kurabiye | 28.04.2015 20:52 | Hallo! Erst mal: Vieeeeelen Dank für die schnelle Antwort :D
Habe alles nach Anleitung gemacht, die logfiles in der Reihenfolge:
mbam tägliches Scanprotokoll
mbam scan logfile
AdwCleaner logfile
JRT
Frst
Addition
Vielen Dank nochmals :) :) :) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 28.04.2015 20:15:30, SYSTEM, KARAKEDI, Manual, Rootkit Database, 2015.2.25.1, 2015.4.21.1,
Update, 28.04.2015 20:15:30, SYSTEM, KARAKEDI, Manual, Remediation Database, 2015.3.9.1, 2015.4.22.1,
Protection, 28.04.2015 20:15:31, SYSTEM, KARAKEDI, Protection, Malware Protection, Starting,
Protection, 28.04.2015 20:15:31, SYSTEM, KARAKEDI, Protection, Malware Protection, Started,
Protection, 28.04.2015 20:15:31, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Starting,
Protection, 28.04.2015 20:15:32, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Started,
Update, 28.04.2015 20:15:35, SYSTEM, KARAKEDI, Manual, Malware Database, 2015.3.9.5, 2015.4.28.5,
Protection, 28.04.2015 20:15:36, SYSTEM, KARAKEDI, Protection, Refresh, Starting,
Protection, 28.04.2015 20:15:36, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Stopping,
Protection, 28.04.2015 20:15:36, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Stopped,
Protection, 28.04.2015 20:15:48, SYSTEM, KARAKEDI, Protection, Refresh, Success,
Protection, 28.04.2015 20:15:48, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Starting,
Protection, 28.04.2015 20:15:48, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Started,
Scan, 28.04.2015 21:08:52, SYSTEM, KARAKEDI, Manual, Start: 28.04.2015 20:16:05, Dauer: 31 Minuten 15 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 1 Malwareerkennung, "63" nicht-Malwareerkennung,
Protection, 28.04.2015 21:11:55, SYSTEM, KARAKEDI, Protection, Malware Protection, Starting,
Protection, 28.04.2015 21:11:55, SYSTEM, KARAKEDI, Protection, Malware Protection, Started,
Protection, 28.04.2015 21:11:55, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Starting,
Protection, 28.04.2015 21:12:30, SYSTEM, KARAKEDI, Protection, Malicious Website Protection, Started,
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.04.2015
Suchlauf-Zeit: 20:16:05
Logdatei: mbam_logfile.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.04.28.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Hobbes
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 421252
Verstrichene Zeit: 31 Min, 15 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor.exe, 1596, Löschen bei Neustart, [d02589e81674b086eac9b3a8cb3a0af6]
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor_run.exe, 1632, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0]
Module: 10
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor_run.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\imdt.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcp100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcp100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcr100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcr100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\qjdwk.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\mvhav.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\yxflk.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\zntxjbb.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
Registrierungsschlüssel: 2
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [e411422f95f5ae88c438e99a649f27d9],
PUP.Optional.CopyEditor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CopyEditor, In Quarantäne, [d02589e81674b086eac9b3a8cb3a0af6],
Registrierungswerte: 2
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [668fa0d1cbbf072f0c63fdf5e51eb34d]
PUP.Optional.SonicSearch.A, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}|URL, hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q={searchTerms}, In Quarantäne, [fff62849f595d660b8d6392235d02cd4]
Registrierungsdaten: 5
PUP.Optional.CopyEditor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\oktr.dll, Gut: (), Schlecht: (C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\oktr.dll),Ersetzt,[b34292df16746fc707d49b2a887b30d0]
PUP.Optional.CopyEditor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\votuniu.dll, Gut: (), Schlecht: (C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\votuniu.dll),Ersetzt,[b34292df16746fc707d49b2a887b30d0]
PUP.Optional.SonicSearch.T, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q={searchTerms}),Ersetzt,[c431e1905238cc6a60d8926fc44232ce]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoilcoqaSJCqmyqlDaKMB7DhrEBj_4rD6lzXgwPTPkk-9CQ26oLwjxpDCB5lpV4h2_dFQ3nctuz_OEpw,,, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoilcoqaSJCqmyqlDaKMB7DhrEBj_4rD6lzXgwPTPkk-9CQ26oLwjxpDCB5lpV4h2_dFQ3nctuz_OEpw,,),Ersetzt,[30c548299cee8bab84ef3ec263a3d828]
PUP.Optional.SonicSearch.T, HKU\S-1-5-21-1299973341-2301843273-3047008240-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q={searchTerms}),Ersetzt,[9560571accbe54e2ac8c996804029e62]
Ordner: 2
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
Dateien: 41
PUP.Optional.ClientConnect, C:\Users\Hobbes\Downloads\SweetJava_TSA1Y1RJ2.exe, In Quarantäne, [63921061a8e27db97e9aae225ca530d0],
