|
Plagegeister aller Art und deren Bekämpfung: Trojaner BMI AKM PaysafeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.08.2012, 21:32 | #1 |
| Trojaner BMI AKM Paysafe Hallo.... Also eins gleich mal vor weg, so wie der PC nicht tut wie ich will, bin ich ein absoluter noob. Und nun ist es passiert dass ich mir einen Trojaner eingefangen habe, und nach Stunden des Versuchens nicht mehr weiterkomme. Habe mich durchgegoogelt und hier durchgesehen.... Also es kommt bei mir so ne seite, dass ich illegale Musik am PC hätte, und der PC solage gesperrt bleibt bis ich 100 Euronen an das Bundesministerium für Inneres in Österreich per paysafe überweise. Ich hab dann den PC in abgesicherten Modus gestartet und per OLT einen Scan durchgeführt. Nur was nun? Ich bitte um Hilfe! Danke und hier noch mal den bericht ungezippt OTL Logfile: Code:
ATTFilter OTL logfile created on: 3/4/2012 4:59:32 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 298.08 Gb Total Space | 233.91 Gb Free Space | 78.47% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet003 ========== Win32 Services (SafeList) ========== SRV - [2012/02/28 11:38:52 | 001,373,576 | ---- | M] (LogMeIn Inc.) [Auto] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012/02/08 13:29:37 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/12/15 08:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011/12/15 08:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011/06/14 07:24:54 | 000,073,600 | ---- | M] () [Auto] -- C:\WINDOWS\system32\ezGOSvc.dll -- (ezGOSvc) SRV - [2011/01/28 06:22:50 | 000,632,792 | ---- | M] (PC Tools) [Auto] -- C:\Programme\Gemeinsame Dateien\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc) SRV - [2010/01/15 07:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009/08/18 04:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2008/11/03 19:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006/10/26 08:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (XDva387) DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - [2012/02/16 12:37:18 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2011/12/15 09:00:00 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011/12/15 09:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010/06/17 08:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010/02/24 05:22:10 | 000,185,472 | ---- | M] (Protect Software GmbH) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\acedrv11.sys -- (acedrv11) DRV - [2009/03/18 11:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2008/09/18 05:48:58 | 004,816,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008/06/30 22:27:44 | 000,108,800 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2005/10/26 11:06:30 | 000,356,096 | R--- | M] (Ralink Technology Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61) Linksys Wireless-G PCI Adapter Driver(RT61) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Eder_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3031778 IE - HKU\Eder_ON_C\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) IE - HKU\Eder_ON_C\..\URLSearchHook: {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) IE - HKU\Eder_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "DVDVideoSoftTB Customized Web Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13" FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012/02/19 05:12:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011/11/26 10:47:24 | 000,000,000 | ---D | M] [2009/11/16 14:37:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Extensions [2012/02/15 13:23:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Firefox\Profiles\becityet.default\extensions [2012/02/15 13:23:50 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Firefox\Profiles\becityet.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2011/09/26 10:58:46 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Firefox\Profiles\becityet.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012/01/24 12:28:15 | 000,000,000 | ---D | M] (SFT_de3 Community Toolbar) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Firefox\Profiles\becityet.default\extensions\{ff88a983-649d-4207-9336-9b999280b436} [2011/08/31 04:25:40 | 000,000,931 | ---- | M] () -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Mozilla\Firefox\Profiles\becityet.default\searchplugins\conduit.xml [2012/01/08 06:31:12 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2011/11/07 14:04:10 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} File not found (No name found) -- () (No name found) -- C:\DOKUMENTE UND EINSTELLUNGEN\EDER\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\BECITYET.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI [2012/02/19 05:12:11 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2011/11/26 08:31:18 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2011/10/06 08:28:32 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2011/10/06 08:28:32 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2011/10/06 08:28:31 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2011/10/06 08:28:31 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2011/10/06 08:28:31 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2011/10/06 08:28:31 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2001/08/23 07:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.) O2 - BHO: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O3 - HKU\Eder_ON_C\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O3 - HKU\Eder_ON_C\..\Toolbar\WebBrowser: (SFT_de3 Toolbar) - {FF88A983-649D-4207-9336-9B999280B436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [VX2bt1oYNKCLnkO] C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O4 - HKU\Eder_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\Eder_ON_C..\Run: [VX2bt1oYNKCLnkO] C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258401056984 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKLM Winlogon: UserInit - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKU\Eder_ON_C Winlogon: Shell - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKU\Eder_ON_C Winlogon: UserInit - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012/02/08 13:14:37 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2009/11/16 14:10:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell - "" = AutoRun O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL start.hta O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell\runthat\command - "" = J:\components\shelexec.exe start.hta O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/03/03 07:28:57 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2012/03/01 09:49:03 | 000,308,224 | ---- | C] (Cutting Edge Software Inc.) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe [2012/02/29 09:19:18 | 000,000,000 | ---D | C] -- C:\Programme\LogMeIn Hamachi [2012/02/29 09:19:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\LogMeIn Hamachi [2012/02/08 13:40:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FLEXnet [2012/02/08 13:35:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Eder\Eigene Dateien\Autodesk [2012/02/08 13:29:37 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared [2012/02/08 13:29:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autodesk [2012/02/08 13:27:27 | 000,000,000 | ---D | C] -- C:\ProgramData [2012/02/08 13:27:27 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Eder\Lokale Einstellungen\Anwendungsdaten\Autodesk [2012/02/08 13:27:27 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Autodesk [2012/02/08 13:27:27 | 000,000,000 | ---D | C] -- C:\Programme\AutoCAD Architecture 2010 [2012/02/08 13:26:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodesk [2012/02/08 13:14:37 | 000,000,000 | ---D | C] -- C:\Autodesk [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/03/04 10:42:25 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/03/04 10:41:50 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012/03/04 10:41:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/03/03 07:12:01 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012/03/01 09:49:02 | 000,308,224 | ---- | M] (Cutting Edge Software Inc.) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe [2012/02/29 14:38:32 | 000,002,241 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Skype.lnk [2012/02/29 13:00:22 | 000,000,244 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job [2012/02/29 09:19:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\LogMeIn Hamachi [2012/02/25 03:06:53 | 000,002,503 | ---- | M] () -- C:\Dokumente und Einstellungen\Eder\Desktop\Microsoft Office Word 2007.lnk [2012/02/23 11:13:27 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eder.job [2012/02/19 12:06:53 | 000,002,607 | ---- | M] () -- C:\Dokumente und Einstellungen\Eder\Desktop\Microsoft Office Outlook 2007.lnk [2012/02/17 10:18:17 | 000,001,777 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk [2012/02/16 13:18:12 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\Cache.db [2012/02/16 12:37:18 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2012/02/16 08:35:33 | 000,387,296 | ---- | M] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat [2012/02/16 07:46:32 | 000,349,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/02/16 07:28:55 | 000,452,236 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2012/02/16 07:28:55 | 000,435,396 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/02/16 07:28:55 | 000,081,306 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2012/02/16 07:28:55 | 000,068,292 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/02/16 07:24:18 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/02/08 13:36:10 | 000,001,967 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\AutoCAD Architecture 2010 - Deutsch (D A CH).lnk [2012/02/08 13:29:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autodesk [2012/02/05 13:13:55 | 000,002,505 | ---- | M] () -- C:\Dokumente und Einstellungen\Eder\Desktop\Microsoft Office Excel 2007.lnk [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/02/16 13:17:44 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\Cache.db [2012/02/16 07:17:38 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012/02/16 07:17:38 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll [2012/02/08 14:13:53 | 000,387,296 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat [2012/02/08 13:36:10 | 000,001,967 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\AutoCAD Architecture 2010 - Deutsch (D A CH).lnk [2011/10/09 02:51:45 | 000,000,074 | ---- | C] () -- C:\Dokumente und Einstellungen\Eder\default.pls [2011/08/19 06:52:03 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe [2011/06/16 07:01:50 | 000,073,600 | ---- | C] () -- C:\WINDOWS\System32\ezGOSvc.dll [2011/03/27 10:38:37 | 000,015,360 | ---- | C] () -- C:\Dokumente und Einstellungen\Eder\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/06/20 10:55:15 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2010/05/27 08:00:50 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2010/04/02 10:17:34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat [2009/12/23 10:31:13 | 000,000,281 | ---- | C] () -- C:\WINDOWS\SIERRA.INI [2009/11/16 14:37:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2009/11/16 14:23:14 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4990.dll [2009/11/16 14:23:13 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin [2009/11/16 14:23:13 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin [2009/11/16 14:11:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2009/11/16 14:07:03 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2009/11/16 13:41:46 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2009/11/16 13:40:38 | 000,349,792 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/05/20 23:24:48 | 000,001,683 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2008/11/05 13:42:45 | 000,062,400 | ---- | C] () -- C:\WINDOWS\System32\IFC.dll [2008/11/05 13:41:56 | 000,422,848 | ---- | C] () -- C:\WINDOWS\System32\PPL.dll [2004/08/03 19:12:38 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2004/08/02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2001/08/23 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2001/08/23 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2001/08/23 07:00:00 | 000,452,236 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat [2001/08/23 07:00:00 | 000,435,396 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2001/08/23 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2001/08/23 07:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat [2001/08/23 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2001/08/23 07:00:00 | 000,081,306 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat [2001/08/23 07:00:00 | 000,068,292 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2001/08/23 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2001/08/23 07:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat [2001/08/23 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2001/08/23 07:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2001/08/23 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat ========== LOP Check ========== [2012/02/15 14:02:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\.minecraft [2012/02/15 14:18:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Autodesk [2011/10/11 11:05:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Bentley [2011/09/26 10:59:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\DVDVideoSoft [2011/09/26 10:58:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\DVDVideoSoftIEHelpers [2011/10/18 10:41:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\go [2011/10/09 02:10:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\HTML Executable [2012/02/23 06:35:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\mcpatcher [2010/07/20 11:23:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Petroglyph [2012/03/01 09:12:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\PriceGong [2011/10/09 02:09:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\ProtectDISC [2012/02/16 13:18:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\Registry Mechanic [2012/02/08 13:31:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodesk [2011/10/11 11:05:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bentley [2011/10/18 12:22:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Easybits GO [2010/12/08 09:32:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NFS Underground [2012/02/29 13:00:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP [2012/02/29 13:00:22 | 000,000,244 | ---- | M] () -- C:\WINDOWS\Tasks\RMSchedule.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 113 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:D1B5B4F1 < End of report > Geändert von pewa (14.08.2012 um 22:27 Uhr) |
15.08.2012, 09:31 | #2 |
/// Helfer-Team | Trojaner BMI AKM PaysafeFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL DRV - File not found [Kernel | On_Demand] -- -- (XDva387) DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Eder_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3031778 IE - HKU\Eder_ON_C\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) IE - HKU\Eder_ON_C\..\URLSearchHook: {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) IE - HKU\Eder_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "DVDVideoSoftTB Customized Web Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2269050&SearchSource=13" FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198 FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=" File not found (No name found) -- O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O2 - BHO: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O3 - HKU\Eder_ON_C\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) O3 - HKU\Eder_ON_C\..\Toolbar\WebBrowser: (SFT_de3 Toolbar) - {FF88A983-649D-4207-9336-9B999280B436} - C:\Programme\SFT_de3\prxtbSFT0.dll (Conduit Ltd.) O4 - HKLM..\Run: [VX2bt1oYNKCLnkO] C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O4 - HKU\Eder_ON_C..\Run: [VX2bt1oYNKCLnkO] C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1 O7 - HKU\Eder_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKLM Winlogon: UserInit - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKU\Eder_ON_C Winlogon: Shell - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O20 - HKU\Eder_ON_C Winlogon: UserInit - (C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe) - C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe (Cutting Edge Software Inc.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/11/16 14:10:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell - "" = AutoRun O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{62ad569f-699d-11df-937e-001cc0c33542}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL start.hta O34 - HKLM BootExecute: (autocheck autochk *) - File not found [2012/03/01 09:49:03 | 000,308,224 | ---- | C] (Cutting Edge Software Inc.) -- C:\Dokumente und Einstellungen\Eder\Anwendungsdaten\h6s5ruij653.exe [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] @Alternate Data Stream - 113 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Temp:D1B5B4F1 [2012/03/04 10:41:50 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012/03/03 07:12:01 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012/02/29 13:00:22 | 000,000,244 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job [2012/02/29 13:00:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Temp [2012/02/23 11:13:27 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eder.job :Files ipconfig /flushdns /c :Commands [purity] [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
15.08.2012, 09:48 | #3 |
| Trojaner BMI AKM Paysafe danke....
