DarkShinigami said:
alright there are a few unrecognized files in there
one is a dll called omibiberer.dll
mywebsearch
my own superhero
and guffins
•mywebsearch : I don't know this one, but I'm always against additional search bar integrated to the system or web-browser. They are changing setting of their own without asking, they are intrusive
It could be the problem. if you never installed it manually, it could have been installed with another program without asking your authorization first.
Check the "add&delete program" function in your windows config pannel and delete it.
•my own superhero (.com) redirect to facebook.
Maybe it's an application you used and it installed something to work with facebook. I don't know if it's dangerous.
•guffins : a website for pet adoption. maybe a game, or a facebook application again?
It shouldn't harm either.
So first uninstall mywebsearch if you can. (let me know if you can find it in the installed program list).
•Now about the dll :
It's definitely suspect
even more suspect that nothing retuns on google except your post here. It's certainly a randomly named adware.
1- In autoruns you have the path were the .dll is located.
2- Open the task manager, check if the dll program is running (same path as the dll, or a temporary path like user//temporary files/notepad.exe, or e.exe, f.exe etc. sometime both at the same time, each spying on the other one to prevent killing them both)
I recommend using this task manager :
http://download.sysinternals.com/Files/ProcessExplorer.zip , you can see path and kill all dependence tree at once with it).
3- if present, kill the process and check if the program is launched again automatically.
If not, you are lucky!
4- in autoruns, right-click the line of the .dll and delete it (for safety you can just untick the checkbox instead of deleting it if you ever want to enable it back).
5- in the .dll folder, delete the .dll and/or all the content
6- delete the temporary fake program if one is running in temp folder.
Sometime, deleting the program in autoruns is detected by the malware and added back, that's why you have to kill the program first.