![]() |
Probleme durch 'Bundesministerium'-Trojaner - OTL startet nicht (abges. Modus) Verehrte Forengemeinde, es ist mein Netbook offenbar mit einem Virus oder Trojaner infiziert worden: Es erscheint eine Seite des Bundesministerium mit Inhalten wegen urheberrechtlichen Angelegenheiten. Ausschalten und Neustart des Systems bringt dann eine weiße blanke Seite. Ich kann zwar im abgesicherten Modus starten aber die hier im Forum empfohlene Anwendung OTL startet nur das erste Fenster. Nach klick auf Scan tut sich nichts. Damit kann ich hier keinen Logfile posten. Aktuell lasse ich gerade Spybot durchlaufen habe aber Zweifel ob dieses Programm hier wirklich hilfreich ist. Ist meine Hoffnung hier auf Hilfe zu hoffen berechtigt? Ich danke allen Lesern für die genommene Zeit und allen Tippgeber oder Helfern aurichtig für jeden Hinweis. |
:hallo: Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Gelesen und verstanden? Schritt 1: Deinstalliere Spybot! Schritt 2: Scan mit Combofix
|
Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen |
Frohe Weihnachten, ryder, Hier nun also das log und: Mein Dank: 1. ABFRAGE WIEDERHERSTELLUNGSKONSOLE - ZUGELASSEN. MELDUNG: DU SCHEINST NICHT MIT DEM INTERNET VERBUNDEN ZU SEIN.... INTERNETVERBINDUNG HERSTELLEN BEVOR DU AUF OK KLICKST. ANMERKUNG DEFINITIV: FALSCH. INTERNETVERBINDUNG VORHANDEN - ÜBERTRAGUNGSSTÄRKE: HERVORRAGEND 2. HERUNTERLADEN DER BENÖTIGTEN DATEIEN FEHLGESCHLAGEN. BRECHE AB ... WERDE MIT DEM SUCHLAUF NACH MALEWARE FORTFAHREN. OK > OK GEKLICKT 3.Combofix Logfile: Code: ComboFix 12-12-20.02 - Daniel 12/21/2012 15:29:18.1.2 - x86 |
Dann haben wir eine Alternative: Gehe auf die Mircosoft Seite => http://support.microsoft.com/?scid=kb%3Bde%3B310994&x=21&y=12 Wähle den Download, der für dein Betriebssystem bestimmt ist: Hinweis: Für WinXP Sp3 wähle die Sp2 Version. http://i94.photobucket.com/albums/l8...ungskonsol.png Lade die Datei herunter und speichere diese mit dem original Namen, neben ComboFix.exe ab. http://i94.photobucket.com/albums/l8...onsole_ani.gif Nun schließe alle offenen Programme und Fenster, inklusive der Antiviren und Antimalware Programme. Dies ist notwendig, damit kein Program den Suchlauf von ComboFix behindert.
|
ryder, nun folgende Meldung: ComboFix hat festgestellt .... antivirus: Avira Desktop Antivirus: avast! Antivirus Ich: Alles abgesucht: START > Programme systemsteuerung > Programme > installieren/deinstalliere START > Suche nix, nirgendwo eines der angemahnten Programme zu finden. Taskleiste: negativ Desktop: negativ und nun??? Den step, das SP auf dem Desktop abzugespeichert und in den Katzenicon zu ziehen haben ich absolviert. mensch, Trojaner aufs netbook, Hackerattacken, Weihnachtsstress und nun soll ich auch noch die Hilfsbereitschaft eines Fremden kurz vor Weihnachten über Gebühr strapazieren.... Tut mir leid. CF fragt mich nun auf eigene verantwortung weiterzu machen. Mache ich nun. Auf eigene Verantwortung. LOG folgt also. Combofix Logfile: Code: ComboFix 12-12-20.02 - Daniel 12/21/2012 17:38:25.2.2 - x86 |
Du musst nur richtig lesen. CF meckert manchmal auch wenn alles deaktiviert ist. So, dann wollen wir mal sehen .... Schritt 1: AdwCleaner: Werbeprogramme suchen und löschen
Schritt 2: Temporäre Dateien löschen mit TFC
Schritt 3: Noch mal Combofix bitte. |
aha, okee. Das klingt beruhigend. Prima. Morgen werde ich dazukommen Deinen Anweisungen Adw, Tfc und nochmal CF zu folgen. Steht einem eine derart sachliche und umgehende Hilfe zu Seite, fühlt sich das gut gut. Für heute einen angenehmen Abend und vielen Dank. (Thread bitte noch nicht schließen) |
Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist |
Entschuldige die Verzögerung: Empfehlung angewendet wie folgt: 1. ADW CLEANER (logfile nachstehend) 2. TF (System wurde einmal neugestartet) 3. NOCHMAL CF (log untenstehend) Adwcleaner-Inhalt: # AdwCleaner v2.102 - Logfile created 12/24/2012 at 12:31:41 # Updated 23/12/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Daniel - STEFANIE # Boot Mode : Normal # Running from : C:\Documents and Settings\Daniel\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whxrf7qe.default\searchplugins\11-suche.xml File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whxrf7qe.default\searchplugins\Web Search.xml File Deleted : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\bprotector_extensions.sqlite File Deleted : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\searchplugins\11-suche.xml File Deleted : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\searchplugins\Web Search.xml File Deleted : C:\Documents and Settings\nbfa\Application Data\Mozilla\Firefox\Profiles\87f7fvnj.default\searchplugins\11-suche.xml File Deleted : C:\Documents and Settings\nimo\Application Data\Mozilla\Firefox\Profiles\a01pgjyw.default\bprotector_extensions.sqlite File Deleted : C:\Documents and Settings\nimo\Application Data\Mozilla\Firefox\Profiles\a01pgjyw.default\searchplugins\Web Search.xml File Deleted : C:\Documents and Settings\Stef\Application Data\Mozilla\Firefox\Profiles\xl4rikme.default-1348241791359\searchplugins\11-suche.xml