No suspicion | 31.08.2013 13:56 | Hallo Matze,
anbei die Logs Grüße No Suspicion - ich hab nu irgendwas Snap.du auf dem Rechner, kam bei Combifix mit. Hat ne Toolbar..gefällt mir nicht. Kann das wieder runter?
Combofix Code:
ComboFix 13-08-30.02 - Obelix 31.08.2013 13:59:39.1.8 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.2944.1675 [GMT 2:00]
ausgeführt von:: c:\users\Obelix\AppData\Local\Temp\setup.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\337
c:\program files\Common Files\337\libcef\1.1364.1123\icudt.dll
c:\program files\Common Files\337\libcef\1.1364.1123\libcef.dll
c:\program files\Common Files\337\libcef\1.1364.1123\locales\en-US.pak
c:\programdata\Roaming
c:\users\Obelix\AppData\Roaming\337
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\ebase.dll
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\app_close.png
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\app_max.png
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\app_min.png
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\app_restore.png
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\wallpaper_resource.xml
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\image\default\window.png
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\language\en_us\wallpaper_lang.ini
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\language\es_es\wallpaper_lang.ini
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\language\pt_br\wallpaper_lang.ini
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\language\tr_tr\wallpaper_lang.ini
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\language\zh_tw\wallpaper_lang.ini
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\layout\default\dp_appwnd.xml
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\layout\default\msgbox.xml
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\libpng.dll
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\main
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\msvcp100.dll
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\msvcr100.dll
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\ouilibnl.dll
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\plusapp.exe
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\style\wallpaper_style.xml
c:\users\Obelix\AppData\Roaming\337\337 Wallpaper\TrayDownloader.exe
c:\users\Obelix\Desktop\Search.lnk
c:\users\Obelix\Desktop\Setup.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-31 ))))))))))))))))))))))))))))))
.
.
2013-08-31 12:04 . 2013-08-31 12:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-31 11:55 . 2013-08-31 11:55 -------- d-----w- c:\program files\Optimizer Pro
2013-08-31 11:55 . 2013-08-31 11:55 -------- d-----w- c:\program files\Tepfel
2013-08-31 11:55 . 2013-08-31 11:55 -------- d-----w- c:\programdata\Tarma Installer
2013-08-31 10:28 . 2013-08-31 10:28 -------- d-----w- C:\FRST
2013-08-30 21:20 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E1A766B6-3542-4649-8703-F8D03C3E73DB}\mpengine.dll
2013-08-30 08:17 . 2013-08-30 08:17 -------- d-----w- c:\program files\Common Files\Skype
2013-08-30 08:17 . 2013-08-30 08:17 -------- d-----r- c:\program files\Skype
2013-08-30 08:17 . 2013-08-30 08:17 -------- d-----w- c:\programdata\Skype
2013-08-29 08:06 . 2012-08-27 13:48 6356496 ----a-w- c:\windows\system32\drivers\rtsuvc.sys
2013-08-29 08:06 . 2012-08-27 13:48 4898448 ----a-w- c:\windows\RTFTrack.exe
2013-08-29 08:06 . 2012-08-27 13:48 316048 ----a-w- c:\windows\system32\RtCamX.dll
2013-08-29 08:06 . 2012-08-27 13:48 1710736 ----a-w- c:\windows\RtCamU.exe
2013-08-29 07:55 . 2013-08-29 07:55 -------- d-----w- c:\programdata\Malwarebytes
2013-08-29 07:55 . 2013-08-29 07:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-08-29 07:55 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-28 17:04 . 2013-08-28 17:04 -------- d-----w- C:\NvidiaLogging
2013-08-28 17:03 . 2013-05-14 19:28 34592 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2013-08-28 17:03 . 2013-05-14 19:27 28448 ----a-w- c:\windows\system32\nvaudcap32v.dll
2013-08-28 16:56 . 2013-08-28 16:56 -------- d-----w- c:\windows\system32\NV
2013-08-28 16:52 . 2013-08-28 16:52 -------- d-----w- c:\program files\AGEIA Technologies
2013-08-28 16:52 . 2013-08-28 16:52 -------- d-----w- c:\users\UpdatusUser
2013-08-28 16:52 . 2013-06-21 09:52 4192544 ----a-w- c:\windows\system32\nvcpl.dll
2013-08-28 16:52 . 2013-06-21 09:52 3045664 ----a-w- c:\windows\system32\nvsvc.dll
2013-08-28 16:52 . 2013-06-21 09:52 640288 ----a-w- c:\windows\system32\nvvsvc.exe
2013-08-28 16:52 . 2013-06-21 09:52 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-08-28 16:52 . 2013-06-21 09:52 575264 ----a-w- c:\windows\system32\oemdspif.dll
2013-08-28 16:52 . 2013-06-21 09:52 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2013-08-28 16:52 . 2013-06-21 09:52 872224 ----a-w- c:\windows\system32\nv3dappshext.dll
2013-08-28 16:52 . 2013-06-21 09:52 66560 ----a-w- c:\windows\system32\nv3dappshextr.dll
2013-08-28 16:52 . 2013-06-21 09:52 223008 ----a-w- c:\windows\system32\nvmctray.dll
2013-08-28 16:52 . 2013-06-19 16:14 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-08-28 16:51 . 2013-08-28 16:55 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-08-28 16:47 . 2013-08-28 17:03 -------- d-----w- c:\program files\NVIDIA Corporation
2013-08-28 16:47 . 2013-08-28 16:47 -------- d-----w- C:\NVIDIA
2013-08-28 16:38 . 2013-08-28 16:56 -------- d-----w- c:\programdata\NVIDIA
2013-08-28 16:36 . 2013-08-28 16:36 -------- d-----w- c:\program files\Common Files\Java
2013-08-28 16:36 . 2013-08-28 16:36 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-28 16:36 . 2013-08-28 16:36 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-28 16:36 . 2013-08-28 16:36 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-28 16:36 . 2013-08-28 16:36 -------- d-----w- c:\program files\Java
2013-08-28 15:40 . 2013-08-28 15:40 -------- d-----w- c:\program files\Atheros
2013-08-28 15:40 . 2012-05-31 15:06 2240512 ----a-w- c:\windows\system32\drivers\athr.sys
2013-08-28 15:40 . 2012-05-31 15:06 2240512 ----a-w- c:\windows\system32\athr.sys
2013-08-28 15:28 . 2013-08-28 15:28 -------- d-----w- c:\program files\Device Doctor
2013-08-27 18:39 . 2012-01-04 14:55 9888360 ----a-w- c:\windows\system32\RtsUVStoricon.dll
2013-08-24 17:39 . 2013-08-24 17:39 -------- d-----w- c:\program files\CCleaner
2013-08-24 16:08 . 2013-08-31 11:58 -------- d-----w- c:\programdata\Search Protection
2013-08-24 16:08 . 2013-08-24 16:08 -------- d-----w- c:\programdata\blekko toolbars
2013-08-24 16:08 . 2013-08-24 16:08 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection
2013-08-24 16:08 . 2013-08-24 16:08 -------- d-----w- c:\program files\Toolbar Cleaner
2013-08-24 16:08 . 2013-08-24 16:08 -------- d-----w- c:\program files\Lavasoft
2013-08-24 16:05 . 2013-08-24 16:06 44424 ----a-w- c:\windows\system32\sbbd.exe
2013-08-24 16:05 . 2013-08-24 16:06 13560 ----a-w- c:\windows\system32\drivers\gfibto.sys
2013-08-24 15:52 . 2013-08-24 15:52 67168 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-24 15:52 . 2013-08-24 15:52 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-08-24 15:52 . 2013-08-24 15:52 -------- d-----w- c:\program files\AskPartnerNetwork
2013-08-24 15:52 . 2013-08-24 15:52 -------- d-----w- c:\programdata\APN
2013-08-24 15:51 . 2013-07-18 06:02 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-24 15:51 . 2013-07-18 06:02 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-24 15:51 . 2013-03-06 14:13 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-08-24 15:51 . 2013-08-24 15:51 -------- d-----w- c:\programdata\Avira
2013-08-24 15:51 . 2013-08-24 15:51 -------- d-----w- c:\program files\Avira
2013-08-24 15:46 . 2013-08-31 10:26 -------- d-----w- c:\program files\WinZipper
2013-08-24 15:45 . 2013-08-24 15:49 -------- d-----w- c:\programdata\eSafe
2013-08-24 15:45 . 2013-08-24 15:46 -------- d-----w- c:\program files\Desk 365
2013-08-24 15:45 . 2013-08-25 10:23 -------- d-----w- c:\program files\Iminent
2013-08-24 15:44 . 2013-08-24 15:44 -------- d-----w- c:\program files\ObviousIdea
2013-08-24 15:24 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2013-08-24 15:24 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2013-08-24 15:22 . 2013-08-24 15:22 -------- d-----w- c:\program files\Microsoft Works
2013-08-24 15:21 . 2013-08-24 15:46 -------- d-----w- c:\program files\Microsoft.NET
2013-08-24 15:21 . 2013-08-24 15:21 -------- d-----w- c:\windows\PCHEALTH
