|
Log-Analyse und Auswertung: Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.08.2012, 19:49 | #1 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Hallo erstmal Entschuldigung für den Rechtschreibfehler in der Überschrift. Ich könnte ein wenig Hilfe gebrauchen. Als ich heute meinen Pc starten wollte, kam eine Meldung, in der stand ich solle 100 euro zahlen, da ich in mehreren Fällen gegen das Gesetz der BRD verstoßen hätte. (Pornographie, Urheberrechtsverletzung etc). Dann habe ich mich mit dem handy mal schnell schlau gemacht, ob jemand so einen Fall selbst schon hatte. Dann bin ich auf diese seite gestoßen, dei der von verschlüsselungstrojaner gesprochen wird. Nun wollte ich wissen ob in meinem Fall auch ein solcher Virus vorliegt und wie ich diesen wieder loswerde. Voreilig habe ich mir dann im abgesicherten modus mit netzwerktreibern das hier empfohlene "Malwarebytes" heruntergeladen und ein Suchdurchlauf gestartet. (Ergebnis im Anhang) Am ende waren es dann doch ein paar mehr Viren wie es aussieht, die aber vllt auch schon länger auf meinem pc sind(?) Dann bin ich auf einmal auf das thema "Computer wegen Verstoß der Gesetze der BRD blockiert" von Bastel vom 12.08.2012 gestoßen, was das selbe probelm zu seien scheint. Soll ich genau so vorgehen wie es ihm empfohlen wurde? Habe angst etwas falsch zu machen Ich hoffe jemand kann mir helfen. Geändert von marce (15.08.2012 um 19:58 Uhr) |
15.08.2012, 22:26 | #2 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. 2. Schritt Systemscan mit OTL (bebilderte Anleitung)
__________________ |
16.08.2012, 01:23 | #3 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Danke für deine schnelle Antwort
__________________Ich habe " Malwarebytes Anti-Malware " aktualisiert und nochmal neu gescannt. Der Rest befindet sich im Anhang. hier das ergebnis vom "OTL" scan OTL Logfile: Code:
ATTFilter OTL logfile created on: 16.08.2012 01:27:31 - Run 1 OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Marcel\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 62,96% Memory free 6,00 Gb Paging File | 4,47 Gb Available in Paging File | 74,56% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 465,66 Gb Total Space | 177,88 Gb Free Space | 38,20% Space Free | Partition Type: NTFS Drive D: | 505,94 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: MARCEL-PC | User Name: Marcel | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Marcel\Downloads\OTL.scr (OldTimer Tools) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Steam\Steam.exe (Valve Corporation) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Sony\Content Manager Assistant\CMAWatcher.exe (Sony Computer Entertainment Inc.) PRC - C:\Programme\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) PRC - C:\Programme\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) PRC - C:\Programme\Ask.com\Updater\Updater.exe (Ask) PRC - C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia) PRC - C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia) PRC - C:\Programme\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia) PRC - C:\Programme\PC Connectivity Solution\Transports\NclIVTBTSrv.exe (Nokia) PRC - C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () PRC - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe () PRC - C:\Programme\IVT Corporation\BlueSoleil\BlueSoleilCS.exe (IVT Corporation) PRC - C:\Programme\IVT Corporation\BlueSoleil\BtTray.exe (IVT Corporation) PRC - C:\Programme\IVT Corporation\BlueSoleil\BsHelpCS.exe (IVT Corporation) PRC - C:\Programme\IVT Corporation\BlueSoleil\BsMobileCS.exe (IVT Corporation) PRC - C:\Programme\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) PRC - C:\Programme\Bandoo\Bandoo.exe (Bandoo Media Inc.) PRC - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) PRC - C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation) PRC - C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) PRC - C:\Programme\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - c:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) PRC - c:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) PRC - C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Programme\Steam\bin\libcef.dll () MOD - C:\Programme\Steam\bin\avcodec-53.dll () MOD - C:\Programme\Steam\bin\chromehtml.dll () MOD - C:\Programme\Steam\bin\avformat-53.dll () MOD - C:\Programme\Steam\bin\avutil-51.dll () MOD - C:\Programme\Nokia\Nokia Suite\ssoengine.dll () MOD - C:\Programme\Nokia\Nokia Suite\securestorage.dll () MOD - C:\Programme\Nokia\Nokia Suite\qjson.dll () MOD - C:\Programme\Nokia\Nokia Suite\phonon4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QxtCore.dll () MOD - C:\Programme\Nokia\Nokia Suite\QxtWeb.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtXmlPatterns4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtXml4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtWebKit4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtSql4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtScript4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtOpenGL4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtNetwork4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtMultimediaKit1.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtGui4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtDeclarative4.dll () MOD - C:\Programme\Nokia\Nokia Suite\QtCore4.dll () MOD - C:\Programme\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll () MOD - C:\Programme\Nokia\Nokia Suite\Imageformats\qjpeg4.dll () MOD - C:\Programme\Nokia\Nokia Suite\Imageformats\qico4.dll () MOD - C:\Programme\Nokia\Nokia Suite\Imageformats\qgif4.dll () MOD - C:\Programme\Nokia\Nokia Suite\OviShareLib.dll () MOD - C:\Programme\Nokia\Nokia Suite\NService.dll () MOD - C:\Programme\Nokia\Nokia Suite\Maps Service API.dll () MOD - C:\Programme\Nokia\Nokia Suite\CommonUpdateChecker.dll () MOD - C:\Programme\Nokia\Nokia Suite\mediaservice\dsengine.dll () MOD - C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.SSL.