Hier die Logfile aus dem Notepad:
[ Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Datenbank Version: 5442
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
02.01.2011 15:08:19
mbam-log-2011-01-02 (15-08-19).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 289381
Laufzeit: 1 Stunde(n), 1 Minute(n), 43 Sekunde(n)
Infizierte Speicherprozesse: 1
Infizierte Speichermodule: 1
Infizierte Registrierungsschlüssel: 5
Infizierte Registrierungswerte: 4
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 12
Infizierte Speicherprozesse:
c:\programme\application updater\applicationupdater.exe (PUP.Dealio) -> 1432 -> Unloaded process successfully.
Infizierte Speichermodule:
c:\programme\gemeinsame dateien\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAMME\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAMME\GEMEINSAME DATEIEN\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
c:\programme\application updater\applicationupdater.exe (PUP.Dealio) -> Quarantined and deleted successfully.
c:\programme\gemeinsame dateien\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\programme\pdfforge toolbar\IE\4.1\pdfforgetoolbarie.dll (PUP.Dealio) -> Quarantined and deleted successfully.
c:\programme\pdfforge toolbar\widgihelper.exe (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059384.rbf (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059387.rbf (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059389.rbf (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059397.old (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059398.old (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059399.old (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059400.old (PUP.Dealio) -> Quarantined and deleted successfully.
c:\system volume information\_restore{dbef6e60-c5c5-47e2-8e78-49320d8cfcdd}\RP175\A0059401.old (PUP.Dealio) -> Not selected for removal. ]