2013-08-24 15:20 . 2013-08-24 15:20 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2013-08-24 15:19 . 2013-08-24 15:24 -------- d-----w- c:\programdata\Microsoft Help
2013-08-24 15:18 . 2013-08-24 15:18 -------- d-----r- C:\MSOCache
2013-08-17 15:33 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-08-17 11:21 . 2013-08-17 11:21 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-17 11:20 . 2013-08-17 11:20 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-08-17 09:00 . 2013-08-17 09:18 -------- d-----w- c:\programdata\SpeedyPC Software
2013-08-15 17:56 . 2013-04-10 05:18 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-15 17:56 . 2013-04-10 05:18 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-08-15 17:56 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-15 17:56 . 2013-05-27 04:57 680960 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-15 17:56 . 2013-05-27 04:57 392704 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-08-15 17:56 . 2013-05-27 04:57 224768 ----a-w- c:\program files\Windows Defender\MpCommu.dll
2013-08-15 17:56 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-15 17:56 . 2013-02-27 05:05 101720 ----a-w- c:\windows\system32\consent.exe
2013-08-15 17:56 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\system32\authui.dll
2013-08-15 17:56 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-08-14 19:18 . 2013-08-14 19:18 -------- d-----w- c:\windows\system32\SPReview
2013-08-12 16:01 . 2013-08-12 16:01 -------- dc----w- c:\windows\system32\DRVSTORE
2013-08-12 16:01 . 2012-08-21 11:01 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-08-12 16:00 . 2013-08-12 16:01 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\program files\iPod
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\programdata\Apple Computer
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\program files\Apple Software Update
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\program files\Bonjour
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\program files\Common Files\Apple
2013-08-12 16:00 . 2013-08-12 16:00 -------- d-----w- c:\programdata\Apple
2013-08-10 09:21 . 2013-08-10 09:21 -------- d-----w- c:\program files\Common Files\Intel Corporation
2013-08-10 09:06 . 2012-05-21 13:24 41984 ----a-w- c:\windows\system32\drivers\USB3Ver.dll
2013-08-10 09:06 . 2012-05-21 13:25 793920 ----a-w- c:\windows\system32\drivers\iusb3xhc.sys
2013-08-10 09:06 . 2012-05-21 13:25 350016 ----a-w- c:\windows\system32\drivers\iusb3hub.sys
2013-08-10 09:06 . 2012-05-21 13:25 15680 ----a-w- c:\windows\system32\drivers\iusb3hcs.sys
2013-08-10 09:05 . 2011-11-29 17:30 470808 ----a-w- c:\windows\system32\drivers\iaStor.sys
2013-08-10 09:05 . 2013-08-10 09:05 -------- d-----w- c:\program files\Elantech
2013-08-10 09:04 . 2012-09-05 17:21 277904 ----a-w- c:\windows\system32\drivers\ETD.sys
2013-08-10 09:04 . 2012-02-21 10:10 15128 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2013-08-10 09:03 . 2013-08-10 09:03 -------- d-----w- c:\program files\Common Files\postureAgent
2013-08-10 08:54 . 2011-11-09 22:52 46080 ----a-w- c:\windows\system32\drivers\HECI.sys
2013-08-10 08:53 . 2011-12-06 13:55 53248 ----a-w- c:\windows\system32\CSVer.dll
2013-08-10 08:52 . 2013-08-10 09:12 -------- d-----w- C:\Intel
2013-08-10 08:52 . 2013-08-28 12:38 -------- d-----w- c:\windows\system32\sda
2013-08-10 08:51 . 2012-01-04 14:55 231528 ----a-w- c:\windows\system32\drivers\RtsUVStor.sys
2013-08-10 08:39 . 2013-08-28 15:17 -------- d-----w- c:\program files\Lenovo
2013-08-10 08:38 . 2013-08-24 16:08 -------- d-----w- c:\programdata\Downloaded Installations
2013-08-09 22:41 . 2013-08-09 22:41 -------- d-----w- c:\windows\system32\EventProviders
2013-08-09 19:12 . 2013-08-24 15:45 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-09 19:12 . 2013-08-24 15:45 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 19:12 . 2013-08-09 19:12 -------- d-----w- c:\windows\system32\Macromed
2013-08-08 17:23 . 2010-11-20 12:30 712576 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-08-08 17:15 . 2011-04-28 03:15 60416 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2013-08-08 17:15 . 2011-04-28 03:15 393728 ----a-w- c:\windows\system32\drivers\bthport.sys