File Deleted : C:\Documents and Settings\Stef\Application Data\Mozilla\Firefox\Profiles\xl4rikme.default-1348241791359\searchplugins\Web Search.xml Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whxrf7qe.default\extensions\crossriderapp5060@crossrider.com Folder Deleted : C:\Documents and Settings\Daniel\Application Data\loadtbs Folder Deleted : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\extensions\crossriderapp5060@crossrider.com Folder Deleted : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\extensions\software@loadtubes.com Folder Deleted : C:\Documents and Settings\nbfa\Application Data\Mozilla\Firefox\Profiles\87f7fvnj.default\extensions\staged Folder Deleted : C:\Documents and Settings\nimo\Application Data\Mozilla\Firefox\Profiles\a01pgjyw.default\extensions\crossriderapp5060@crossrider.com Folder Deleted : C:\Documents and Settings\Stef\Application Data\Mozilla\Firefox\Profiles\xl4rikme.default-1348241791359\extensions\crossriderapp5060@crossrider.com ***** [Registry] ***** Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\Claro LTD Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\InstalledBrowserExtensions Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055505560} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066506660} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044504460} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://newtab.certified-toolbar.com/nie?si=41460&tid=2937&new=true --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= --> hxxp://www.google.com -\\ Mozilla Firefox v17.0.1 (de) File : C:\Documents and Settings\Stef\Application Data\Mozilla\Firefox\Profiles\xl4rikme.default-1348241791359\prefs.js Deleted : user_pref("browser.search.defaultengine", "Web Search"); Deleted : user_pref("browser.search.defaultenginename", "Web Search"); Deleted : user_pref("browser.search.order.1", "Web Search"); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1355413092); Deleted : user_pref("extensions.crossriderapp5060.5060.active", true); Deleted : user_pref("extensions.crossriderapp5060.5060.addressbar", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG_NEW&&[...] Deleted : user_pref("extensions.crossriderapp5060.5060.backgroundver", 7); Deleted : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true); Deleted : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.changeprevious", false); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1355413092"); Deleted : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick"); Deleted : user_pref("extensions.crossriderapp5060.5060.domain", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.enablesearch", false); Deleted : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.group", 0); Deleted : user_pref("extensions.crossriderapp5060.5060.homepage", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.iframe", false); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "40"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Thu Dec 13[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...] Deleted : user_pref("extensions.crossriderapp5060.5060.manifesturl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick"); Deleted : user_pref("extensions.crossriderapp5060.5060.newtab", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.opensearch", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 7); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 4); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "if((typeof isBackground===\"u[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 4); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...] Deleted : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...] Deleted : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 16); Deleted : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps"); Deleted : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0); Deleted : user_pref("extensions.crossriderapp5060.5060.setnewtab", false); Deleted : user_pref("extensions.crossriderapp5060.5060.settingsurl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.thankyou", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360); Deleted : user_pref("extensions.crossriderapp5060.5060.ver", 40); Deleted : user_pref("extensions.crossriderapp5060.apps", "5060"); Deleted : user_pref("extensions.crossriderapp5060.bic", "13ab35e2f2a7f290832f97b2eac5b6e9"); Deleted : user_pref("extensions.crossriderapp5060.cid", 5060); Deleted : user_pref("extensions.crossriderapp5060.firstrun", false); Deleted : user_pref("extensions.crossriderapp5060.hadappinstalled", true); Deleted : user_pref("extensions.crossriderapp5060.installationdate", 1355413088); Deleted : user_pref("extensions.crossriderapp5060.lastcheck", 22590218); Deleted : user_pref("extensions.crossriderapp5060.lastcheckitem", 22590222); Deleted : user_pref("extensions.crossriderapp5060.modetype", "production"); Deleted : user_pref("extensions.crossriderapp5060.reportInstall", true); Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q="); File : C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\wlzwr0sm.