0200 TOBI-PC tobi MESSAGE Starting IP protection 2012/08/29 20:59:40 +0200 TOBI-PC tobi MESSAGE IP Protection started successfully |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
so, erstmal der adwcleaner-bericht # AdwCleaner v1.801 - Logfile created 08/31/2012 at 23:13:41 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : tobi - TOBI-PC # Boot Mode : Normal # Running from : C:\Users\tobi\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : Bandoo Coordinator ***** [Files / Folders] ***** Folder Deleted : C:\Users\tobi\AppData\Local\Ilivid Player Folder Deleted : C:\Users\tobi\AppData\Local\Temp\avg@toolbar Folder Deleted : C:\Users\tobi\AppData\LocalLow\Bandoo Folder Deleted : C:\Users\tobi\AppData\LocalLow\boost_interprocess Folder Deleted : C:\Users\tobi\AppData\Roaming\Babylon Folder Deleted : C:\Users\tobi\AppData\Roaming\Bandoo Folder Deleted : C:\Users\tobi\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\tobi\AppData\Roaming\pdfforge Folder Deleted : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\extensions\ffox@bandoo.com Folder Deleted : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\extensions\plugin@yontoo.com Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Bandoo Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandoo Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Deleted : C:\Program Files (x86)\Bandoo Folder Deleted : C:\Program Files (x86)\DealPly Folder Deleted : C:\Program Files (x86)\Ilivid Folder Deleted : C:\Program Files (x86)\Yontoo File Deleted : C:\Users\tobi\AppData\Local\Temp\Searchqu.ini File Deleted : C:\Users\tobi\AppData\Local\Temp\SetupDataMngr_Searchqu.exe File Deleted : C:\Users\tobi\AppData\Local\Temp\Uninstall.exe File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml File Deleted : C:\user.js ***** [Registry] ***** Key Deleted : HKCU\Software\DealPly Key Deleted : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Babylon Key Deleted : HKLM\SOFTWARE\bandoo Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin Key Deleted : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 Key Deleted : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl Key Deleted : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 Key Deleted : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl Key Deleted : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\DealPly Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dloejdefkancmfajekobpfoacecnhpgp Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandoo Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Deleted : HKLM\SOFTWARE\Web Assistant Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [ffox@bandoo.com] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] [x64] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Deleted : HKLM\SOFTWARE\Tarma Installer [x64] Key Deleted : HKLM\SOFTWARE\Web Assistant ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{074E4EFE-81BB-4EA4-866E-082CB0E01070} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0CE5B352-9D9C-41E1-9551-FCCD92820217} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{167B2B5F-2757-434A-BBDA-2FDB2003F14F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF2B6317-C367-401B-83B8-80302D6588A7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F5379B4B-24D8-432A-9A96-BE75EE5117DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=114351&tt=201208_mnt_n_3512_3&babsrc=HP_ss&mntrId=e4a73a82000000000000206a8a34f794 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=114351&tt=201208_mnt_n_3512_3&babsrc=NT_ss&mntrId=e4a73a82000000000000206a8a34f794 --> hxxp://www.google.com -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\prefs.js C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\2zjibpqp.default\user.js ... Deleted ! Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb155?a=6R8DmV1zuD&loc=FF_NT"); Deleted : user_pref("browser.search.defaultenginename", "MyStart Search"); Deleted : user_pref("extensions.BabylonToolbar.admin", false); Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=114351&tt=201208_mnt_n_3512_3"); Deleted : user_pref("extensions.BabylonToolbar.cntry", "DE"); Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Deleted : user_pref("extensions.BabylonToolbar.dp_alert", "newBlk"); Deleted : user_pref("extensions.BabylonToolbar.envrmnt", "production"); Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false); Deleted : user_pref("extensions.BabylonToolbar.hdrMd5", "475C53185168DA8963B0934BC3F44F88"); Deleted : user_pref("extensions.BabylonToolbar.hmpg", false); Deleted : user_pref("extensions.BabylonToolbar.id", "e4a73a82000000000000206a8a34f794"); Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15579"); Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar.isdcmntcmplt", true); Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.6.9.1219:04:08"); Deleted : user_pref("extensions.BabylonToolbar.mntrvrsn", "1.3.1"); Deleted : user_pref("extensions.BabylonToolbar.newTab", false); Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar.sg", "none"); Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base"); Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...] Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12"); Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.6.9.1219:04:08"); Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.6.9.12"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=114351&tt=201208_mnt_n_3512_3"); Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false); Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1219:04:08"); Deleted : user_pref("extensions.incredibar.cntry", "DE"); Deleted : user_pref("extensions.incredibar.did", "10657"); Deleted : user_pref("extensions.incredibar.envrmnt", "production"); Deleted : user_pref("extensions.incredibar.hdrMd5", ""); Deleted : user_pref("extensions.incredibar.hmpg", false); Deleted : user_pref("extensions.incredibar.installerproductid", "26"); Deleted : user_pref("extensions.incredibar.isDcmntCmplt", true); Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1419:02:49"); Deleted : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Deleted : user_pref("extensions.incredibar.newTab", false); Deleted : user_pref("extensions.incredibar.ppd", ""); Deleted : user_pref("extensions.incredibar.productid", "26"); Deleted : user_pref("extensions.incredibar.sg", "none"); Deleted : user_pref("extensions.incredibar.smplGrp", "none"); Deleted : user_pref("extensions.incredibar.upn2", "6R8DmV1zuD"); Deleted : user_pref("extensions.incredibar.upn2n", "92824953997166463"); Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1419:02:49"); Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl"); Deleted : user_pref("extensions.incredibar_i.dfltLng", ""); Deleted : user_pref("extensions.incredibar_i.did", "10657"); Deleted : user_pref("extensions.incredibar_i.excTlbr", false); Deleted : user_pref("extensions.incredibar_i.id", "e4a73a82000000000000206a8a34f794"); Deleted : user_pref("extensions.incredibar_i.installerproductid", "26"); Deleted : user_pref("extensions.incredibar_i.instlDay", "15579"); Deleted : user_pref("extensions.incredibar_i.instlRef", ""); Deleted : user_pref("extensions.incredibar_i.ms_url_id", ""); Deleted : user_pref("extensions.incredibar_i.newTab", false); Deleted : user_pref("extensions.incredibar_i.ppd", ""); Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar"); Deleted : user_pref("extensions.incredibar_i.productid", "26"); Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Deleted : user_pref("extensions.incredibar_i.smplGrp", "none"); Deleted : user_pref("extensions.incredibar_i.tlbrId", "base"); Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8DmV1zuD&loc=IB[...] Deleted : user_pref("extensions.incredibar_i.upn2", "6R8DmV1zuD"); Deleted : user_pref("extensions.incredibar_i.upn2n", "92824953997166463"); Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1419:02:49"); Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Deleted : user_pref("keyword.URL", "hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=e4a73a82000000000000206a8a3[...] Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] ************************* AdwCleaner[R1].txt - [25295 octets] - [29/08/2012 20:52:17] AdwCleaner[S1].txt - [20858 octets] - [31/08/2012 23:13:41] ########## EOF - C:\AdwCleaner[S1].txt - [20987 octets] ########## |
Schaue bitte in der Anleitung (http://www.trojaner-board.de/103809-...i-malware.html) nach, wo du die Logfiles finden kannst. Poste das Logfile bitte. |
Emsisoft Anti-Malware - Version 6.6 Letztes Update: 01.09.2012 10:24:56 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 01.09.2012 10:26:09 Value: hkey_current_user\software\kazaa\advanced --> scanfolder gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconfile gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconpath gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> displayname gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> channelfile gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> channeltype gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconserver gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> mandatory gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> notadded gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> targeturl gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> source gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> visible gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> position gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> uninstalled gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> ssmurl gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconfile gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconpath gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> displayname gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> mandatory gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> notadded gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconserver gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> channelfile gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> ssmurl gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> position gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> source gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> visible gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> targeturl gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> uninstalled gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> adult_filter_level gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\dontshow --> closetosystray gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\localcontent --> disablelistfiles gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\transfer --> nouploadlimitwhenidle gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> firewall_filter gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\skins --> skinsdir gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> channeltype gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> autoconnected gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> countrycode gefunden: Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> username gefunden: Trace.Registry.kazaa!E1 Key: hkey_current_user\software\kazaa gefunden: Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\bandwidth\in --> b0 gefunden: Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\bandwidth\in --> b1 gefunden: Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa\connectioninfo gefunden: Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\connectioninfo --> kazaanet gefunden: Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa\localcontent gefunden: Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\localcontent --> databasedir gefunden: Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\localcontent --> downloaddir gefunden: Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa gefunden: Trace.Registry.kazaa!E1 Value: hkey_classes_root\sig2dat --> url protocol gefunden: Trace.Registry.trustyfiles!E1 Value: hkey_local_machine\software\classes\sig2dat --> url protocol gefunden: Trace.Registry.trustyfiles!E1 Value: hkey_current_user\software\kazaa\advanced --> maxsearchresult gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\localcontent --> downloaddir gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\k-lite --> installsig gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\localcontent --> disablesharing gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\advanced --> supernode gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> virus_filter gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> custom_filter_phrases gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> concurrentdownloads gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> bogus_filter gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\socks --> enabled gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> showdisableadultfilter gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa --> disableport80listen gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa --> installdir gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\k-sig --> usealternatemethod gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> corrupted gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> uploadbandwidth gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> file url gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> last update gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> days gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa\cloudload --> exedir gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> title gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> songs gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> version url gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> concurrentuploads gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> version gefunden: Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> sysscans gefunden: Trace.Registry.kazaa lite resurrection!E1 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\5db17489-3ef3d047 -> P.class gefunden: JAVA.Agent!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\5db17489-3ef3d047 -> Field.class gefunden: JAVA.Agent!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\75530ce4-61d78445 -> jgcpgy\mytdjcjdam.class gefunden: JAVA.Agent!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\75530ce4-61d78445 -> jgcpgy\blbradcaajnkluularuwvh.class gefunden: Exploit.Java.CVE!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\74f780d3-14cf9774 -> t.class gefunden: Java.Downloader.BX!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\5f85a58e-3223d01d -> ttfare\anjmhcsmfbumgmwpqwt.class gefunden: Java.CVE!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\5f85a58e-3223d01d -> ttfare\bmyfp.class gefunden: Java.Downloader.AS!E2 C:\Users\tobi\AppData\Local\Temp\YontooSetup-Silent.exe gefunden: Adware.Win32.Yontoo.AMN!E1 C:\Users\tobi\AppData\Local\Temp\YontooIEClient.dll gefunden: Adware.Win32.Yontoo.AMN!E1 C:\Users\tobi\AppData\Local\Temp\plugtmp-3\plugin-2fdp.php gefunden: Exploit.JS.Pdfka!E2 C:\Users\tobi\AppData\Local\Temp\is1566002423\MyBabylonTB.exe gefunden: Riskware.Win32.Toolbar.Babylon.AMN!E1 C:\Program Files (x86)\McAfee Security Scan\uninstall.exe gefunden: Trojan-Clicker.Win32.NSIS!E1 Gescannt 730212 Gefunden 87 Scan Ende: 01.09.2012 12:39:16 Scan Zeit: 2:13:07 C:\Program Files (x86)\McAfee Security Scan\uninstall.exe Quarantäne Trojan-Clicker.Win32.NSIS!E1 C:\Users\tobi\AppData\Local\Temp\is1566002423\MyBabylonTB.exe Quarantäne Riskware.Win32.Toolbar.Babylon.AMN!E1 C:\Users\tobi\AppData\Local\Temp\plugtmp-3\plugin-2fdp.php Quarantäne Exploit.JS.Pdfka!E2 C:\Users\tobi\AppData\Local\Temp\YontooSetup-Silent.exe Quarantäne Adware.Win32.Yontoo.AMN!E1 C:\Users\tobi\AppData\Local\Temp\YontooIEClient.dll Quarantäne Adware.Win32.Yontoo.AMN!E1 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\5f85a58e-3223d01d -> ttfare\bmyfp.class Quarantäne Java.Downloader.AS!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\74f780d3-14cf9774 -> t.class Quarantäne Java.Downloader.BX!