2013-08-08 17:15 . 2010-11-20 12:17 219648 ----a-w- c:\windows\system32\fsquirt.exe
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-14 19:22 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-07-26 20:30 12240 ----a-w- c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2013-08-09 14:50 91536 ----a-w- c:\program files\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-07-26 12240]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll" [2013-08-09 91536]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Doctor"="c:\program files\Device Doctor\DDLauncher.exe" [2012-01-02 80016]
"Browser Infrastructure Helper"="c:\users\Obelix\AppData\Local\Smartbar\Application\SnapDo.exe" [2013-08-04 21024]
"WebCake Desktop"="c:\users\Obelix\AppData\Roaming\Tepfel\WebCakeDesktop.exe" [2013-08-10 52504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2012-05-03 8000560]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\Utility.exe" [2012-05-03 5942320]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-08-10 11672208]
"ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2012-09-05 2244496]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-21 291648]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="z:\musik\iTunes\iTunesHelper.exe" [2013-05-31 152392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-18 345144]
"ApnTBMon"="c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-07-26 1558480]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-07-15 554384]
"Search Protection"="c:\programdata\Search Protection\SearchProtection.exe" [2013-06-13 943016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
"RtsFT"="RTFTrack.exe" [2012-08-27 4898448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-27 144664]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-27 180504]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-27 187672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-08-14 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\NVIDIA~1\NVSTRE~1\rxinput.dll
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-07-25 162672]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2012-03-15 143360]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2012-06-25 241968]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys [2012-01-04 231528]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2013-08-24 13560]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-05-21 15680]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2013-06-21 25376]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-06 37352]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-03-15 509448]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-18 84024]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-07-18 589368]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-07-26 168400]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-04-23 104208]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 458464]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-28 161560]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-07-27 14592288]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-28 363800]
S2 WebCakeUpdater;WebCakeUpdater;c:\program files\Tepfel\WebCakeDesktop.Updater.exe [2013-08-10 51992]
S2 winzipersvc;WinZiper service;c:\program files\WinZipper\winzipersvc.exe [2013-08-24 424104]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2012-06-25 2759984]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-12-15 24672]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2012-03-15 143360]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-09-05 277904]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 280576]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-05-21 350016]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-05-21 793920]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2011-11-09 46080]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-05-14 34592]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys [2012-08-27 6356496]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-09 15:45]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=hp&installDate=31/08/2013
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=hp&installDate=31/08/2013