__________________hab heute noch mal in der früh die systemwiederherstellung versucht, nachdem die gestern nicht funktioniert hat. und siehe da es läuft wieder alles... hab dann den malewarebytes drüberlaufen lassen, und dürfte soweit alles clean sein. zz läuft noch der avira..... mal schaun.... |
15.08.2012, 11:08 | #4 |
/// Helfer-Team | Trojaner BMI AKM Paysafe Wo sind die Logs? |
15.08.2012, 13:52 | #5 |
| Trojaner BMI AKM Paysafe hier nummer 1 Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.15.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Peter :: PETER-TOSH [Administrator] Schutz: Aktiviert 15.08.2012 09:19:50 mbam-log-2012-08-15 (09-19-50).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 209422 Laufzeit: 8 Minute(n), 50 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 6 C:\$RECYCLE.BIN\S-1-5-21-701151992-7915442-1855273204-1001\$R59AUSV.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Peter\AppData\Local\Temp\softonic_ssk_conduit.exe (PUP.BundleInstaller.IB) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Peter\Downloads\SoftonicDownloader_fuer_flash-video-downloader.exe (PUP.BundleOffer.Downloader.S) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Peter\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Peter\Downloads\SoftonicDownloader_fuer_quicktime.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Peter\Downloads\SoftonicDownloader_fuer_tunatic.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.15.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Peter :: PETER-TOSH [Administrator] Schutz: Aktiviert 15.08.2012 12:09:18 mbam-log-2012-08-15 (12-09-18).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 210121 Laufzeit: 8 Minute(n), 16 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
15.08.2012, 14:26 | #6 |
/// Helfer-Team | Trojaner BMI AKM Paysafe ESET Online Scanner Vorbereitung
__________________ --> Trojaner BMI AKM Paysafe |
15.08.2012, 17:01 | #7 |
| Trojaner BMI AKM Paysafe danke schon mal für die genaue anleitung. firewall und avira hab i jetzt nachd em scan wieder aktiviert. hier der log [edit] ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=8a0473afa2382c41bc7390fc542a23ae # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-15 04:57:46 # local_time=2012-08-15 05:57:46 (+0100, Mitteleuropäische Zeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 26519104 26519104 0 0 # compatibility_mode=5893 16776573 100 94 23455 97507394 0 0 # compatibility_mode=8192 67108863 100 0 176 176 0 0 # scanned=244437 # found=34 # cleaned=34 # scan_time=7522 C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.10 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.11 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.12 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.13 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.14 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.15 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.9 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Fun4IM\InstallerHelper.dll a variant of Win32/Adware.Bandoo.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe a variant of Win32/InstallBrain.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Uninstall Information\ib_uninst_540\uninstall.exe a variant of Win32/InstallBrain.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Uninstall Information\ib_uninst_555\uninstall.exe a variant of Win32/InstallBrain.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Windows Searchqu Toolbar\ToolBar\SearchquTb.dll Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Windows Searchqu Toolbar\ToolBar\chrome\content\searchqutb.js Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.htm Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.xul Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\ezLooker-S-Setup_Suite1.exe probably a variant of Win32/Adware.FCVRETQ application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\FFoxPackage.exe a variant of Win32/Adware.Bandoo.AA application (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\Fun4IMFiles\Bin\FFoxPackage.exe a variant of Win32/Adware.Bandoo.AA application (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\Fun4IMFiles\Bin\InstallerHelper.dll a variant of Win32/Adware.Bandoo.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\ICReinstall\cnet2_OrbitDownloaderSetup_exe.exe a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\AppData\Local\Temp\Searchqu_DM\SearchquMediaBar.exe Win32/Adware.Bandoo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\Downloads\cnet2_OrbitDownloaderSetup_exe(1).exe a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\Downloads\cnet2_OrbitDownloaderSetup_exe.exe a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\Downloads\WinZip165International.exe a variant of Win32/OpenInstall application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Peter\Downloads\YouTubeDownloaderSetup34.exe a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Windows\Installer\7eedf56.msi a variant of Win32/Toolbar.Widgi application (deleted - quarantined) 00000000000000000000000000000000 C [/edit] |
15.08.2012, 19:59 | #8 |
/// Helfer-Team | Trojaner BMI AKM Paysafe Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
15.08.2012, 20:06 | #9 |
| Trojaner BMI AKM Paysafe so schon erledigt.... Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/15/2012 at 21:03:33 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Peter - PETER-TOSH # Boot Mode : Normal # Running from : C:\Users\Peter\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** Found : Application Updater Found : Sidekick Manager ***** [Files / Folders] ***** Folder Found : C:\Users\Peter\AppData\Local\Conduit Folder Found : C:\Users\Peter\AppData\Local\Temp\CT3227982 Folder Found : C:\Users\Peter\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\Peter\AppData\LocalLow\boost_interprocess Folder Found : C:\Users\Peter\AppData\LocalLow\Conduit Folder Found : C:\Users\Peter\AppData\LocalLow\Search Settings Folder Found : C:\Users\Peter\AppData\LocalLow\SearchquTB Folder Found : C:\Users\Peter\AppData\Roaming\Bandoo Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\Conduit Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\ConduitCommon Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\ConduitEngine Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\CT2857572 Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\CT3227982 Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\SearchquTB Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\extensions\{0cc09160-108c-4759-bab1-5c12c216e005} Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\extensions\{38542454-dfb6-44f5-b052-d4e071a3d073} Folder Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\extensions\ffxtlbr@babylon.com Folder Found : C:\ProgramData\Bandoo Folder Found : C:\ProgramData\Fun4IM Folder Found : C:\ProgramData\IBUpdaterService Folder Found : C:\ProgramData\Sidekick Manager Folder Found : C:\ProgramData\SweetIM Folder Found : C:\ProgramData\Trymedia Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fun4IM Folder Found : C:\Program Files\Babylon Folder Found : C:\Program Files (x86)\Application Updater Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\Fun4IM Folder Found : C:\Program Files (x86)\SweetIM Folder Found : C:\Program Files (x86)\Windows Searchqu Toolbar Folder Found : C:\Program Files (x86)\Common Files\spigot Folder Found : C:\Windows\Installer\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Folder Found : C:\Windows\Installer\{5B58EF61-85F2-4977-97A5-84C19F926579} Folder Found : C:\Windows\Installer\{FB697452-8CA4-46B4-98B1-165C922A2EF3} File Found : C:\Users\Peter\AppData\Local\Temp\Searchqu.ini File Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\searchplugins\Conduit.xml File Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\searchplugins\SearchquWebSearch.xml File Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\searchplugins\SweetIm.xml File Found : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi File Found : C:\Users\Public\Desktop\eBay.lnk File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3227982 Key Found : HKCU\Software\AppDataLow\Software\Search Settings Key Found : HKCU\Software\AppDataLow\Software\searchqutb Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\bProtector Key Found : HKCU\Software\Cr_Installer Key Found : HKCU\Software\DataMngr Key Found : HKCU\Software\DataMngr_Toolbar Key Found : HKCU\Software\Search Settings Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\SweetIm Key Found : HKLM\SOFTWARE\Application Updater Key Found : HKLM\SOFTWARE\bandoo Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Key Found : HKLM\SOFTWARE\Classes\sim-packages Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\DataMngr Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5B58EF61-85F2-4977-97A5-84C19F926579} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FB697452-8CA4-46B4-98B1-165C922A2EF3} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandoo Key Found : HKLM\SOFTWARE\Search Settings Key Found : HKLM\SOFTWARE\SearchquMediabarTb Key Found : HKLM\SOFTWARE\SweetIM Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SweetIM] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Sweetpacks Communicator] Value Found : HKCU\Software\Mozilla\Firefox\Extensions [firefox@bandoo.com] [x64] Key Found : HKCU\Software\AppDataLow\Software\Search Settings [x64] Key Found : HKCU\Software\AppDataLow\Software\searchqutb [x64] Key Found : HKCU\Software\AppDataLow\Software\SmartBar [x64] Key Found : HKCU\Software\bProtector [x64] Key Found : HKCU\Software\Cr_Installer [x64] Key Found : HKCU\Software\DataMngr [x64] Key Found : HKCU\Software\DataMngr_Toolbar [x64] Key Found : HKCU\Software\Search Settings [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKCU\Software\SweetIm [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr [x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin [x64] Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl [x64] Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 [x64] Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl [x64] Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 [x64] Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils [x64] Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 [x64] Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator [x64] Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 [x64] Key Found : HKLM\SOFTWARE\Classes\sim-packages [x64] Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar [x64] Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 [x64] Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook [x64] Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 [x64] Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie [x64] Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe [x64] Key Found : HKLM\SOFTWARE\Software [x64] Value Found : HKCU\Software\Mozilla\Firefox\Extensions [firefox@bandoo.com] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Found : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{074E4EFE-81BB-4EA4-866E-082CB0E01070} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0CE5B352-9D9C-41E1-9551-FCCD92820217} Key Found : HKLM\SOFTWARE\Classes\CLSID\{167B2B5F-2757-434A-BBDA-2FDB2003F14F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531} Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020} Key Found : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF2B6317-C367-401B-83B8-80302D6588A7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F5379B4B-24D8-432A-9A96-BE75EE5117DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1} Key Found : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Found : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Found : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Found : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7FF99715-3016-4381-84CE-E4E4C9673020} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FF99715-3016-4381-84CE-E4E4C9673020} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FF99715-3016-4381-84CE-E4E4C9673020} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FF99715-3016-4381-84CE-E4E4C9673020} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7FF99715-3016-4381-84CE-E4E4C9673020}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F3FEE66E-E034-436A-86E4-9690573BEE8A}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F3FEE66E-E034-436A-86E4-9690573BEE8A}] [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FF99715-3016-4381-84CE-E4E4C9673020} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F3FEE66E-E034-436A-86E4-9690573BEE8A} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FF99715-3016-4381-84CE-E4E4C9673020} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A} [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F3FEE66E-E034-436A-86E4-9690573BEE8A}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227982 [HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227982 -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\3v5aww6q.default\prefs.js Found : user_pref("CT2269050..clientLogIsEnabled", true); Found : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2269050.CTID", "CT2269050"); Found : user_pref("CT2269050.CurrentServerDate", "14-3-2011"); Found : user_pref("CT2269050.DialogsAlignMode", "LTR"); Found : user_pref("CT2269050.DialogsGetterLastCheckTime", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2269050.DownloadReferralCookieData", ""); Found : user_pref("CT2269050.EMailNotifierPollDate", "Mon Mar 14 2011 23:23:08 GMT+0100"); Found : user_pref("CT2269050.FirstServerDate", "14-3-2011"); Found : user_pref("CT2269050.FirstTime", true); Found : user_pref("CT2269050.FirstTimeFF3", true); Found : user_pref("CT2269050.FixPageNotFoundErrors", true); Found : user_pref("CT2269050.GroupingServerCheckInterval", 1440); Found : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2269050.Initialize", true); Found : user_pref("CT2269050.InitializeCommonPrefs", true); Found : user_pref("CT2269050.InstallationAndCookieDataSentCount", 2); Found : user_pref("CT2269050.InstallationType", "UnknownIntegration"); Found : user_pref("CT2269050.InstalledDate", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2269050.InvalidateCache", false); Found : user_pref("CT2269050.IsGrouping", false); Found : user_pref("CT2269050.IsMulticommunity", false); Found : user_pref("CT2269050.IsOpenThankYouPage", false); Found : user_pref("CT2269050.IsOpenUninstallPage", false); Found : user_pref("CT2269050.LanguagePackLastCheckTime", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2269050.LastLogin_3.3.0.19", "Mon Mar 14 2011 18:09:39 GMT+0100"); Found : user_pref("CT2269050.LatestVersion", "3.2.5.2"); Found : user_pref("CT2269050.Locale", "en"); Found : user_pref("CT2269050.MCDetectTooltipHeight", "83"); Found : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2269050.MCDetectTooltipWidth", "295"); Found : user_pref("CT2269050.RadioIsPodcast", false); Found : user_pref("CT2269050.RadioLastCheckTime", "Mon Mar 14 2011 18:09:39 GMT+0100"); Found : user_pref("CT2269050.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000"); Found : user_pref("CT2269050.RadioMediaID", "12473414"); Found : user_pref("CT2269050.RadioMediaType", "Media Player"); Found : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT2269050_RECENT12473414"); Found : user_pref("CT2269050.RadioShrinked", "shrinked"); Found : user_pref("CT2269050.RadioStationName", "LATINA%2C%201250%20AM%20-%20Venezuela"); Found : user_pref("CT2269050.RadioStationURL", "hxxp://www.fm.com.ve/latina1250"); Found : user_pref("CT2269050.RadioVolume", "100"); Found : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...] Found : user_pref("CT2269050.SearchFromAddressBarIsInit", true); Found : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...] Found : user_pref("CT2269050.SearchInNewTabEnabled", true); Found : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT2269050.ServiceMapLastCheckTime", "Mon Mar 14 2011 18:09:36 GMT+0100"); Found : user_pref("CT2269050.SettingsLastCheckTime", "Mon Mar 14 2011 18:09:36 GMT+0100"); Found : user_pref("CT2269050.SettingsLastUpdate", "1299585172"); Found : user_pref("CT2269050.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Mon Mar 14 2011 18:09:36 GMT+0100"); Found : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1246790578"); Found : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Found : user_pref("CT2269050.UserID", "UN65839034296972111"); Found : user_pref("CT2269050.ValidationData_Toolbar", 2); Found : user_pref("CT2269050.WeatherNetwork", ""); Found : user_pref("CT2269050.WeatherPollDate", "Mon Mar 14 2011 23:03:08 GMT+0100"); Found : user_pref("CT2269050.WeatherUnit", "C"); Found : user_pref("CT2269050.alertChannelId", "666138"); Found : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2269050.isAppTrackingManagerOn", true); Found : user_pref("CT2269050.myStuffEnabled", true); Found : user_pref("CT2269050.myStuffPublihserMinWidth", 400); Found : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2269050.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Mon Mar 14 2011 18:09:37 GMT+0100"); Found : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Mon Mar 14 2011 18:09:38 GMT+0100"); Found : user_pref("CT2857572..clientLogIsEnabled", true); Found : user_pref("CT2857572..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2857572..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2857572.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2857572.AppTrackingLastCheckTime", "Sat Feb 12 2011 09:11:33 GMT+0100"); Found : user_pref("CT2857572.CT2857572", "CT2857572"); Found : user_pref("CT2857572.CurrentServerDate", "12-2-2011"); Found : user_pref("CT2857572.DialogsAlignMode", "LTR"); Found : user_pref("CT2857572.DialogsGetterLastCheckTime", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT2857572.DownloadReferralCookieData", ""); Found : user_pref("CT2857572.ExternalComponentPollDate129356796046694434", "Sat Feb 12 2011 09:11:22 GMT+010[...] Found : user_pref("CT2857572.FirstServerDate", "12-2-2011"); Found : user_pref("CT2857572.FirstTime", true); Found : user_pref("CT2857572.FirstTimeFF3", true); Found : user_pref("CT2857572.FixPageNotFoundErrors", false); Found : user_pref("CT2857572.GroupingServerCheckInterval", 1440); Found : user_pref("CT2857572.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2857572.HasUserGlobalKeys", true); Found : user_pref("CT2857572.Initialize", true); Found : user_pref("CT2857572.InitializeCommonPrefs", true); Found : user_pref("CT2857572.InstallationAndCookieDataSentCount", 2); Found : user_pref("CT2857572.InstalledDate", "Sat Feb 12 2011 09:11:37 GMT+0100"); Found : user_pref("CT2857572.InvalidateCache", false); Found : user_pref("CT2857572.IsGrouping", false); Found : user_pref("CT2857572.IsMulticommunity", false); Found : user_pref("CT2857572.IsOpenThankYouPage", true); Found : user_pref("CT2857572.IsOpenUninstallPage", true); Found : user_pref("CT2857572.LanguagePackLastCheckTime", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT2857572.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2857572.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2857572.LastLogin_3.3.0.19", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT2857572.LatestVersion", "3.2.5.2"); Found : user_pref("CT2857572.Locale", "en"); Found : user_pref("CT2857572.MCDetectTooltipHeight", "83"); Found : user_pref("CT2857572.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2857572.MCDetectTooltipWidth", "295"); Found : user_pref("CT2857572.RadioIsPodcast", false); Found : user_pref("CT2857572.RadioLastCheckTime", "Sat Feb 12 2011 09:09:30 GMT+0100"); Found : user_pref("CT2857572.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2857572.RadioLastUpdateServer", "129400870958430000"); Found : user_pref("CT2857572.RadioMediaID", "21753723"); Found : user_pref("CT2857572.RadioMediaType", "Media Player"); Found : user_pref("CT2857572.RadioMenuSelectedID", "EBRadioMenu_CT285757221753723"); Found : user_pref("CT2857572.RadioStationName", "California%20Rock%20-%20Rock"); Found : user_pref("CT2857572.RadioStationURL", "hxxp://www.feedlive.net/california.asx"); Found : user_pref("CT2857572.SavedHomepage", "www.google.at"); Found : user_pref("CT2857572.SearchFromAddressBarIsInit", true); Found : user_pref("CT2857572.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT285[...] Found : user_pref("CT2857572.SearchInNewTabEnabled", true); Found : user_pref("CT2857572.