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\75530ce4-61d78445 -> jgcpgy\blbradcaajnkluularuwvh.class Quarantäne Exploit.Java.CVE!E2 C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\5db17489-3ef3d047 -> P.class Quarantäne JAVA.Agent!E2 Value: hkey_current_user\software\kazaa\advanced --> maxsearchresult Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\localcontent --> downloaddir Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\k-lite --> installsig Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\localcontent --> disablesharing Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\advanced --> supernode Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> virus_filter Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> custom_filter_phrases Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> concurrentdownloads Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> bogus_filter Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\socks --> enabled Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> showdisableadultfilter Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa --> disableport80listen Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa --> installdir Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\k-sig --> usealternatemethod Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> corrupted Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> uploadbandwidth Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> file url Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> last update Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> days Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\kazaa\cloudload --> exedir Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> title Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> songs Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> version url Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_current_user\software\kazaa\transfer --> concurrentuploads Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> version Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_local_machine\software\mp3shield --> sysscans Quarantäne Trace.Registry.kazaa lite resurrection!E1 Value: hkey_classes_root\sig2dat --> url protocol Quarantäne Trace.Registry.trustyfiles!E1 Value: hkey_local_machine\software\classes\sig2dat --> url protocol Quarantäne Trace.Registry.trustyfiles!E1 Value: hkey_current_user\software\kazaa\advanced --> scanfolder Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconfile Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconpath Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> displayname Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> channelfile Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> channeltype Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> iconserver Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> mandatory Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> notadded Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> targeturl Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> source Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> visible Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> position Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> uninstalled Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\p2p --> ssmurl Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconfile Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconpath Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> displayname Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> mandatory Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> notadded Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> iconserver Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> channelfile Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> ssmurl Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> position Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> source Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> visible Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> targeturl Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> uninstalled Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> adult_filter_level Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\dontshow --> closetosystray Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\localcontent --> disablelistfiles Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\transfer --> nouploadlimitwhenidle Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\resultsfilter --> firewall_filter Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\skins --> skinsdir Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\channels\websearch --> channeltype Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> autoconnected Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> countrycode Quarantäne Trace.Registry.kazaa!E1 Value: hkey_current_user\software\kazaa\userdetails --> username Quarantäne Trace.Registry.kazaa!E1 Key: hkey_current_user\software\kazaa Quarantäne Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\bandwidth\in --> b0 Quarantäne Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\bandwidth\in --> b1 Quarantäne Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa\connectioninfo Quarantäne Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\connectioninfo --> kazaanet Quarantäne Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa\localcontent Quarantäne Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\localcontent --> databasedir Quarantäne Trace.Registry.kazaa!E1 Value: hkey_local_machine\software\kazaa\localcontent --> downloaddir Quarantäne Trace.Registry.kazaa!E1 Key: hkey_local_machine\software\kazaa Quarantäne Trace.Registry.kazaa!E1 Quarantäne 84 |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=8a51307ac7db6647b26c1e5d9101d296 