FF - prefs.js: keyword.URL - hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=ds&installDate=31/08/2013&q=
FF - ExtSQL: 2013-07-26 22:31; toolbar_AVIRA-V7@apn.ask.com; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF - ExtSQL: 2013-08-05 21:06; {66E978CD-981F-47DF-AC42-E3CF417C1467}; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi
FF - ExtSQL: 2013-08-07 20:26; socialfixer@mattkruse.com; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\socialfixer@mattkruse.com.xpi
FF - ExtSQL: 2013-08-24 17:45; toolbarbutton@obviousidea.us; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\toolbarbutton@obviousidea.us
FF - ExtSQL: 2013-08-25 12:31; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-31 13:55; {20c62c14-1d48-5cc1-2281-292fc211aa4e}; c:\users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\extensions\{20c62c14-1d48-5cc1-2281-292fc211aa4e}
FF - user.js: extensions.autoDisableScopes - 10);user_pref(extentions.webcake.installId, 9a79d726-ead3-4e45-84ad-582593c26e89
FF - user.js: extentions.webcake.defaultEnableAppsList - layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wc
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-31 14:06:11
ComboFix-quarantined-files.txt 2013-08-31 12:06
.
Vor Suchlauf: 11 Verzeichnis(se), 34.663.124.992 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 34.803.351.552 Bytes frei
.
- - End Of File - - 0DCFA97ADA26FB1EB825F2B419DCA7E5
A36C5E4F47E84449FF07ED3517B43A31
ADWCleaner S0...es gibt auch noch ein R0...?:eek::eek::confused: Code:
# AdwCleaner v3.001 - Report created 31/08/2013 at 14:10:49
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Obelix - OBELIX-PC
# Running from : C:\Users\Obelix\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : APNMCP
[#] Service Deleted : WebCakeUpdater
Service Deleted : winzipersvc
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\eSafe
Folder Deleted : C:\ProgramData\search protection
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Program Files\Desk 365
Folder Deleted : C:\Program Files\Iminent
Folder Deleted : C:\Program Files\optimizer pro
Folder Deleted : C:\Program Files\Tepfel
Folder Deleted : C:\Program Files\WinZipper
Folder Deleted : C:\Users\Obelix\AppData\Local\Smartbar
Folder Deleted : C:\Users\Obelix\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Obelix\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\Obelix\AppData\Roaming\Desk 365
Folder Deleted : C:\Users\Obelix\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Obelix\AppData\Roaming\optimizer pro
Folder Deleted : C:\Users\Obelix\AppData\Roaming\Tepfel
Folder Deleted : C:\Users\Obelix\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\adawaretb
Folder Deleted : C:\Users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\Extensions\plugin@getwebcake.com
File Deleted : C:\Users\Obelix\Desktop\Optimizer Pro.lnk
File Deleted : C:\Users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\user.js
File Deleted : C:\Windows\System32\Tasks\Omiga Plus RunAsStdUser
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Omiga Plus RunAsStdUser
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC17CF56-D1F7-4CA2-97E7-EF890C1449BB}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC17CF56-D1F7-4CA2-97E7-EF890C1449BB}
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [WebCake Desktop]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WebCakeIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Key Deleted : HKLM\SOFTWARE\Classes\WebCakeIEClient.Api
Key Deleted : HKLM\SOFTWARE\Classes\WebCakeIEClient.Api.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB975E58-E769-4E5A-BA12-B765BC559FF3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\FoxyDeal
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\SmartbarBackup
Key Deleted : HKCU\Software\SmartbarLog
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Desksvc
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\omigaplusSvc
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Obelix\AppData\Roaming\Mozilla\Firefox\Profiles\8iniiwbx.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Line Deleted : user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":38,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Analytics\\\",\\\"category\\\[...]