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2857572.SearchInNewTabLastCheckTime", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT2857572.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2857572.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT2857572.ServiceMapLastCheckTime", "Sat Feb 12 2011 09:09:30 GMT+0100"); Found : user_pref("CT2857572.SettingsLastCheckTime", "Sat Feb 12 2011 09:09:30 GMT+0100"); Found : user_pref("CT2857572.SettingsLastUpdate", "1297285592"); Found : user_pref("CT2857572.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2857572.ThirdPartyComponentsLastCheck", "Sat Feb 12 2011 09:09:30 GMT+0100"); Found : user_pref("CT2857572.ThirdPartyComponentsLastUpdate", "1246790578"); Found : user_pref("CT2857572.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Found : user_pref("CT2857572.UserID", "UN02118661809438748"); Found : user_pref("CT2857572.WeatherNetwork", ""); Found : user_pref("CT2857572.WeatherPollDate", "Sat Feb 12 2011 09:11:23 GMT+0100"); Found : user_pref("CT2857572.WeatherUnit", "C"); Found : user_pref("CT2857572.alertChannelId", "1249594"); Found : user_pref("CT2857572.approveUntrustedApps", true); Found : user_pref("CT2857572.backendstorage._fb_dailyactivity", "31323937343938323833323339"); Found : user_pref("CT2857572.backendstorage._fb_lifetimesent", "54525545"); Found : user_pref("CT2857572.globalFirstTimeInfoLastCheckTime", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT2857572.isAppTrackingManagerOn", true); Found : user_pref("CT2857572.myStuffEnabled", true); Found : user_pref("CT2857572.myStuffPublihserMinWidth", 400); Found : user_pref("CT2857572.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2857572.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2857572.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2857572.testingCtid", ""); Found : user_pref("CT2857572.toolbarAppMetaDataLastCheckTime", "Sat Feb 12 2011 09:09:30 GMT+0100"); Found : user_pref("CT2857572.toolbarContextMenuLastCheckTime", "Sat Feb 12 2011 09:09:31 GMT+0100"); Found : user_pref("CT3227982..clientLogIsEnabled", false); Found : user_pref("CT3227982..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT3227982..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT3227982.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT3227982.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT3227982.AppTrackingLastCheckTime", "Fri Aug 03 2012 14:38:36 GMT+0100"); Found : user_pref("CT3227982.BrowserCompStateIsOpen_1000515", true); Found : user_pref("CT3227982.BrowserCompStateIsOpen_129837883714349761", true); Found : user_pref("CT3227982.BrowserCompStateIsOpen_9221552460232570768", true); Found : user_pref("CT3227982.CTID", "CT3227982"); Found : user_pref("CT3227982.CurrentServerDate", "15-8-2012"); Found : user_pref("CT3227982.DSChangedManually", true); Found : user_pref("CT3227982.DSInstall", true); Found : user_pref("CT3227982.DialogsAlignMode", "LTR"); Found : user_pref("CT3227982.DialogsGetterLastCheckTime", "Tue Aug 14 2012 16:12:15 GMT+0100"); Found : user_pref("CT3227982.DownloadReferralCookieData", ""); Found : user_pref("CT3227982.FirstServerDate", "28-7-2012"); Found : user_pref("CT3227982.FirstTime", true); Found : user_pref("CT3227982.FirstTimeFF3", true); Found : user_pref("CT3227982.FirstTimeHiddenVer", true); Found : user_pref("CT3227982.FixPageNotFoundErrors", true); Found : user_pref("CT3227982.GroupingServerCheckInterval", 1440); Found : user_pref("CT3227982.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT3227982.HPInstall", true); Found : user_pref("CT3227982.HasUserGlobalKeys", true); Found : user_pref("CT3227982.HomePageProtectorEnabled", false); Found : user_pref("CT3227982.HomepageBeforeUnload", "www.google.at"); Found : user_pref("CT3227982.Initialize", true); Found : user_pref("CT3227982.InitializeCommonPrefs", true); Found : user_pref("CT3227982.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT3227982.InstallationId", "installbrain"); Found : user_pref("CT3227982.InstallationType", "ConduitNSISIntegration"); Found : user_pref("CT3227982.InstalledDate", "Sat Jul 28 2012 20:01:13 GMT+0100"); Found : user_pref("CT3227982.InvalidateCache", false); Found : user_pref("CT3227982.IsAlertDBUpdated", true); Found : user_pref("CT3227982.IsGrouping", false); Found : user_pref("CT3227982.IsInitSetupIni", true); Found : user_pref("CT3227982.IsMulticommunity", false); Found : user_pref("CT3227982.IsOpenThankYouPage", false); Found : user_pref("CT3227982.IsOpenUninstallPage", true); Found : user_pref("CT3227982.IsProtectorsInit", true); Found : user_pref("CT3227982.LanguagePackLastCheckTime", "Wed Aug 15 2012 09:14:18 GMT+0100"); Found : user_pref("CT3227982.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT3227982.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT3227982.LastLogin_3.15.0.0", "Wed Aug 15 2012 17:14:19 GMT+0100"); Found : user_pref("CT3227982.LatestVersion", "3.15.0.0"); Found : user_pref("CT3227982.Locale", "en"); Found : user_pref("CT3227982.MCDetectTooltipHeight", "83"); Found : user_pref("CT3227982.MCDetectTooltipShow", false); Found : user_pref("CT3227982.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT3227982.MCDetectTooltipWidth", "295"); Found : user_pref("CT3227982.MyStuffEnabledAtInstallation", true); Found : user_pref("CT3227982.OriginalFirstVersion", "3.15.0.0"); Found : user_pref("CT3227982.RadioIsPodcast", false); Found : user_pref("CT3227982.RadioLastCheckTime", "Sat Jul 28 2012 20:01:15 GMT+0100"); Found : user_pref("CT3227982.RadioLastUpdateIPServer", "3"); Found : user_pref("CT3227982.RadioLastUpdateServer", "3"); Found : user_pref("CT3227982.RadioMediaID", "9962"); Found : user_pref("CT3227982.RadioMediaType", "Media Player"); Found : user_pref("CT3227982.RadioMenuSelectedID", "EBRadioMenu_CT32279829962"); Found : user_pref("CT3227982.RadioShrinkedFromSetup", false); Found : user_pref("CT3227982.RadioStationName", "California%20Rock"); Found : user_pref("CT3227982.RadioStationURL", "hxxp://feedlive.net/california.asx"); Found : user_pref("CT3227982.SavedHomepage", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13"); Found : user_pref("CT3227982.SearchCaption", "appbario8 Customized Web Search"); Found : user_pref("CT3227982.SearchEngineBeforeUnload", "Wikipedia (de)"); Found : user_pref("CT3227982.SearchFromAddressBarIsInit", true); Found : user_pref("CT3227982.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...] Found : user_pref("CT3227982.SearchInNewTabEnabled", true); Found : user_pref("CT3227982.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT3227982.SearchInNewTabLastCheckTime", "Wed Aug 15 2012 09:14:17 GMT+0100"); Found : user_pref("CT3227982.