| LOOP PARA |  28.08.2013 15:30 |        Von Malwarebytes habe ich drei Logs:   Code:  
 Malwarebytes Anti-Malware (Test) 1.75.0.1300 
www.malwarebytes.org   
Datenbank Version: v2013.08.28.02   
Windows 7 Service Pack 1 x86 NTFS 
Internet Explorer 10.0.9200.16660 
LOOP PARA :: BLOCK [Administrator]   
Schutz: Aktiviert   
28.08.2013 13:05:05 
MBAM-log-2013-08-28 (14-01-26).txt   
Art des Suchlaufs: Vollständiger Suchlauf (C:\|) 
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM 
Deaktivierte Suchlaufeinstellungen: P2P 
Durchsuchte Objekte: 351160 
Laufzeit: 55 Minute(n), 9 Sekunde(n)   
Infizierte Speicherprozesse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungswerte: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateiobjekte der Registrierung: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 9 
C:\AdwCleaner\Quarantine\C\Users\LOOP PARA\AppData\Roaming\file scout\filescout.exe.vir (Trojan.PUP.Optional.FileScout.A) -> Keine Aktion durchgeführt. 
C:\AdwCleaner\Quarantine\C\Windows\system32\roboot.exe.vir (PUP.Optional.PCPerformer.A) -> Keine Aktion durchgeführt. 
C:\Games\SoftonicDownloader_fuer_super-mario-world-deluxe.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt. 
C:\Games\SoftonicDownloader_fuer_supertuxkart.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt. 
C:\Users\LOOP PARA\Desktop\SoftonicDownloader_fuer_mario-forever.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt. 
C:\Users\LOOP PARA\Desktop\bundleSetup.exe (PUP.BundleInstaller.IB) -> Keine Aktion durchgeführt. 
C:\Users\LOOP PARA\Desktop\SIMON_BLOCK\.Trashes\501\vlc-1.1.1.exe (Spyware.Agent) -> Keine Aktion durchgeführt. 
C:\Users\LOOP PARA\Desktop\SIMON_BLOCK\.Trashes\501\install_flash_player.exe.download\install_flash_player.exe (Trojan.Downloader) -> Keine Aktion durchgeführt. 
C:\Users\LOOP PARA\Downloads\iLividSetup-r559-n-bf.exe (PUP.Optional.Bandoo) -> Keine Aktion durchgeführt.   
(Ende)    Code:  
 Malwarebytes Anti-Malware (Test) 1.75.0.1300 
www.malwarebytes.org   
Datenbank Version: v2013.08.28.03   
Windows 7 Service Pack 1 x86 NTFS 
Internet Explorer 10.0.9200.16660 
LOOP PARA :: BLOCK [Administrator]   
Schutz: Aktiviert   
28.08.2013 14:02:43 
mbam-log-2013-08-28 (14-02-43).txt   
Art des Suchlaufs: Vollständiger Suchlauf (C:\|) 
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM 
Deaktivierte Suchlaufeinstellungen: P2P 
Durchsuchte Objekte: 351082 
Laufzeit: 52 Minute(n), 3 Sekunde(n)   
Infizierte Speicherprozesse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungswerte: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateiobjekte der Registrierung: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 0 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 9 
C:\AdwCleaner\Quarantine\C\Users\LOOP PARA\AppData\Roaming\file scout\filescout.exe.vir (Trojan.PUP.Optional.FileScout.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\AdwCleaner\Quarantine\C\Windows\system32\roboot.exe.vir (PUP.Optional.PCPerformer.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Games\SoftonicDownloader_fuer_super-mario-world-deluxe.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Games\SoftonicDownloader_fuer_supertuxkart.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Users\LOOP PARA\Desktop\SoftonicDownloader_fuer_mario-forever.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Users\LOOP PARA\Desktop\bundleSetup.exe (PUP.BundleInstaller.IB) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Users\LOOP PARA\Desktop\SIMON_BLOCK\.Trashes\501\vlc-1.1.1.exe (Spyware.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Users\LOOP PARA\Desktop\SIMON_BLOCK\.Trashes\501\install_flash_player.exe.download\install_flash_player.exe (Trojan.Downloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\Users\LOOP PARA\Downloads\iLividSetup-r559-n-bf.exe (PUP.Optional.Bandoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.   