Line Deleted : user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
Line Deleted : user_pref("extensions.enabledAddons", "%7B66E978CD-981F-47DF-AC42-E3CF417C1467%7D:0.4.3,toolbarbutton%40obviousidea.us:2.0,toolbar_AVIRA-V7%40apn.ask.com:20.53263,%7B87934c42-161d-45bc-8cef-ef18abe2a3[...]
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.LastHiddenTime", 22965850);
Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", true);
Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", true);
Line Deleted : user_pref("extensions.helperbar.countryiso", "de");
Line Deleted : user_pref("extensions.helperbar.downloadprovider", "adknowledgeyb");
Line Deleted : user_pref("extensions.helperbar.installationid", "20c62c14-1d48-5cc1-2281-292fc211aa4e");
Line Deleted : user_pref("extensions.helperbar.installdate", "31/08/2013");
Line Deleted : user_pref("extensions.helperbar.publisher", "adknowledgeyb");
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\browser\\\\extensions[...]
Line Deleted : user_pref("extentions.webcake.defaultEnableAppsList", "layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wc");
Line Deleted : user_pref("extentions.webcake.installId", "9a79d726-ead3-4e45-84ad-582593c26e89");
*************************
AdwCleaner[R0].txt - [9400 octets] - [31/08/2013 14:10:28]
AdwCleaner[S0].txt - [9645 octets] - [31/08/2013 14:10:49]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9705 octets] ########## und JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.6 (08.30.2013:1)
OS: Windows 7 Professional x86
Ran by Obelix on 31.08.2013 at 14:17:05,02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2715393653-226820321-1141994478-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\speedypc software"
Successfully deleted: [Folder] "C:\Users\Obelix\AppData\Roaming\speedypc software"
Successfully deleted: [Folder] "C:\Users\Obelix\appdata\local\adawarebp"
~~~ FireFox
Successfully deleted: [File] C:\Users\Obelix\AppData\Roaming\mozilla\firefox\profiles\8iniiwbx.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Successfully deleted: [Folder] C:\Users\Obelix\AppData\Roaming\mozilla\firefox\profiles\8iniiwbx.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
Successfully deleted the following from C:\Users\Obelix\AppData\Roaming\mozilla\firefox\profiles\8iniiwbx.default\prefs.js
user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=nt&installDate
user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=DE&userid=20c62c14-1d48-5cc1-2281-292fc211aa4e&searchtype=hp&insta
user_pref("extensions.helperbar.SmartbarDisabled", true);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
user_pref("iminent.ShowThankyouPixel", "0");
user_pref("iminent.displayFavLinks", "1");
user_pref("iminent.registerToolbarEvent102", "1377359237772");
user_pref("iminent.version", "7.33.3.1");
user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.33.3.1\",\"InstallEventCTime\":1377359334585,\"InstallEvent\":\"True\"}");
user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=bs&q=");
user_pref("socialfixer.1435014019/typeahead_new", "for (;;);{\"__ar\":1,\"payload\":{\"entries\":[{\"uid\":100000522541906,\"photo\":\"hxxps:\\/\\/fbcdn-profile-a.akamaihd.net
Emptied folder: C:\Users\Obelix\AppData\Roaming\mozilla\firefox\profiles\8iniiwbx.default\minidumps [14 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.08.2013 at 14:18:27,65
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |