So ich habs nun geschafft :)
Hier die Log vom Adw Cleaner: Code:
# AdwCleaner v1.800 - Logfile created 08/03/2012 at 17:13:32
# Updated 01/08/2012 by Xplode
# Operating system : Windows 7 Ultimate (64 bits)
# User : T - T-PC
# Running from : C:\Users\T\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Users\T\AppDaTa\Local\vghd
Deleted on reboot : C:\Users\T\AppDaTa\LocalLow\Conduit
Deleted on reboot : C:\Users\T\AppDaTa\LocalLow\Winload
Deleted on reboot : C:\Users\T\AppDaTa\Roaming\loadtbs
Deleted on reboot : C:\Users\T\AppDaTa\Roaming\Mozilla\Firefox\Profiles\vf8abre1.default\Smartbar
***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2319825
Key Deleted : HKCU\Software\APN DTX
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DT Soft
Key Deleted : HKLM\SOFTWARE\Freeze.com
Key Deleted : HKLM\SOFTWARE\Winload
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94366E2C-9923-431C-B0D6-747447DD0F2B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4D494D9D-1436-41D8-AC95-35AA4F4AEFAF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94366E2C-9923-431C-B0D6-747447DD0F2B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{664DCF12-5FED-45A3-95BA-52BE84107CA5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A57AE04-3187-40C8-B158-9C2854626E0A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4D494D9D-1436-41D8-AC95-35AA4F4AEFAF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.7600.16385
[OK] Registry is clean.
-\\ Mozilla Firefox v14.0.1 (de)
Profile name : default
File : C:\Users\T\AppDaTa\Roaming\Mozilla\Firefox\Profiles\vf8abre1.default\prefs.js
C:\Users\T\AppDaTa\Roaming\Mozilla\Firefox\Profiles\vf8abre1.default\user.js ... Deleted !
Deleted : user_pref("CT2319825.1000082.isPlayDisplay", "true");
Deleted : user_pref("CT2319825.1000082.state", "{\"state\":\"stopped\",\"text\":\"1Live\",\"description\":\"1L[...]
Deleted : user_pref("CT2319825.1000234.TWC_TMP_city", "BERLIN");
Deleted : user_pref("CT2319825.1000234.TWC_TMP_country", "DE");
Deleted : user_pref("CT2319825.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT2319825.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Deleted : user_pref("CT2319825.FirstTime", "true");
Deleted : user_pref("CT2319825.FirstTimeFF3", "true");
Deleted : user_pref("CT2319825.ID", "47760400");
Deleted : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT231[...]
Deleted : user_pref("CT2319825.UserID", "UN70556239186142540");
Deleted : user_pref("CT2319825.addressBarTakeOverEnabledInHidden", "true");
Deleted : user_pref("CT2319825.autoDisableScopes", -1);
Deleted : user_pref("CT2319825.browser.search.defaultthis.engineName", "");
Deleted : user_pref("CT2319825.defaultSearch", "true");
Deleted : user_pref("CT2319825.embeddedsData", "[{\"appId\":\"128898076802619666\",\"apiPermissions\":{\"cross[...]
Deleted : user_pref("CT2319825.enableAlerts", "always");
Deleted : user_pref("CT2319825.enableSearchFromAddressBar", "true");
Deleted : user_pref("CT2319825.firstTimeDialogOpened", "true");
Deleted : user_pref("CT2319825.fixPageNotFoundError", "true");
Deleted : user_pref("CT2319825.fixPageNotFoundErrorInHidden", "true");
Deleted : user_pref("CT2319825.fixUrls", true);
Deleted : user_pref("CT2319825.installId", "ConduitNSISIntegration");
Deleted : user_pref("CT2319825.installType", "ConduitNSISIntegration");
Deleted : user_pref("CT2319825.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT2319825.isNewTabEnabled", true);
Deleted : user_pref("CT2319825.isPerformedSmartBarTransition", "true");
Deleted : user_pref("CT2319825.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Deleted : user_pref("CT2319825.keyword", true);
Deleted : user_pref("CT2319825.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%[...]
Deleted : user_pref("CT2319825.openThankYouPage", "false");
Deleted : user_pref("CT2319825.openUninstallPage", "true");
Deleted : user_pref("CT2319825.search.searchAppId", "128898076802619666");
Deleted : user_pref("CT2319825.search.searchCount", "0");
Deleted : user_pref("CT2319825.searchInNewTabEnabledInHidden", "true");
Deleted : user_pref("CT2319825.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT2319825.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Deleted : user_pref("CT2319825.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Deleted : user_pref("CT2319825.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data[...]
Deleted : user_pref("CT2319825.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1343408566364");
Deleted : user_pref("CT2319825.serviceLayer_services_appTracking_lastUpdate", "1343408567596");
Deleted : user_pref("CT2319825.serviceLayer_services_appsMetadata_lastUpdate", "1343408566034");
Deleted : user_pref("CT2319825.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1343408566489");
Deleted : user_pref("CT2319825.serviceLayer_services_login_10.10.20.14_lastUpdate", "1343408566818");
Deleted : user_pref("CT2319825.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1343408566515");
Deleted : user_pref("CT2319825.serviceLayer_services_searchAPI_lastUpdate", "1343408565785");
Deleted : user_pref("CT2319825.serviceLayer_services_serviceMap_lastUpdate", "1343408565632");
Deleted : user_pref("CT2319825.serviceLayer_services_toolbarContextMenu_lastUpdate", "1343408566465");
Deleted : user_pref("CT2319825.serviceLayer_services_toolbarSettings_lastUpdate", "1343408565787");
Deleted : user_pref("CT2319825.serviceLayer_services_translation_lastUpdate", "1343408566036");
Deleted : user_pref("CT2319825.settingsINI", true);
Deleted : user_pref("CT2319825.shouldFirstTimeDialog", "false");
Deleted : user_pref("CT2319825.smartbar.CTID", "CT2319825");
Deleted : user_pref("CT2319825.smartbar.Uninstall", "0");
Deleted : user_pref("CT2319825.smartbar.homepage", true);
Deleted : user_pref("CT2319825.smartbar.toolbarName", "Winload ");
Deleted : user_pref("CT2319825.toolbarBornServerTime", "27-7-2012");
Deleted : user_pref("CT2319825.toolbarCurrentServerTime", "27-7-2012");
Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=1[...]
Deleted : user_pref("Smartbar.ConduitSearchEngineList", "Winload Customized Web Search");
Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825[...]
Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT2319825");
*************************
AdwCleaner[R1].txt - [9001 octets] - [03/08/2012 16:37:44]
AdwCleaner[S1].txt - [8472 octets] - [03/08/2012 17:13:32]
########## EOF - C:\AdwCleaner[S1].txt - [8600 octets] ########## Und hier vom Emisoft Anti-Malware: Code:
Emsisoft Anti-Malware - Version 6.6
Letztes Update: 04.08.2012 15:29:49
Scan Einstellungen:
Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, E:\, F:\
Archiv Scan: An
ADS Scan: An
Scan Beginn: 04.08.2012 15:30:21
C:\Users\T\Desktop\Neuer Ordner\Neuer Ordner\files\zergRush gefunden: Exploit.Linux.Lotoor!E2
C:\Users\T\Desktop\Neuer Ordner\data\zergRush gefunden: Exploit.Linux.Lotoor!E2
C:\Users\T\AppData\Roaming\Thunderbird\Profiles\p5ihjktn.default\ImapMail\imap.gmx.net\Trash -> [unnamed] -> Schreiben.zip gefunden: Trojan-Dropper.Win32.Injector!E2
C:\Users\T\AppData\Roaming\Thunderbird\Profiles\p5ihjktn.default\ImapMail\imap.gmx.net\Trash -> [unnamed] -> Schreiben.zip -> Schreiben 10.07.2012 .com gefunden: Trojan-Dropper.Win32.Injector!E2
Gescannt 588705
Gefunden 4
Scan Ende: 04.08.2012 15:54:33
Scan Zeit: 0:24:12 |