Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-08-2014 02
Ran by arne at 2014-09-01 15:54:12 Run:1
Running from C:\Users\arne\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVAST Software <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Spyware Terminator <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Spyware Terminator <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION
AppInit_DLLs: C:\Program Files C:\Program Files => C:\Program Files C:\Program Files File Not Found
AppInit_DLLs-x32: C:\Program Files C:\Program Files => "C:\Program Files C:\Program Files" File Not Found
*****************
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
"C:\Program Files C:\Program Files" => Value Data removed successfully.
"C:\Program Files C:\Program Files" => Value Data removed successfully.
==== End of Fixlog ==== Code:
# AdwCleaner v3.308 - Bericht erstellt am 01/09/2014 um 15:55:50
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : arne - ARNE-PC
# Gestartet von : C:\Users\arne\Desktop\adwcleaner_3.308.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\user.js
Ordner Gefunden : C:\Program Files (x86)\Jump Flip
Ordner Gefunden : C:\Users\arne\AppData\Local\Temp\mt_ffx
Ordner Gefunden : C:\Users\arne\AppData\Local\Temp\OCS
Ordner Gefunden : C:\Users\arne\AppData\LocalLow\Softonic
Ordner Gefunden : C:\Users\arne\AppData\Roaming\pdfforge
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gefunden : HKLM\SOFTWARE\InstallCore
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateJumpFlip_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateJumpFlip_RASMANCS
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js ]
Zeile gefunden : user_pref("browser.search.order.1", "Mysearchdial");
Zeile gefunden : user_pref("extensions.irmysearch.aflt", "irmsd0101");
Zeile gefunden : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1Qzu0CtB0FtA0CtCtCyC0FyCyD0ByCyB0FyDtN0D0Tzu0SyBtAtBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R");
Zeile gefunden : user_pref("extensions.irmysearch.cr", "2017528363");
Zeile gefunden : user_pref("extensions.irmysearch.instlRef", "");
*************************
AdwCleaner[R0].txt - [3498 octets] - [01/09/2014 15:55:50]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3558 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by arne on 01.09.2014 at 16:10:22,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.09.2014 at 16:16:11,92
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 01.09.2014
Suchlauf-Zeit: 11:53:18
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.01.01
Rootkit Datenbank: v2014.08.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: arne
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 342586
Verstrichene Zeit: 5 Min, 36 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 26
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), Ersetzt,[680db335c6b50e28e2360c0d65a09a66]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.aflt", "OC");), Ersetzt,[fb7ab5337a0161d50d0b5bbeff064db3]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");), Ersetzt,[284dc3250576c76fd24638e1917401ff]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.autoRvrt", "false");), Ersetzt,[a2d3feea8cef83b3ba5e0613fb0a956b]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltLng", "de");), Ersetzt,[5025f1f781fac2748a8e12075baa41bf]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltSrch", true);), Ersetzt,[8fe6e40485f6f145a276a5749273bb45]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dnsErr", true);), Ersetzt,[e68f6a7e6a11b581cf49f227d92c46ba]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.excTlbr", false);), Ersetzt,[4e275593e99242f4b4640b0ee421b749]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.ffxUnstlRst", false);), Ersetzt,[ec890ddb29525cda96825dbc8b7a8977]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpg", true);), Ersetzt,[fd788c5ca6d58ea8b76163b6a06552ae]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=be7467f5000000000000bc5ff48d4cd0");), Ersetzt,[64111fc99edd6bcbda3e22f743c2ca36]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.id", "be7467f5000000000000bc5ff48d4cd0");), Ersetzt,[9ed713d5e4979d9951c7f3267e8711ef]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlDay", "16004");), Ersetzt,[f184499fbbc038fec55325f4c243659b]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlRef", "MOY00621");), Ersetzt,[8aebb5336912a88ec2564ecb15f006fa]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTab", true);), Ersetzt,[c0b5b434fc7fd75fd8409e7bc1446799]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=be7467f5000000000000bc5ff48d4cd0");), Ersetzt,[3e378a5e8cef1323d0481108996c916f]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prdct", "Softonic");), Ersetzt,[2e4784641665e452a6723ddcb74e24dc]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prtnrId", "softonic");), Ersetzt,[62139454a3d8ef47c55333e61ee74ab6]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.rvrt", "false");), Ersetzt,[037244a4eb90d46276a28e8b35d0c13f]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.smplGrp", "none");), Ersetzt,[1d58aa3e562583b37a9ebb5ef70e6f91]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");), Ersetzt,[3441dc0c7407a0962cec7c9dc441d729]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrId", "opencandy2013");), Ersetzt,[65105f89a5d670c634e49188a263a55b]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=be7467f5000000000000bc5ff48d4cd0&q=");), Ersetzt,[babb9a4e4f2cde5857c124f5689db749]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsn", "1.8.21.14");), Ersetzt,[ef865692df9c78beee2a85941de81ce4]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsnTs", "1.8.21.1418:36:29");), Ersetzt,[284d5098b1cad85e9583ca4f5ea7f010]
PUP.Optional.Softonic.A, C:\Users\arne\AppData\Roaming\Mozilla\Firefox\Profiles\4uanr8qj.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsni", "1.8.21.14");), Ersetzt,[5c19a2466912350151c7f2270203ab55]
Physische Sektoren: 0
(No malicious items detected)
(end) |