(Ende)    Code:  
 2013/08/28 12:59:30 +0200        BLOCK        LOOP PARA        MESSAGE        Executing scheduled update:  Daily 
2013/08/28 12:59:37 +0200        BLOCK        LOOP PARA        MESSAGE        Starting protection 
2013/08/28 12:59:37 +0200        BLOCK        LOOP PARA        MESSAGE        Protection started successfully 
2013/08/28 12:59:37 +0200        BLOCK        LOOP PARA        MESSAGE        Starting IP protection 
2013/08/28 13:00:09 +0200        BLOCK        LOOP PARA        MESSAGE        IP Protection started successfully 
2013/08/28 13:00:33 +0200        BLOCK        LOOP PARA        MESSAGE        Starting database refresh 
2013/08/28 13:00:33 +0200        BLOCK        LOOP PARA        MESSAGE        Stopping IP protection 
2013/08/28 13:00:37 +0200        BLOCK        LOOP PARA        MESSAGE        IP Protection stopped successfully 
2013/08/28 13:00:39 +0200        BLOCK        LOOP PARA        MESSAGE        Scheduled update executed successfully:  database updated from version v2013.04.04.07 to version v2013.08.28.02 
2013/08/28 13:00:42 +0200        BLOCK        LOOP PARA        MESSAGE        Database refreshed successfully 
2013/08/28 13:00:42 +0200        BLOCK        LOOP PARA        MESSAGE        Starting IP protection 
2013/08/28 13:00:48 +0200        BLOCK        LOOP PARA        MESSAGE        IP Protection started successfully 
2013/08/28 14:02:14 +0200        BLOCK        LOOP PARA        MESSAGE        Starting database refresh 
2013/08/28 14:02:14 +0200        BLOCK        LOOP PARA        MESSAGE        Stopping IP protection 
2013/08/28 14:02:14 +0200        BLOCK        LOOP PARA        MESSAGE        IP Protection stopped successfully 
2013/08/28 14:02:33 +0200        BLOCK        LOOP PARA        MESSAGE        Database refreshed successfully 
2013/08/28 14:02:33 +0200        BLOCK        LOOP PARA        MESSAGE        Starting IP protection 
2013/08/28 14:02:37 +0200        BLOCK        LOOP PARA        MESSAGE        IP Protection started successfully 
2013/08/28 15:35:28 +0200        BLOCK        (null)        MESSAGE        Starting protection 
2013/08/28 15:35:28 +0200        BLOCK        (null)        MESSAGE        Protection started successfully 
2013/08/28 15:35:28 +0200        BLOCK        (null)        MESSAGE        Starting IP protection 
2013/08/28 15:35:31 +0200        BLOCK        (null)        MESSAGE        IP Protection started successfully   JRT:  Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 5.5.4 (08.22.2013:1) 
OS: Windows 7 Home Premium x86 
Ran by LOOP PARA on 28.08.2013 at 16:14:06,55 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services       
~~~ Registry Values   
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName 
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL       
~~~ Registry Keys   
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\uniblue 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\chatzum_softonic_yahoo_62_v5_RASAPI32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\chatzum_softonic_yahoo_62_v5_RASMANCS 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic_chr_1-8-16-10_RASAPI32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic_chr_1-8-16-10_RASMANCS 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{71588120-FC17-4463-B07D-2C71FE6E057B} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D0D1AF60-A423-400D-8CEB-6C40DBCFC704} 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{71588120-FC17-4463-B07D-2C71FE6E057B}       
~~~ Files       
~~~ Folders   
Successfully deleted: [Folder] "C:\Users\LOOP PARA\AppData\Roaming\isafe" 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{0E783A0D-53E6-417E-941C-A874A959BF78} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{0F03C573-3062-4D01-93B3-0A054B75BF97} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{1B05A95C-5A51-430D-9249-79CFB10AEBEA} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{2DBC482C-2403-42C1-80CE-AFA7845A14EF} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{40D895D9-1DFC-4C1F-971E-3C31154F03DD} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{420580E7-FEF2-4C5F-9E6B-834A3BFA6729} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{9170477A-7519-4183-A993-FE04638879D7} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{9D64D173-3254-40B2-8A56-D2C5B75E97D3} 
Successfully deleted: [Empty Folder] C:\Users\LOOP PARA\appdata\local\{DCE92382-0875-4A29-8BBC-B631B13AAF19}       
~~~ FireFox   
Successfully deleted the following from C:\Users\LOOP PARA\AppData\Roaming\mozilla\firefox\profiles\h1dvoqqj.default\prefs.js   
user_pref("iminent.ShowThankyouPixel", "0"); 
user_pref("iminent.displayFavLinks", "1"); 
user_pref("iminent.registerToolbarEvent101", "1377614112386"); 
user_pref("iminent.registerToolbarEvent102", "1377598809467"); 
user_pref("iminent.registerToolbarEvent140", "1377445481694"); 
user_pref("iminent.version", "7.33.3.1"); 
user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.33.3.1\",\"InstallEventCTime\":1377364580860,\"InstallEvent\":\"True\"}"); 
user_pref("iminent.webbooster.scripts.minibar.LayoutId", "1"); 
user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar"); 
user_pref("iminent.webbooster.scripts.minibar.Services.BHPCode", "01"); 
user_pref("iminent.webbooster.scripts.minibar.Services.DefaultEvent", "000"); 
user_pref("iminent.webbooster.scripts.minibar.Services.DefaultWebSite", "000"); 
user_pref("iminent.webbooster.scripts.minibar.Services.IminentClientCode", "11"); 
user_pref("iminent.webbooster.scripts.minibar.Services.SmartFavCode", "02"); 
user_pref("iminent.webbooster.scripts.minibar.ShowThankyouPixel", "0"); 
user_pref("iminent.webbooster.scripts.minibar.displayFavLinks", "1"); 
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent101", "1373634731091"); 
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent102", "1377360170464"); 
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1372930618349"); 
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1372930618358"); 
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent122", "1372930618366"); 
user_pref("iminent.webbooster.scripts.sslminibar.LayoutId", "1"); 
user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar"); 
user_pref("iminent.webbooster.scripts.sslminibar.Services.BHPCode", "01"); 
user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultEvent", "000"); 
user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultWebSite", "000"); 
user_pref("iminent.webbooster.scripts.sslminibar.Services.IminentClientCode", "11"); 
user_pref("iminent.webbooster.scripts.sslminibar.Services.SmartFavCode", "02"); 
user_pref("iminent.webbooster.scripts.sslminibar.ShowThankyouPixel", "0"); 
user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "0"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent101", "1373634734495"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent102", "1377360164965"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent109", "1377358709243"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent111", "1377358709255"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent112", "1377350689431"); 
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent122", "1377358709263"); 
Emptied folder: C:\Users\LOOP PARA\AppData\Roaming\mozilla\firefox\profiles\h1dvoqqj.default\minidumps [16 files]       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 28.08.2013 at 16:17:34,05 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~      |