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT3227982.SearchProtectorEnabled", false); Found : user_pref("CT3227982.SearchProtectorToolbarDisabled", false); Found : user_pref("CT3227982.SendProtectorDataViaLogin", true); Found : user_pref("CT3227982.ServiceMapLastCheckTime", "Wed Aug 15 2012 09:14:17 GMT+0100"); Found : user_pref("CT3227982.SettingsLastCheckTime", "Wed Aug 15 2012 18:03:41 GMT+0100"); Found : user_pref("CT3227982.SettingsLastUpdate", "1345033695"); Found : user_pref("CT3227982.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13"); Found : user_pref("CT3227982.ThirdPartyComponentsInterval", 504); Found : user_pref("CT3227982.ThirdPartyComponentsLastCheck", "Sat Jul 28 2012 20:01:12 GMT+0100"); Found : user_pref("CT3227982.ThirdPartyComponentsLastUpdate", "1331805997"); Found : user_pref("CT3227982.ToolbarShrinkedFromSetup", false); Found : user_pref("CT3227982.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3227982"); Found : user_pref("CT3227982.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT3227982.UserID", "UN29908575852101216"); Found : user_pref("CT3227982.ValidationData_Toolbar", 2); Found : user_pref("CT3227982.alertChannelId", "1663751"); Found : user_pref("CT3227982.approveUntrustedApps", false); Found : user_pref("CT3227982.autoDisableScopes", 0); Found : user_pref("CT3227982.backendstorage.bday_installdate", "32382D36"); Found : user_pref("CT3227982.backendstorage.bday_installfromtoolbar", "796573"); Found : user_pref("CT3227982.backendstorage.cbcountry_001", "4154"); Found : user_pref("CT3227982.backendstorage.cbfirsttime", "536174204A756C20323820323031322032303A30313A32382[...] Found : user_pref("CT3227982.backendstorage.ct3227982ads1", "25374225323261647325323225334125354225374225323[...] Found : user_pref("CT3227982.backendstorage.ct3227982current_term", ""); Found : user_pref("CT3227982.backendstorage.ct3227982sdate", "3238"); Found : user_pref("CT3227982.backendstorage.facebbok_user_cuid_1375515809", "62346131303030312D353166632D303[...] Found : user_pref("CT3227982.backendstorage.facebbok_user_id", "31333735353135383039"); Found : user_pref("CT3227982.backendstorage.facebook_conduit_social_sskey_1375515809", "56645364744853534C5F[...] Found : user_pref("CT3227982.backendstorage.facebook_ctid_connect_send_n", "73656E646564"); Found : user_pref("CT3227982.backendstorage.facebook_first_visit", "6E6F744669727374"); Found : user_pref("CT3227982.backendstorage.facebook_last_message_choice", "756E72656164"); Found : user_pref("CT3227982.backendstorage.facebook_loggedin", "796573"); Found : user_pref("CT3227982.backendstorage.facebook_login_refresh", "302E38373337343536323233393938323137")[...] Found : user_pref("CT3227982.backendstorage.facebook_login_status", "33"); Found : user_pref("CT3227982.backendstorage.facebook_lust_recieve", "36303039373434312C"); Found : user_pref("CT3227982.backendstorage.facebook_lust_recievegadet", ""); Found : user_pref("CT3227982.backendstorage.facebook_mode", "32"); Found : user_pref("CT3227982.backendstorage.facebook_toolbar_not_numer", "31"); Found : user_pref("CT3227982.backendstorage.facebook_user_locale", "6465"); Found : user_pref("CT3227982.backendstorage.facebook_user_name", "3078303035302C3078303036352C3078303037342C[...] Found : user_pref("CT3227982.backendstorage.facebook_user_token", "41414141414D4E75394953674241503730686F717[...] Found : user_pref("CT3227982.backendstorage.facebooknotifications", "31"); Found : user_pref("CT3227982.backendstorage.hxxp://facebook_conduitapps_com/v3_13.facebook_last_visit_tab", [...] Found : user_pref("CT3227982.backendstorage.shoppingapp.gk.exipres", "5468752041756720303220323031322032303A[...] Found : user_pref("CT3227982.backendstorage.shoppingapp.gk.geolocation", "61757374726961"); Found : user_pref("CT3227982.backendstorage.url_history0001", "68747470733A2F2F7777772E656D65726F2E64652F6C6[...] Found : user_pref("CT3227982.components.1000082", false); Found : user_pref("CT3227982.components.1000515", true); Found : user_pref("CT3227982.components.129837883713568504", false); Found : user_pref("CT3227982.components.129837883714037255", false); Found : user_pref("CT3227982.components.129837883714349761", false); Found : user_pref("CT3227982.components.3192020651322554256", false); Found : user_pref("CT3227982.components.4040000215049528074", false); Found : user_pref("CT3227982.components.9043685021158420454", false); Found : user_pref("CT3227982.components.9221552460232570768", false); Found : user_pref("CT3227982.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT3227982.globalFirstTimeInfoLastCheckTime", "Tue Aug 07 2012 20:01:14 GMT+0100"); Found : user_pref("CT3227982.homepageProtectorEnableByLogin", true); Found : user_pref("CT3227982.initDone", true); Found : user_pref("CT3227982.isAppTrackingManagerOn", true); Found : user_pref("CT3227982.isFirstRadioInstallation", false); Found : user_pref("CT3227982.myStuffEnabled", true); Found : user_pref("CT3227982.myStuffPublihserMinWidth", 400); Found : user_pref("CT3227982.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT3227982.myStuffServiceIntervalMM", 1440); Found : user_pref("CT3227982.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT3227982.navigateToUrlOnSearch", false); Found : user_pref("CT3227982.oldAppsList", "129837883711381002,129837883713256003,111,129837883713568504,129[...] Found : user_pref("CT3227982.revertSettingsEnabled", true); Found : user_pref("CT3227982.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT3227982.searchProtectorEnableByLogin", true); Found : user_pref("CT3227982.testingCtid", ""); Found : user_pref("CT3227982.toolbarAppMetaDataLastCheckTime", "Wed Aug 15 2012 16:12:16 GMT+0100"); Found : user_pref("CT3227982.toolbarContextMenuLastCheckTime", "Mon Aug 13 2012 17:47:48 GMT+0100"); Found : user_pref("CT3227982.usagesFlag", 2); Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227982&Search[...] Found : user_pref("CommunityToolbar.ConduitSearchList", "appbario8 Customized Web Search"); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3227982/CT3227982[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1249594/1245267/AT", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1663751/1656277/AT", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/AT", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/AT", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2857572", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3227982", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.0[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=2.7.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2857572",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3227982",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2269050/CT2269050[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2857572/CT2857572[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/maxi.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play_mini[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"7ae[...] Found : user_pref("CommunityToolbar.EngineHiddenByUser", true); Found : user_pref("CommunityToolbar.EngineOwner", "CT2857572"); Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{38542454-dfb6-44f5-b052-d4e071a3d073}"); Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "elf_1.12"); Found : user_pref("CommunityToolbar.IsEngineShown", false); Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Peter\\AppData\\Roaming\\Mozilla\\F[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.15.0.0"); Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2857572"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{38542454-dfb6-44f5-b052-d4e071a3d073}"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "elf_1.12"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Found : user_pref("CommunityToolbar.ToolbarsList", "CT2857572,ConduitEngine,CT2269050,CT3227982"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2857572,CT2269050,CT3227982"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT3227982"); Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Tue Apr 12 2011 15:43:40 GMT+01[...] Found : user_pref("CommunityToolbar.alert.alertEnabled", true); Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 60); Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri Jun 24 2011 13:39:38 GMT+0100"); Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.alert.locale", "en"); Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat Jun 25 2011 17:21:44 GMT+0100"); Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.alert.userId", "85488f54-5ec7-46ce-b633-1f928f2f0039"); Found : user_pref("CommunityToolbar.globalUserId", "8c94a356-9e14-45aa-b3af-95200f80786b"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3227982"); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Aug 14 2012 16:12:2[...] Found : user_pref("CommunityToolbar.notifications.alertEnabled", true); Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Aug 15 2012 16:12:31 GMT+010[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Aug 15 2012 16:12:17 GMT+0100"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "f052534a-b7c0-45fa-850e-a1d0006feb60"); Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSour[...] Found : user_pref("CommunityToolbar.originalSearchEngine", "appbario8 Customized Web Search"); Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Tue Jun 21 2011 21:54:45 GMT+0100"); Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sat Mar 26 2011 14:53:31 GMT+0100"); Found : user_pref("ConduitEngine.FirstServerDate", "02/12/2011 11"); Found : user_pref("ConduitEngine.FirstTime", true); Found : user_pref("ConduitEngine.FirstTimeFF3", true); Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Found : user_pref("ConduitEngine.Initialize", true); Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Found : user_pref("ConduitEngine.InstalledDate", "Sat Feb 12 2011 09:37:46 GMT+0100"); Found : user_pref("ConduitEngine.IsMulticommunity", false); Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Found : user_pref("ConduitEngine.IsOpenUninstallPage", true); Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sat Mar 26 2011 14:53:31 GMT+0100"); Found : user_pref("ConduitEngine.LastLogin_3.3.0.19", "Sat Feb 12 2011 09:37:46 GMT+0100"); Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sat Mar 26 2011 14:53:31 GMT+0100"); Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Sat Mar 26 2011 14:53:30 GMT+0100"); Found : user_pref("ConduitEngine.UserID", "UN87340657769737014"); Found : user_pref("ConduitEngine.engineLocale", "de"); Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sat Mar 26 2011 14:53:30 GMT+0100"); Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sat Mar 26 2011 14:53:31 GMT+0100"); Found : user_pref("ConduitEngine.initDone", true); Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Found : user_pref("ConduitEngine.usagesFlag", 1); Found : user_pref("browser.search.defaultenginename", "appbario8 Customized Web Search"); Found : user_pref("browser.search.defaultthis.engineName", "appbario8 Customized Web Search"); Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&Sea[...] Found : user_pref("browser.search.order.1", "appbario8 Customized Web Search"); Found : user_pref("extensions.engine@conduit.com.install-event-fired", true); Found : user_pref("extensions.ffxtlbr@babylon.com.install-event-fired", true); Found : user_pref("extensions.foxlingo.addit.defaultAddons", "{ \"software\": {\"7\": {\"id\": \"7\",\"title[...] Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=2&q=[...] -\\ Google Chrome v [Unable to get version] File : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "homepage" : "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=48", Found : "urls_to_restore_on_startup" : [ "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=48" ] ************************* AdwCleaner[R1].txt - [58857 octets] - [15/08/2012 21:03:33] ########## EOF - C:\AdwCleaner[R1].txt - [58986 octets] ########## |
15.08.2012, 21:59 | #10 |
/// Helfer-Team | Trojaner BMI AKM Paysafe Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
15.08.2012, 23:16 | #11 |
| Trojaner BMI AKM Paysafe der adwcleaner stürtzt immer ab, mehrfach versucht |
16.08.2012, 01:13 | #12 |
/// Helfer-Team | Trojaner BMI AKM Paysafe Emsisoft Log? |
16.08.2012, 09:36 | #13 |
| Trojaner BMI AKM Paysafe so hier der log Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 16.08.2012 08:39:48 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 16.08.2012 08:40:21 Key: hkey_local_machine\software\trymedia systems\activemark software gefunden: Trace.Registry.trymedia!E1 Key: hkey_local_machine\software\trymedia systems gefunden: Trace.Registry.trymedia!E1 Gescannt 680307 Gefunden 2 Scan Ende: 16.08.2012 09:51:43 Scan Zeit: 1:11:22 |
16.08.2012, 12:16 | #14 |
/// Helfer-Team | Trojaner BMI AKM Paysafe Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
16.08.2012, 14:27 | #15 |
| Trojaner BMI AKM Paysafe ich hab zwar keine ahnung was ich hier tue, aber ich glaub das log schaut gut aus Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=8a0473afa2382c41bc7390fc542a23ae # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-16 02:18:22 # local_time=2012-08-16 03:18:22 (+0100, Mitteleuropäische Zeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 26596544 26596544 0 0 # compatibility_mode=5893 16776573 100 94 10112 97584834 0 0 # compatibility_mode=8192 67108863 100 0 276 276 0 0 # scanned=243904 # found=0 # cleaned=0 # scan_time=6917 |
Themen zu Trojaner BMI AKM Paysafe |
abgesicherte, abgesicherten, abgesicherten modus, absoluter, bitte um hilfe, eingefangen, euro, fontcache, gefangen, gen, gesperrt, gestartet, google earth, illegale, modus, musik, nicht mehr, paysafe, plug-in, scan, seite, stunde, stunden, troja, trojaner, versuche, Österreich |