Hi Jürgen, danke schon einmal, dass du mir hilfst :)
Hier schon einmal die Logdatei aus Schritt 2: Code:
# AdwCleaner v4.107 - Bericht erstellt am 13/01/2015 um 20:37:30
# Aktualisiert 07/01/2015 von Xplode
# Database : 2015-01-13.2 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Maike - MAIKE-PC
# Gestartet von : c:\Users\Maike\Downloads\adwcleaner_4.107.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\Extensions\BH8@L0I4xk13.edu
Ordner Gelöscht : C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\Extensions\Es@3BH9t.com
Datei Gelöscht : C:\Windows\Reimage.ini
Datei Gelöscht : C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
Datei Gelöscht : C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Reimage
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0 (x86 de)
[mdz7ctkd.default\prefs.js] - Zeile gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[mdz7ctkd.default\prefs.js] - Zeile gelöscht : user_pref("extensions.8RItSA6CYrRIU6TD.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[mdz7ctkd.default\prefs.js] - Zeile gelöscht : user_pref("extensions.uRdCgCztxTeKfB9k.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
-\\ Google Chrome v39.0.2171.95
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=8CC900FF4024642D&affID=119357&tl=3273868&tt=070713_91114&tsp=4936
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis&mntrId=8CC900FF4024642D&affID=119357&tl=3273868&tt=070713_91114&tsp=4936
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis&mntrId=8CC900FF4024642D&affID=119357&tl=3273868&tt=070713_91114&tsp=4936
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis&mntrId=8CC900FF4024642D&affID=119357&tl=3273868&tt=070713_91114&tsp=4936
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST750LM022XHN-M750MBB_S2USJ9AC304368&ts=1376996840&type=default&q={searchTerms}
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST750LM022XHN-M750MBB_S2USJ9AC304368&ts=1377285204&type=default&q={searchTerms}
[C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=2921&r=2015/01/11&hid=2135232739592073866&lg=EN&cc=DE&unqvl=74
*************************
AdwCleaner[R0].txt - [105641 octets] - [02/01/2014 12:34:57]
AdwCleaner[R1].txt - [9037 octets] - [13/01/2015 17:56:38]
AdwCleaner[R2].txt - [4213 octets] - [13/01/2015 20:34:48]
AdwCleaner[S0].txt - [101922 octets] - [02/01/2014 12:45:13]
AdwCleaner[S1].txt - [8638 octets] - [13/01/2015 17:59:03]
AdwCleaner[S2].txt - [4099 octets] - [13/01/2015 20:37:30]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4159 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.01.2015
Suchlauf-Zeit: 20:52:29
Logdatei:
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.13.15
Rootkit Datenbank: v2015.01.07.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Maike
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 353781
Verstrichene Zeit: 16 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 10
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}, In Quarantäne, [2771e90bef9a70c67d2444bc36cc57a9],
PUP.Optional.AdLyrics.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\cjkpeelhbaipjkogeledgpkllepmkdmc, In Quarantäne, [7f1970848bfe63d35c3a8b61e71dcc34],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
Registrierungswerte: 1
PUP.Optional.AdLyrics.A, HKU\S-1-5-21-141412449-1442800650-3382891103-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|lrcsearch@bjornet.net, C:\Program Files (x86)\LyricSearch\FF\, In Quarantäne, [9afe5d97e0a96dc9445b28c41ee659a7]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 10
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\content, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\content\images, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\defaults, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\defaults\preferences, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0, In Quarantäne, [e9afcd273f4a9b9b0559f04df90a2cd4],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.FreeHD.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\jetpack\fhdp@fhdp.tv, In Quarantäne, [edab6f8586033402f68fb28fac57738d],
PUP.Optional.FreeHD.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\jetpack\fhdp@fhdp.tv\simple-storage, In Quarantäne, [edab6f8586033402f68fb28fac57738d],
Dateien: 27
Trojan.Agent, C:\Program Files (x86)\uniusalese\uniusalese.exe, In Quarantäne, [9701a2520a7ffd394a57b14f25dde21e],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.dll, In Quarantäne, [d9bf3aba1277df576c85166fcf366f91],
Trojan.Agent, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.exe, In Quarantäne, [52465c98b7d2d066772af70912f09e62],
Trojan.Agent, C:\Program Files (x86)\RSS Subscription Extension by Google\RSS Subscription Extension by Google.exe, In Quarantäne, [2771e90bef9a70c67d2444bc36cc57a9],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\uanisalleS\4r6eW3M9Rc6ER1.dll, In Quarantäne, [9dfb767e7a0fde584ba6572e07fea858],
Trojan.Agent, C:\Program Files (x86)\uanisalleS\4r6eW3M9Rc6ER1.exe, In Quarantäne, [cfc9cd276425a78f5849d82831d11ee2],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0.localstorage, In Quarantäne, [2a6e6d87c0c971c51570e1c1f310fa06],
PUP.Optional.ReMarkable.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Löschen bei Neustart, [0890aa4ac6c348ee5105be2e877d19e7],
PUP.Optional.ReMarkable.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Löschen bei Neustart, [d7c19c583c4dbc7a7dd99a5229db7c84],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.dat, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.exe, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.tlb, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\S2F9s4qSyz3940.x64.dll, In Quarantäne, [cace8f65e4a53afc6def84b359aaae52],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\chrome.manifest, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\install.rdf, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\content\bargainjoy.xul, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\content\images\32.png, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.BargainJoy.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}\defaults\preferences\defaults.js, In Quarantäne, [6f2939bbd0b954e251826ece8281a25e],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\1, In Quarantäne, [e9afcd273f4a9b9b0559f04df90a2cd4],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\2, In Quarantäne, [e9afcd273f4a9b9b0559f04df90a2cd4],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\000009.log, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\CURRENT, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\LOCK, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\LOG, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\LOG.old, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.CrossRider.A, C:\Users\Maike\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\MANIFEST-000007, In Quarantäne, [ceca09ebc9c04aec91d1df5e897aba46],
PUP.Optional.FreeHD.A, C:\Users\Maike\AppData\Roaming\Mozilla\Firefox\Profiles\mdz7ctkd.default\jetpack\fhdp@fhdp.tv\simple-storage\store.json, In Quarantäne, [edab6f8586033402f68fb28fac57738d],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) |