Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Werbe Tabs öffnen sich in Firefox (https://www.trojaner-board.de/145823-werbe-tabs-oeffnen-firefox.html)

aharonov 13.01.2014 19:54

Also ist der Scan nicht durchgelaufen?

ThunderX 13.01.2014 20:16

Doch der ist durchgelaufen, aber erst nach sehr langer Zeit, der Fehler oben ist mehrmals aufgetreten

Code:

Zoek.exe v5.0.0.0 Updated 09-Januari-2014
Tool run by user on 12.01.2014 at 19:58:19,71.
Microsoft Windows 8.1 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\usr1\Downloads\zoek\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

12.01.2014 19:59:16 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\usr2\AppData\Roaming\Mozilla\Firefox\Profiles\20achfvp.default\prefs.js:

Added to C:\Users\usr2\AppData\Roaming\Mozilla\Firefox\Profiles\20achfvp.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\usr1\AppData\Roaming\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\prefs.js:

Added to C:\Users\usr1\AppData\Roaming\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\trk79v17.default\prefs.js:

Added to C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\trk79v17.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\usr3\AppData\Roaming\Mozilla\Firefox\Profiles\x88fm5vb.default\prefs.js:

Added to C:\Users\usr3\AppData\Roaming\Mozilla\Firefox\Profiles\x88fm5vb.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Deleting Files \ Folders ======================

C:\WINDOWS\SysWow64\AI_RecycleBin deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" []

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://acer13.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://acer13.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} Unknown  Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3055901358-908682401-1845398182-1001\Software\Microsoft\Internet Explorer\SearchScopes\{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} deleted successfully
HKEY_USERS\S-1-5-21-3055901358-908682401-1845398182-1002\Software\Microsoft\Internet Explorer\SearchScopes\{50879D8F-1AF2-43CB-BA3D-9E5E4AD6EF36} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\usr2\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr1\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr1\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr3\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\usr3\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\usr2\AppData\Local\Mozilla\Firefox\Profiles\20achfvp.default\Cache emptied successfully
C:\Users\usr1\AppData\Local\Mozilla\Firefox\Profiles\994orcq1.default-1386955681184\Cache emptied successfully
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\trk79v17.default\Cache emptied successfully
C:\Users\usr3\AppData\Local\Mozilla\Firefox\Profiles\x88fm5vb.default\Cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1 folders=3 77 bytes)

==== Empty Temp Folders ======================

C:\Users\usr2\AppData\Local\Temp emptied successfully
C:\Users\usr1\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\usr3\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\user\AppData\Local\Temp  will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot


aharonov 13.01.2014 20:34

Und die Werbetabs sind immer noch vorhanden?

ThunderX 13.01.2014 20:36

Kann ich im Moment noch nicht sagen, die kommen ab und zu. Trotzdem danke für die Hilfe ;)

aharonov 14.01.2014 00:19

Behalt es mal im Auge und melde dich dann wieder.

ThunderX 23.01.2014 20:56

Es scheinen sich keine Tabs mehr zu öffnen. Vielen Dank für die Hilfe :dankeschoen:


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:16 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19