![]() |
My Start - Incredibar-Ich krieg ihn nicht weg. Hallo, im Forum steht ja schon so mancher tip, aber ich habe leider trotzdem noch immer incredibar.com als startseite wenn ich tabs öffne. zwar ist es bei addons und auch in der systemsteuerung raus, aber leider noch nicht bei tabs. ich habe folgendes schon gemacht: malwarebytes: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.09.08.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Daivoon :: DAIVOON-PC [Administrator] Schutz: Aktiviert 08.09.2012 17:25:31 mbam-log-2012-09-08 (17-25-31).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 226034 Laufzeit: 2 Minute(n), 43 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) danach hab ich noch adware cleaner laufen lassen AdwCleaner v2.000 - Datei am 09/08/2012 um 17:24:41 erstellt # Aktualisiert am 30/08/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Daivoon - DAIVOON-PC # Normaler Modus : Normal # Ausgeführt unter : C:\Users\Daivoon\Downloads\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\user.js Datei Gefunden : C:\Users\Daivoon\AppData\Roaming\Mozilla\Firefox\Profiles\39kf9qu1.default\extensions\toolbar@alexa.com.xpi Ordner Gefunden : C:\Users\Daivoon\AppData\Local\Software Ordner Gefunden : C:\Users\Daivoon\AppData\Roaming\pdfforge ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\IM Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gefunden : HKLM\Software\Web Assistant Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Web Assistant Schlüssel Gefunden : HKU\S-1-5-21-4091172970-1133717160-3061418228-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb174?a=6OyNuoUQdq&i=26 -\\ Mozilla Firefox v15.0.1 (de) Profilname : default Datei : C:\Users\Daivoon\AppData\Roaming\Mozilla\Firefox\Profiles\39kf9qu1.default\prefs.js Gefunden : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb174?a=6OyNuoUQdq&loc=FF_NT"); Gefunden : user_pref("browser.search.defaultenginename", "MyStart Search"); Gefunden : user_pref("browser.search.selectedEngine", "MyStart Search"); Gefunden : user_pref("extensions.alexa.toolbarXMLText", "<?xml version=\"1.0\" encoding=\"utf-8\"?>\n<toolbar>\[...] Gefunden : user_pref("extensions.incredibar.actvtyRptTime", "1347101275031"); Gefunden : user_pref("extensions.incredibar.admin", false); Gefunden : user_pref("extensions.incredibar.aflt", "orgnl"); Gefunden : user_pref("extensions.incredibar.afterInstallRpt", "sent"); Gefunden : user_pref("extensions.incredibar.cntry", "ES"); Gefunden : user_pref("extensions.incredibar.dfltLng", "EN"); Gefunden : user_pref("extensions.incredibar.dfltSrch", false); Gefunden : user_pref("extensions.incredibar.dfltlng", "en"); Gefunden : user_pref("extensions.incredibar.dfltsrch", "false"); Gefunden : user_pref("extensions.incredibar.did", "10671"); Gefunden : user_pref("extensions.incredibar.envrmnt", "production"); Gefunden : user_pref("extensions.incredibar.excTlbr", false); Gefunden : user_pref("extensions.incredibar.hdrMd5", "53BBAEF47A95E0BB449BA7E5900C415A"); Gefunden : user_pref("extensions.incredibar.hmpg", false); Gefunden : user_pref("extensions.incredibar.hrdid", "54f104400000000000003860773d1449"); Gefunden : user_pref("extensions.incredibar.id", "54f104400000000000003860773d1449"); Gefunden : user_pref("extensions.incredibar.installerproductid", "26"); Gefunden : user_pref("extensions.incredibar.instlDay", "15591"); Gefunden : user_pref("extensions.incredibar.instlRef", ""); Gefunden : user_pref("extensions.incredibar.instlday", "15591"); Gefunden : user_pref("extensions.incredibar.instlref", ""); Gefunden : user_pref("extensions.incredibar.isDcmntCmplt", true); Gefunden : user_pref("extensions.incredibar.isdcmntcmplt", "false"); Gefunden : user_pref("extensions.incredibar.keywordurl", ""); Gefunden : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1411:47:38"); Gefunden : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Gefunden : user_pref("extensions.incredibar.newTab", false); Gefunden : user_pref("extensions.incredibar.newtab", "false"); Gefunden : user_pref("extensions.incredibar.newtaburl", ""); Gefunden : user_pref("extensions.incredibar.noFFXTlbr", false); Gefunden : user_pref("extensions.incredibar.ppd", "77777174"); Gefunden : user_pref("extensions.incredibar.prdct", "incredibar"); Gefunden : user_pref("extensions.incredibar.productid", "26"); Gefunden : user_pref("extensions.incredibar.prtnrId", "Incredibar"); Gefunden : user_pref("extensions.incredibar.prtnrid", "Incredibar"); Gefunden : user_pref("extensions.incredibar.sg", "none"); Gefunden : user_pref("extensions.incredibar.smplGrp", "none"); Gefunden : user_pref("extensions.incredibar.smplgrp", "none"); Gefunden : user_pref("extensions.incredibar.srch", ""); Gefunden : user_pref("extensions.incredibar.srchprvdr", ""); Gefunden : user_pref("extensions.incredibar.tlbrId", "base"); Gefunden : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyNuoUQdq&loc=IB_T[...] Gefunden : user_pref("extensions.incredibar.tlbrid", "base"); Gefunden : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6OyNuoUQdq&loc=IB_T[...] Gefunden : user_pref("extensions.incredibar.upn2", "6OyNuoUQdq"); Gefunden : user_pref("extensions.incredibar.upn2n", "92262070517144912"); Gefunden : user_pref("extensions.incredibar.vrsn", "1.5.11.14"); Gefunden : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1411:47:38"); Gefunden : user_pref("extensions.incredibar.vrsni", "1.5.11.14"); Gefunden : user_pref("extensions.incredibar.vrsnts", "1.5.11.1411:47:38"); Gefunden : user_pref("extensions.incredibar_i.aflt", "orgnl"); Gefunden : user_pref("extensions.incredibar_i.dfltLng", ""); Gefunden : user_pref("extensions.incredibar_i.did", "10671"); Gefunden : user_pref("extensions.incredibar_i.excTlbr", false); Gefunden : user_pref("extensions.incredibar_i.id", "54f104400000000000003860773d1449"); Gefunden : user_pref("extensions.incredibar_i.installerproductid", "26"); Gefunden : user_pref("extensions.incredibar_i.instlDay", "15591"); Gefunden : user_pref("extensions.incredibar_i.instlRef", ""); Gefunden : user_pref("extensions.incredibar_i.ms_url_id", ""); Gefunden : user_pref("extensions.incredibar_i.newTab", false); Gefunden : user_pref("extensions.incredibar_i.ppd", "77777174"); Gefunden : user_pref("extensions.incredibar_i.prdct", "incredibar"); Gefunden : user_pref("extensions.incredibar_i.productid", "26"); Gefunden : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Gefunden : user_pref("extensions.incredibar_i.smplGrp", "none"); Gefunden : user_pref("extensions.incredibar_i.tlbrId", "base"); Gefunden : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyNuoUQdq&loc=IB[...] Gefunden : user_pref("extensions.incredibar_i.upn2", "6OyNuoUQdq"); Gefunden : user_pref("extensions.incredibar_i.upn2n", "92262070517144912"); Gefunden : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Gefunden : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1411:47:38"); Gefunden : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Gefunden : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6OyNuoUQdq&&i=26&search="[...] Gefunden : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] ************************* AdwCleaner[R1].txt - [7959 octets] - [08/09/2012 17:19:23] AdwCleaner[R2].txt - [7898 octets] - [08/09/2012 17:24:41] ########## EOF - C:\AdwCleaner[R2].txt - [7958 octets] ########## und zum schluss noch otl by old timerOTL Logfile: Code: OTL logfile created on: 08.09.2012 17:28:48 - Run 1 leider immer noch das gleiche problem. und nur zu aller erst mit malware hat der scan überhaupt was gefunden. was allerdings glaub ich nicht incedibar war. hoffe mir kann jemand helfen. ich ärgere mich schwarz das ich unabsichtlich die toolbar installiert hab. danke im voraus, liebe grüße amphitrite |
:hallo: Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 4 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern mede dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
4. Schritt
|
Schritt 1: gemacht, allerdings hat der neustart nicht funktioniert! ich habe nach 3h den computer abgewürgt und erst danach ist er neu gestartet. habe ihn im normalen modus gestartet und otb ist zu folgendem ergebniss gekommen All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-4091172970-1133717160-3061418228-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKEY_USERS\S-1-5-21-4091172970-1133717160-3061418228-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-4091172970-1133717160-3061418228-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found. HKU\S-1-5-21-4091172970-1133717160-3061418228-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "MyStart Search" removed from browser.search.defaultenginename Prefs.js: "MyStart Search" removed from browser.search.selectedEngine Prefs.js: false removed from browser.search.suggest.enabled Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "www.google.at" removed from browser.startup.homepage Prefs.js: toolbar@alexa.com:2.15 removed from extensions.enabledAddons Prefs.js: wrc@avast.com:7.0.1466 removed from extensions.enabledAddons Prefs.js: ffe_ff3aeroff4@game-point.net:2.0.1 removed from extensions.enabledAddons Prefs.js: "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6OyNuoUQdq&&i=26&search=" removed from keyword.URL 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found. File C:\Program Files\WEB ASSISTANT\Firefox not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. C:\Users\Daivoon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk moved successfully. C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\Windows\SysWOW64\config.nt moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml moved successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. C:\ProgramData\Temp\{E8E37C4F-DE01-4286-AFB6-9FBEC8265A1A} folder moved successfully. C:\ProgramData\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41} folder moved successfully. C:\ProgramData\Temp\{37126D87-E4FD-4614-B908-A0BB7ECE3992} folder moved successfully. C:\ProgramData\Temp\{14C4C3B6-F1F4-401F-8C86-03E8E19AAC8C} folder moved successfully. C:\ProgramData\Temp folder moved successfully. C:\Users\Daivoon\AppData\Local\{041FA7A7-7733-4FAF-883A-E7087A134489} folder moved successfully. C:\Users\Daivoon\AppData\Local\{122781E7-E4A4-4E54-AF3E-76766C02FDF7} folder moved successfully. C:\Users\Daivoon\AppData\Local\{6E9171EB-97DA-4974-B86D-BAD49A494BF3} folder moved successfully. C:\Users\Daivoon\AppData\Local\{7EF848BF-55D8-49AC-BC09-7737DD70EFD9} folder moved successfully. C:\Users\Daivoon\AppData\Local\{C1C7B54D-4492-4057-8F8C-68DB9A068FCB} folder moved successfully. C:\Users\Daivoon\AppData\Local\{DA19772C-B362-4088-A395-93A90F72A6D5} folder moved successfully. C:\Users\Daivoon\AppData\Local\{FF3E2DBA-570D-4A28-B005-AA18072BEAD1} folder moved successfully. C:\Users\Daivoon\AppData\Local\Temp\COMAP.EXE moved successfully. C:\Users\Daivoon\AppData\Local\Temp\Foxit Updater.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\incredibar_installer.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\MyBabylonTB_google_20120807.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\ose00000.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\qc_a402013b_7656_4f6f_b57f_5a8ef69f5fc4_32.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\SkypeSetup.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\UpdateCheckerSetup.exe moved successfully. C:\Users\Daivoon\AppData\Local\Temp\vlc-2.0.2-win32.exe moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Daivoon\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. File/Folder C:\Users\Daivoon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Daivoon\Desktop\cmd.bat deleted successfully. C:\Users\Daivoon\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Daivoon ->Temp folder emptied: 995872996 bytes ->Temporary Internet Files folder emptied: 267897327 bytes ->FireFox cache emptied: 145467576 bytes ->Flash cache emptied: 78457 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Invitado ->Temp folder emptied: 151744 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56543 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 181952025 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 63163 bytes RecycleBin emptied: 6870048477 bytes Total Files Cleaned = 8.070,00 mb OTL by OldTimer - Version 3.2.61.2 log created on 09082012_193827 Files\Folders moved on Reboot... C:\Users\Daivoon\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot. File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... ich hoffe soweit ist das schonmal ok ich habe jetzt leider schritt 2 schon gemacht, da ich zu spät gelesen habe, ich solle warten wenn otb nicht komplett fehlerfrei durchläuft. 1 bedrohung gefunden und in container verschoben, die scheint allerdings nichts mit dem eigentlichen problem zu tun zu haben. soll ich weitermachen? vielen vielen dank auf alle fälle für die hilfe! Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2012.09.08.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Daivoon :: DAIVOON-PC [Administrator] Schutz: Aktiviert 08.09.2012 23:51:59 mbam-log-2012-09-08 (23-51-59).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 370443 Laufzeit: 33 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 D:\Programme\Corel Draw X6\CorelDRAW Graphics Suite X6 16.0.0.707 (32 bit) (keygen-CORE) [ChingLiu]\Keygen-CORE\keygen.exe (RiskWare.Tool.HCK) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
Zitat:
Schon mal darueber nachgedacht, warum es Cracks gibt? Mit Cracks & Co installiert man sich Hintertueren auf dem Rechner. Kriminelle nutzen solche Rechner als Botnetz fuer ihre Machenschaften. Dein System ist als nicht vertrauenswuerdig einzustufen und du solltest keine sensiblen Sachen wie Homebanking an dem PC betreiben. Anleitungen zum Neuaufsetzen (bebildert) > Windows 7 neu aufsetzen > Vista > XP 1. Datenrettung:
2. Formatieren, Windows neu instalieren:
3. PC absichern: http://www.trojaner-board.de/96344-a...-rechners.html ich werde außerdem noch weitere punkte dazu posten. 4. alle Passwörter ändern! 5. nach PC Absicherung, die gesicherten Daten prüfen und falls sauber: zurückspielen. |
kein anderer weg als neu aufsetzen? ich will doch nur den incredibar loswerden danke trotzdem für die hilfe! |
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 19:25 Uhr. |
Copyright ©2000-2025, Trojaner-Board