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Web Search"); Deleted : user_pref("browser.search.defaultenginename", "Web Search"); Deleted : user_pref("browser.search.order.1", "Web Search"); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationThankYouPage", true); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1351103191); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.searchUserConifrmation", false[...] Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setHomepage", false); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setNewTab", false); Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setSearch", false); Deleted : user_pref("extensions.crossriderapp5060.5060.active", true); Deleted : user_pref("extensions.crossriderapp5060.5060.addressbar", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG_NEW&&[...] Deleted : user_pref("extensions.crossriderapp5060.5060.backgroundver", 7); Deleted : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true); Deleted : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.changeprevious", false); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1351103191"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.value", "1351103191"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.expiration", "Fri Nov 30 2012 18:[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.value", "%22nonexistantdomain.com[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.expiration", "Sun Dec 02 2012 [...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.value", "%22DE%22"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.value", "1354295571"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.value", "%221%22"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.value", "%7B%22source_id%2[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.value", "%2214019%22"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.value", "1353852501763"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.value", "%221224%22"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.value", "%2297646%22"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.value", "1353852487519"); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.lastrequest.expiration", "Fri Feb 01 2030 00:00:[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.lastrequest.value", "%7B%22path%22%3A%22/raylene[...] Deleted : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick"); Deleted : user_pref("extensions.crossriderapp5060.5060.domain", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.enablesearch", false); Deleted : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.group", 0); Deleted : user_pref("extensions.crossriderapp5060.5060.homepage", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.iframe", false); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.value", "%7B%22installe[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "38"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Sat Dec 01[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.expiration", "Fri[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.value", "%7B%22re[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.SoftwareDetected.expiration", "Fri Feb 01 20[...] Deleted : user_pref("extensions.crossriderapp5060.5060.internaldb.SoftwareDetected.value", "%7B%22AnySoftware%[...] Deleted : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...] Deleted : user_pref("extensions.crossriderapp5060.5060.manifesturl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick"); Deleted : user_pref("extensions.crossriderapp5060.5060.newtab", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.opensearch", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 7); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 4); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "if((typeof isBackground===\"u[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 4); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...] Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015"); Deleted : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...] Deleted : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...] Deleted : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 16); Deleted : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps"); Deleted : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0); Deleted : user_pref("extensions.crossriderapp5060.5060.setnewtab", false); Deleted : user_pref("extensions.crossriderapp5060.5060.settingsurl", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.thankyou", ""); Deleted : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360); Deleted : user_pref("extensions.crossriderapp5060.5060.ver", 38); Deleted : user_pref("extensions.crossriderapp5060.apps", "5060"); Deleted : user_pref("extensions.crossriderapp5060.bic", "13a94072196fa53aa47a365095f8a893"); Deleted : user_pref("extensions.crossriderapp5060.cid", 5060); Deleted : user_pref("extensions.crossriderapp5060.firstrun", false); Deleted : user_pref("extensions.crossriderapp5060.hadappinstalled", true); Deleted : user_pref("extensions.crossriderapp5060.installationdate", 1353843272); Deleted : user_pref("extensions.crossriderapp5060.lastcheck", 22571591); Deleted : user_pref("extensions.crossriderapp5060.lastcheckitem", 22571600); Deleted : user_pref("extensions.crossriderapp5060.modetype", "production"); Deleted : user_pref("extensions.crossriderapp5060.reportInstall", true); File : C:\Documents and Settings\nimo\Application Data\Mozilla\Firefox\Profiles\a01pgjyw.default\prefs.js Deleted : user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=41460&home=true&tid=29[...] Deleted : user_pref("extensions.crossriderapp5060.bic", "13ab8232c104b729506742f49b32eeb7"); Deleted : user_pref("extensions.crossriderapp5060.firstrun", false); Deleted : user_pref("extensions.crossriderapp5060.installationdate", 1353953300); Deleted : user_pref("extensions.enabledAddons", "crossriderapp5060@crossrider.com:0.86.38,{972ce4c6-7e08-4474-[...] Deleted : user_pref("browser.search.defaultenginename", "Web Search"); Deleted : user_pref("browser.search.defaultengine", "Web Search"); Deleted : user_pref("browser.search.selectedEngine", "Web Search"); Deleted : user_pref("browser.newtab.url", "hxxp://newtab.certified-toolbar.com/nff?si=41460&tid=2937&new=true"[...] Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q="); Deleted : user_pref("browser.search.order.1", "Web Search"); File : C:\Documents and Settings\nbfa\Application Data\Mozilla\Firefox\Profiles\87f7fvnj.default\prefs.js [OK] File is clean. File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whxrf7qe.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Web Search"); Deleted : user_pref("browser.search.defaultenginename", "Web Search"); Deleted : user_pref("browser.search.order.1", "Web Search"); Deleted : user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=41460&home=true&tid=29[...] Deleted : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1355409230); Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...] Deleted : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1355409230"); Deleted : user_pref("extensions.crossriderapp5060.bic", "13b94af87c9b745277314ee9e545a29a"); Deleted : user_pref("extensions.crossriderapp5060.firstrun", false); Deleted : user_pref("extensions.crossriderapp5060.installationdate", 1355409230); Deleted : user_pref("extensions.crossriderapp5060.lastcheck", 22590154); Deleted : user_pref("extensions.crossriderapp5060.lastcheckitem", 22590154); Deleted : user_pref("extensions.crossriderapp5060.reportInstall", true); Deleted : user_pref("extensions.enabledAddons", "crossriderapp5060%40crossrider.com:0.85.36,%7B411beae9-8c58-4[...] Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q="); -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Stef\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.4] : homepage = "hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937", Deleted [l.5] : homepage =rowser":{"show_home_button":true,"window_placement":{"bottom":568,"left":2,"maximized":false,"right"[...] File : C:\Documents and Settings\Daniel\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.4] : homepage = "hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937", ************************* AdwCleaner[R1].txt - [46703 octets] - [25/11/2012 12:09:16] AdwCleaner[S1].txt - [47092 octets] - [25/11/2012 12:21:46] AdwCleaner[S2].txt - [34510 octets] - [24/12/2012 12:31:41] ########## EOF - C:\AdwCleaner[S2].txt - [34571 octets] ########## ABSCHLIESSEND NOCHMAL CF WIE EMPFOHLEN _ INHALT NACHFOLGEND Combofix Logfile: Code: ComboFix 12-12-20.02 - Daniel 12/24/2012 12:45:29.3.2 - x86 |
Schritt 1: Warnung: Mehrere Anti-Virus-Programme Ich würde Avira entfernen. Schritt 2: Combofix nochmal laufen lassen und mir dann ALLE Logfiles posten die du unter c:\qoobox findest. |
Anhang 47767 Anhang 47768 Anhang 47769 Anhang 47770 Anhang 47771 Anhang 47772 Lieber ryder, unter Start Systemsteuerung > Programme+Funktionen > ist nach wie vor kein Avira und kein anderes Sicherheitsprogramm mehr. Die Schritte unter dem empfohlenen Link empfehlen Start - Control Panel - Uninstall a program Remove Press Yes, to confirm the removal and then OK. Click Next until Finish. The software is removed. Das hatte ich bereits diese Woche getan daher auch unter dem o.g. Schritt kein Programm mehr. aswclear.exe (AVAST) folgendes Problem: Fährt sich herunter (auto), startet neu, meldet das das programm im abges. gestartet wird fragt nach ok, bei ok fährt herunter, startet neu, meldet wieder die safetymodus frage, bestätigt man mit ok das gleiche Spiel von vorne. Files und ein screenshot anbei. Zwischendurch: Schöne Weihnachten. |
Okay, dann deinstalliere noch Spybot. Welchen Virenscanner hast du denn jetzt installiert? Avast? AVG? |
Ausserdem: Weißt du zufällig was das hier sein könnte ich finde dazu nichts ... Zitat:
|
Zitat:
Zitat:
Deinstallieren? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:56 Uhr. |
Copyright ©2000-2025, Trojaner-Board