ADW cleaner hab ich durchlaufen lassen und das ergebnis sieht so aus
Code
# AdwCleaner v4.113 - Bericht erstellt 29/03/2015 um 18:10:47
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-28.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : HB - HB-PC
# Gestarted von : C:\Users\HB\Downloads\adwcleaner_4.113.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\HB\AppData\Roaming\Mozilla\Firefox\Profiles\ek3pc810.default\user.js
Ordner Gefunden : C:\Program Files (x86)\SiteLookup
Ordner Gefunden : C:\Users\HB\AppData\LocalLow\sitefinder
Ordner Gefunden : C:\Users\HB\AppData\Roaming\Security Systems
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\Mozilla\Extends
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\systweak
Schlüssel Gefunden : [x64] HKCU\Software\APN PIP
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\systweak
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\istart123Software
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.4 (x86 de)
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.plugin@searchgby.com.install-event-fired", true);
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.data", "{ \"v\":\"1.1\", \"help\": \"hxxp://searchgby.com/pages/help/\", \"news\":{ \"news\":[ \"hxxp://www.cnn.com/\", \"hxxp://cbsnews.com/\", \"hxxp://abcnews.go.com[...]
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.dd", "1399844288417");
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.dd.data", "{\"v\":\"1.5\",\"ip\":\"83.135.167.68\",\"widget\":{\"meta\": {\"code\": 200},\"response\": {\"deals\": []}}}");
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.lastupdate", "1399972289700");
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.osearch", false);
[ek3pc810.default] - Zeile Gefunden : user_pref("extensions.searchgby.thumbs", false);
*************************
AdwCleaner[R0].txt - [5196 Bytes] - [27/07/2014 03:18:19]
AdwCleaner[R1].txt - [923 Bytes] - [27/07/2014 03:26:53]
AdwCleaner[R2].txt - [1041 Bytes] - [27/07/2014 03:32:23]
AdwCleaner[R3].txt - [3677 Bytes] - [28/03/2015 10:42:01]
AdwCleaner[R4].txt - [3406 Bytes] - [29/03/2015 18:10:47]
AdwCleaner[S0].txt - [4236 Bytes] - [27/07/2014 03:22:30]
AdwCleaner[S1].txt - [983 Bytes] - [27/07/2014 03:29:47]
AdwCleaner[S2].txt - [1103 Bytes] - [27/07/2014 03:35:03]
########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [3641 Bytes] ##########
Alles anzeigen
Edit 2002Andreas
Text in Klammercode gesetzt.