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-09-02 12:37:21 # local_time=2012-09-02 02:37:21 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5121 16777213 100 75 523947 863244 0 0 # compatibility_mode=5893 16776574 66 85 37104589 98207992 0 0 # compatibility_mode=8192 67108863 100 0 180 180 0 0 # scanned=283173 # found=8 # cleaned=8 # scan_time=11298 C:\Users\tobi\AppData\Local\Temp\BandooV6.exe multiple threats (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\AppData\Local\Temp\U9nqfrrf.exe.part probably a variant of Win32/Adware.EHJCQJF application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\AppData\Local\Temp\YontooFFClient.xpi Win32/Adware.Yontoo application (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\Downloads\BestVideoDownloaderSetup(1).exe probably a variant of Win32/Adware.EHJCQJF application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\Downloads\BestVideoDownloaderSetup.exe probably a variant of Win32/Adware.EHJCQJF application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\Downloads\SoftonicDownloader_fuer_kalenderchen.exe Win32/SoftonicDownloader.C application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\Downloads\SoftonicDownloader_fuer_scummvm.exe a variant of Win32/SoftonicDownloader.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\tobi\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/InstallCore.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C |
CustomScan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code: netsvcs
|
OTL Logfile: Code: OTL logfile created on: 03.09.2012 12:33:45 - Run 2 |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}\ deleted successfully. File move failed. c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll scheduled to be moved on reboot. HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AB89AC78-CE96-467A-BE3F-BD3E4DB165BB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB89AC78-CE96-467A-BE3F-BD3E4DB165BB}\ not found. HKU\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://www.yahoo.de/" removed from browser.startup.homepage Prefs.js: "file:///C:\\Users\\tobi\\AppData\\Local\\Temp\\proxtube.pac" removed from network.proxy.autoconfig_url Prefs.js: 4 removed from network.proxy.type 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\bandoo\bndhook.dll deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! File move failed. D:\Autorun.inf scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fd3b846-48d1-11e0-a40a-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fd3b846-48d1-11e0-a40a-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fd3b846-48d1-11e0-a40a-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fd3b846-48d1-11e0-a40a-806e6f6e6963}\ not found. File move failed. D:\ESRI.exe scheduled to be moved on reboot. ADS C:\ProgramData\Temp:CDFF58FE deleted successfully. ADS C:\ProgramData\Temp:0B9176C0 deleted successfully. ========== FILES ========== C:\Users\tobi\AppData\Local\{20A5A887-72FE-4E08-A55F-2E1FC04A4422} folder moved successfully. C:\ProgramData\FullRemove.exe moved successfully. C:\ProgramData\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8} folder moved successfully. C:\ProgramData\Temp folder moved successfully. C:\Users\tobi\AppData\Local\Temp\7za.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\CommonInstaller.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\contentDATs.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\EAD4C02.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\MachineIdCreator.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\MSN8154.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\oi_{CD7355B3-BC35-4C8A-9008-51C74DAEEED0}.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\ose00000.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\rootsupd.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\SecurityScan_Release.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\Setup.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\SkypeSetup.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\ToolbarInstaller.exe moved successfully. C:\Users\tobi\AppData\Local\Temp\vcredist_x64.exe moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\tobi\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. File/Folder C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. File/Folder C:\Windows\System32\*.tmp not found. File/Folder C:\Windows\SysWOW64\*.tmp not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\tobi\Desktop\cmd.bat deleted successfully. C:\Users\tobi\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: tobi ->Temp folder emptied: 4477712040 bytes ->Temporary Internet Files folder emptied: 661007071 bytes ->FireFox cache emptied: 1245691412 bytes ->Flash cache emptied: 204736 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 551611627 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 34960 bytes RecycleBin emptied: 3328500676 bytes Total Files Cleaned = 9.789,00 mb OTL by OldTimer - Version 3.2.60.0 log created on 09032012_215406 Files\Folders moved on Reboot... File move failed. c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll scheduled to be moved on reboot. File move failed. D:\Autorun.inf scheduled to be moved on reboot. File move failed. D:\ESRI.exe scheduled to be moved on reboot. C:\Users\tobi\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Alle Zeitangaben in WEZ +1. Es ist jetzt 21:17 Uhr. |
Copyright ©2000-2025, Trojaner-Board