Sie sind auf Seite 1von 2

start

C:\Program Files\569B28CA-75D1-4EA2-9778-830E01DBBC88\cnfygfszki.exe
C:\Program Files\005\jxbalvtmyz32.exe
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96
DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAE
F20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274
A524} => No File
ShellIconOverlayIdentifiers: ExplorerEx -> {E056AFDD-03E9-4D73-8D33-8FCCBCA7
3438} => No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplor
e.exe http://istart.webssearches.com/?type=sc&ts=1406813021&from=amt&uid=SAMSUNG
XHD080HJ_S08EJ1TLB06440
SearchScopes: HKLM - DefaultScope {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL
=
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://ist
art.webssearches.com/web/?type=ds&ts=1406813021&from=amt&uid=SAMSUNGXHD080HJ_S08
EJ1TLB06440&q={searchTerms}
SearchScopes: HKLM - {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL =
BHO: Mercan Programlar Toolbar -> {b475cfd8-45d8-4905-b319-ad995327abeb} ->
C:\Program Files\Mercan_Programlar\tbMer0.dll No File
BHO: AllDaySavings -> {fbdff406-2c4c-5d35-8469-34bb67ea3353} -> C:\Program F
iles\569B28CA-75D1-4EA2-9778-830E01DBBC88\kzhxnitccw.dll ()
Toolbar: HKLM - Mercan Programlar Toolbar - {b475cfd8-45d8-4905-b319-ad99532
7abeb} - C:\Program Files\Mercan_Programlar\tbMer0.dll No File
DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0
/jinstall-1_7_0_51-windows-i586.cab
FF ProfilePath: C:\Users\TEMP.ECE\AppData\Roaming\Mozilla\Firefox\Profiles\y
yxrht0w.default
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\portalsepeti
.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webssearches
.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yand
ex-tr.xml
C:\Program Files\569B28CA-75D1-4EA2-9778-830E01DBBC88\nfapi.dll
C:\Program Files\569B28CA-75D1-4EA2-9778-830E01DBBC88\cnfygfszki.exe
C:\Program Files\569B28CA-75D1-4EA2-9778-830E01DBBC88\ProtocolFilters.dll
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32
\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\G
oogle\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Goo
gle\Update\GoogleUpdate.exe
Task: {B3BC1D3B-CCC2-40B3-9DFE-B08BFD8C4A4B} - System32\Tasks\GoogleUpdateTa
skMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: {A1674E79-12D2-4F67-A324-748F78ADBB72} - System32\Tasks\AmiUpdXp => C:
\Users\user.ZEKI\AppData\Local\20512\a2158.exe <==== ATTENTION
CHR Extension: (Ebay Shopping Assistant by Spigot) - C:\Users\TEMP.ECE\AppDa
ta\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcad
eocj
CHR Extension: (Amazon Shopping Assistant by Spigot) - C:\Users\TEMP.ECE\App
Data\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancn
lgocpp [2014-09-22]
CHR HKLM\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Progr
am Files\Common Files\Spigot\GC\saebay_1.1.crx [2013-10-14]
CHR HKLM\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Progr
am Files\Common Files\Spigot\GC\ErrorAssistant_1.3.crx [2013-12-27]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Progr
am Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Users
\user\AppData\Local\Slick Savings\coupons.crx [2014-01-20]
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Progr
am Files\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx [2014-01-20
]
CHR HKLM\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Progr
am Files\Common Files\Spigot\GC\saamazon_1.0.crx
R2 AllDaySavingsService; C:\Program Files\569B28CA-75D1-4EA2-9778-830E01DBBC
88\cnfygfszki.exe
R2 jxbalvtmyz32; C:\Program Files\005\jxbalvtmyz32.exe [543232 2014-07-31] (
) [File not signed]
S2 Sed; C:\Users\user.ZEKI\AppData\Roaming\ntsvc\ntsvc.exe
S3 VGPU; System32\drivers\rdvgkmd.sys
C:\Users\TEMP.ECE\AppData\Roaming\ProductData
C:\Program Files\AllDaySavings
C:\ProgramData\ProductData
C:\Users\user\AppData\Local\Temp\AskSLib.dll
C:\Program Files\005
end

Das könnte Ihnen auch gefallen