Adware.Linkular, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\ngakg.dll, In Quarantäne, [de17274abad0f442774307ed13f2de22],
PUP.Optional.WebSearch.A, C:\Users\Hobbes\AppData\Roaming\Mozilla\Firefox\Profiles\evayqiaa.default\searchplugins\Web Search.xml, In Quarantäne, [37be6c05f3979c9a214e9973da2a45bb],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor.exe, Löschen bei Neustart, [d02589e81674b086eac9b3a8cb3a0af6],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\app.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor_run.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor_run.exe, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\CopyEditor_run.exe.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\imdt.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcp100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\msvcr100.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\mtmdr, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\mtmuc.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\mupxgeuc.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\nrcmjg.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\qjdwk.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\rudaci.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\run.log, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\service.sqlite, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\Uninstaller.exe, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\bgiat.exe.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\conf.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\epjnsq.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\labq.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\lfwftbs.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\mbweivan.exe, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\mbweivan.exe.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\mvhav.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\mypi.exe.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\ngakg.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\oktgez.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\oktr.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\qvtvluop.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\rrqsx.exe.config, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\Timers.xml, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\votuniu.dll, In Quarantäne, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\yxflk.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.CopyEditor.A, C:\Users\Hobbes\AppData\Local\CopyEditor\ghpk\zntxjbb.dll, Löschen bei Neustart, [b34292df16746fc707d49b2a887b30d0],
PUP.Optional.SnapDo.A, C:\Users\Hobbes\AppData\Roaming\Mozilla\Firefox\Profiles\evayqiaa.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoilGhTB1K0ub-WMbhVexoyFbt9evt_6OU0iJmV9DSLUkcQvO2htfRghW5gFOprNAVllEH7Zs6IShlRw,,");), Ersetzt,[1adb472af09a72c44944ac9d5da99c64]
PUP.Optional.SnapDo.A, C:\Users\Hobbes\AppData\Roaming\Mozilla\Firefox\Profiles\evayqiaa.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoilcoqaSJCqmyqlDaKMB7DhrEBj_4rD6lzXgwPTPkk-9CQ26oLwjxpDCB5lpV4h2_dFQ3nctuz_OEpw,,");), Ersetzt,[ae47640d4f3b31056f2049009b6b49b7]
PUP.Optional.SonicSearch.T, C:\Users\Hobbes\AppData\Roaming\Mozilla\Firefox\Profiles\evayqiaa.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.sonic-search.com/?p=mKO_AwFzXIpYRa4j3q-3hUPE9a9InJ9YovTwLIQAT9Pa3aeCIuYbpIydrFZ43x_462PFUyC8iuhlx_bH4iHcwK0TcXCWcZ1-KCrBlQTO8TuwXjhoiltM1oTUCvtXL18BPbzVuXB8Kiut_HEl1fwpeQE-78a9ubNiTqIccVw6NQrhv5QJckHRz6LfVgp-lA,,&q=");), Ersetzt,[8f662d44fe8c61d515d4f456b45228d8]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.202 - Bericht erstellt 28/04/2015 um 21:22:23
# Aktualisiert 23/04/2015 von Xplode
# Datenbank : 2015-04-27.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Hobbes - KARAKEDI
# Gestarted von : C:\Users\Hobbes\Downloads\AdwCleaner_4.202.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\{d49fd075-350b-38c3-d49f-fd07535041d4}
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKU\.DEFAULT\Software\Local AppWizard-Generated Applications
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:53990;hxxps=127.0.0.1:53990
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v37.0.1 (x86 de)
[evayqiaa.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
-\\ Google Chrome v42.0.2311.90
*************************
AdwCleaner[R0].txt - [3923 Bytes] - [12/04/2015 22:42:17]
AdwCleaner[R1].txt - [1791 Bytes] - [28/04/2015 21:19:49]
AdwCleaner[S0].txt - [3469 Bytes] - [12/04/2015 22:44:06]
AdwCleaner[S1].txt - [1490 Bytes] - [28/04/2015 21:22:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1549 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.6 (04.28.2015:1)
OS: Windows 8.1 x64
Ran by Hobbes on 28.04.2015 at 21:30:57,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\AviraSpeedup
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-1299973341-2301843273-3047008240-1004
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-1299973341-2301843273-3047008240-500
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3124938557-2334116980-2269491839-500
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.04.2015 at 21:35:37,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |