Ok, mit der 4er Version von
SUPERAntiSpyware hat es endlich geklappt. Ich habe alle Tracking Cookies und BrowserHijacker löschen (bzw. ich glaube in Quarantäne verschieben) lassen. SuperAntispyware wollte neu starten. Danach sind leider rpcnet.exe und agremove.exe immer noch da. Vielleicht kannst Du ja mit dem Log was anfangen:
Code:
Alles auswählen Aufklappen ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com
Generated 08/08/2011 at 08:23 PM
Application Version : 4.52.1000
Core Rules Database Version : 7526
Trace Rules Database Version: 5338
Scan type : Complete Scan
Total Scan Time : 02:10:09
Memory items scanned : 589
Memory threats detected : 0
Registry items scanned : 22602
Registry threats detected : 4
File items scanned : 198480
File threats detected : 63
Adware.Tracking Cookie
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@smartadserver[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@doubleclick[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ads.pubmatic[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adbrite[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@zanox[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@fastclick[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@vidasco.rotator.hadj7.adjuggler[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@m1.mediasrv[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ads.addynamix[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ar.atwola[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adxpose[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@content.yieldmanager[3].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@content.yieldmanager[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.yieldmanager[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.adition[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@cdn.at.atwola[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adecn[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@clicksor[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@webmasterplan[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@serving-sys[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.ad-srv[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@tacoda[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adx.chip[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@atwola[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.zanox[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@atdmt[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@unitymedia[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.dyntracker[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@traffictrack[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@at.atwola[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adfarm1.adition[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@harrenmedianetwork[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ru4[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@mediaplex[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adserver.adtechus[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@advertising[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@yieldmanager[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@media6degrees[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@user.lucidmedia[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@tradedoubler[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad3.adfarm1.adition[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@apmebf[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@adserving.versaneeds[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ads.creative-serving[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@mediabrandsww[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.360yield[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad1.adfarm1.adition[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@ad.harrenmedianetwork[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@tracking.quisma[2].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@myroitracking[1].txt
C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Cookies\jana@invitemedia[2].txt
cdn1.eyewonder.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
ch.mediaplanet.streamingbolaget.se [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
files.youporn.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
ia.media-imdb.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
m.doubleclick.net [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
media.cwtv.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
msnbcmedia.msn.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
secure-uk.imrworldwide.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
secure-us.imrworldwide.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
track.webgains.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
www.99counters.com [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
www.unitymedia.de [ C:\Users\Jana\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3XA2KTA2 ]
Browser Hijacker.Deskbar
(x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
(x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
(x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
(x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version
So langsam bekomme ich das Gefühl, das wird nix
Was habe ich mir denn da überhaupt eingefangen?
Danke trotzdem schonmal soweit. Vielleicht findest Du ja noch eine Lösung für diesen Mist, den ich mir da eingefangen habe.
__________________