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\pyovpnc.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.rand.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.crypto.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\twisted.protocols._c_urlarg.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\zope.interface._zope_interface_coptimizations.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\ovpntray.dll () MOD - C:\Windows\System32\BsMobileCSps.dll () MOD - C:\Programme\WinRAR\RarExt.dll () MOD - C:\Programme\IVT Corporation\BlueSoleil\Mobile\BaseLib.dll () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\pywintypes26.dll () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\win32gui.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\win32api.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\win32process.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\win32event.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\select.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\_hashlib.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\pyexpat.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\_ctypes.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\_ssl.pyd () MOD - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\_socket.pyd () MOD - C:\Programme\IVT Corporation\BlueSoleil\Mobile\s40pack.dll () MOD - C:\Programme\IVT Corporation\BlueSoleil\Mobile\CsCvt.dll () ========== Win32 Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (OpenVPNAccessClient) -- C:\Programme\OpenVPN Technologies\OpenVPN Client\core\capiws.exe () SRV - (BlueSoleilCS) -- C:\Programme\IVT Corporation\BlueSoleil\BlueSoleilCS.exe (IVT Corporation) SRV - (BsHelpCS) -- C:\Programme\IVT Corporation\BlueSoleil\BsHelpCS.exe (IVT Corporation) SRV - (BsMobileCS) -- C:\Programme\IVT Corporation\BlueSoleil\BsMobileCS.exe (IVT Corporation) SRV - (Bandoo Coordinator) -- C:\Programme\Bandoo\Bandoo.exe (Bandoo Media Inc.) SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation) SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (SwitchBoard) -- C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (wlidsvc) -- c:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (Microsoft Office Groove Audit Service) -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation) SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (VGPU) -- System32\drivers\rdvgkmd.sys File not found DRV - (tsusbhub) -- system32\drivers\tsusbhub.sys File not found DRV - (Synth3dVsc) -- System32\drivers\synth3dvsc.sys File not found DRV - (EagleXNt) -- C:\Users\Marcel\AppData\Local\Temp\EagleXNt.sys File not found DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia) DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia) DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia) DRV - (nmwcdnsu) -- C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia) DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia) DRV - (nmwcdnsuc) -- C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia) DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH) DRV - (tapoas) -- C:\Windows\System32\drivers\tapoas.sys (The OpenVPN Project) DRV - (BtHidBus) -- C:\Windows\System32\drivers\BtHidBus.sys (IVT Corporation.) DRV - (BTCOMBUS) -- C:\Windows\System32\drivers\btcombus.sys (IVT Corporation.) DRV - (BTCOM) -- C:\Windows\System32\drivers\btcomport.sys (IVT Corporation.) DRV - (Btcsrusb) -- C:\Windows\System32\drivers\btcusb.sys (IVT Corporation.) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation) DRV - (BT) -- C:\Windows\System32\drivers\btnetdrv.sys (IVT Corporation.) DRV - (btnetBUs) -- C:\Windows\System32\drivers\btnetBus.sys () DRV - (IvtBtBUs) -- C:\Windows\System32\drivers\IvtBtBus.sys (IVT Corporation.) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (VSTHWICH) -- C:\Windows\System32\drivers\VSTICH3.SYS (Conexant Systems, Inc.) DRV - (L1E) -- C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.) DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (AmdLLD) -- C:\Windows\System32\drivers\AmdLLD.sys (AMD, Inc.) DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys () DRV - (SilverLink) -- C:\Windows\System32\drivers\SilvrLnk.sys (Texas Instruments Incorporated) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com IE - HKLM\..\URLSearchHook: {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2319825 IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8F D1 B4 58 B5 59 CC 01 [binary data] IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\URLSearchHook: {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{2A6D7DF9-855C-4D40-8CDB-18EBA6276A57}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3242337 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8F D1 B4 58 B5 59 CC 01 [binary data] IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "SweetIM Search" FF - prefs.js..browser.search.defaultthis.engineName: "servershare Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "servershare Customized Web Search" FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.5 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27 FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.2.1 FF - prefs.js..extensions.enabledItems: ffox@bandoo.com:5.1 FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.8.0.8 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: {6571950c-6eb2-4d8b-975e-5a25053ff845}:3.8.0.8 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=2&q=" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "" FF - prefs.js..browser.startup.homepage: "hxxp://google.de" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.29 20:08:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.15 15:09:39 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.02.15 00:22:42 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\ffox@bandoo.com: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffox@bandoo.com [2011.09.08 17:00:38 | 000,000,000 | ---D | M] [2011.08.13 14:39:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcel\AppData\Roaming\mozilla\Extensions [2012.07.28 20:39:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions [2012.07.15 23:38:52 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2012.07.09 17:18:57 | 000,000,000 | ---D | M] (servershare Community Toolbar) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{6571950c-6eb2-4d8b-975e-5a25053ff845} [2011.08.28 09:22:32 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011.08.28 14:33:31 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} [2011.09.08 17:00:38 | 000,000,000 | ---D | M] (Bandoo for Firefox) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffox@bandoo.com [2011.08.28 14:49:34 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\Marcel\AppData\Roaming\mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffxtlbr@Facemoods.com [2011.11.09 01:21:10 | 000,000,925 | ---- | M] () -- C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\conduit.xml [2011.08.28 14:33:28 | 000,003,915 | ---- | M] () -- C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\sweetim.xml [2012.06.28 09:46:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.07.29 20:08:22 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.04.10 10:07:45 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.06.28 09:45:55 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.06.28 09:45:55 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.06.28 09:45:55 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.06.28 09:45:55 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.06.28 09:45:55 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.06.28 09:45:55 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\pdf.dll CHR - plugin: Bandoo (Enabled) = C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\dloejdefkancmfajekobpfoacecnhpgp\1.0.0.0_0\ChromePlugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: Bandoo = C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\dloejdefkancmfajekobpfoacecnhpgp\1.0.0.0_0\ CHR - Extension: Facemoods = C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0\ CHR - Extension: Winload = C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk\2.0.1.4_0\ O1 HOSTS File: ([2012.03.30 00:40:06 | 000,000,994 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.94.0.1 client.openvpn.net O1 - Hosts: 127.94.0.2 openvpn-client.us.shieldexchange.com O2 - BHO: (WiseConvert 1.3 Toolbar) - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (BandooIEPlugin Class) - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Programme\Bandoo\Plugins\IE\ieplugin.dll (Bandoo Media Inc.) O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (WiseConvert 1.3 Toolbar) - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll (facemoods.com) O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\Toolbar\WebBrowser: (WiseConvert 1.3 Toolbar) - {213C8ED6-1D78-4D8F-8729-25006AA86A76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [amd_dc_opt] C:\Programme\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD) O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BtTray] C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe (IVT Corporation) O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe (facemoods.com) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [SwitchBoard] C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [] File not found O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1001..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1001..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CNET TechTracker.lnk = C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () O4 - Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Users\Marcel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Marcel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - c:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - c:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E36DD0B0-3BEB-4CE8-A06A-6A0832E25654}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\System32\skype4com.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\progra~1\bandoo\bndhook.dll) - c:\Programme\Bandoo\BndHook.dll (Discordia Limited) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.01.13 22:02:44 | 000,000,053 | R--- | M] () - D:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe -- [2005.01.13 22:02:44 | 000,049,152 | R--- | M] () O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.08.16 01:18:31 | 000,000,000 | ---D | C] -- C:\Program Files\WiseConvert_1.3 [2012.08.15 17:32:16 | 000,000,000 | ---D | C] -- C:\Users\Marcel\AppData\Roaming\Malwarebytes [2012.08.15 17:32:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.08.15 17:32:05 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.08.15 17:32:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.08.15 17:32:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.08.15 15:08:56 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.08.15 15:03:22 | 000,000,000 | ---D | C] -- C:\Users\Marcel\AppData\Roaming\hellomoto [2012.08.13 14:41:12 | 000,000,000 | ---D | C] -- C:\ProgramData\036DFF8602D474E4DAF5BBD4F875EF7E [2012.08.12 18:28:27 | 000,000,000 | ---D | C] -- C:\Users\Marcel\AppData\Roaming\PDAppFlex [2012.08.12 18:16:02 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe [2012.08.12 17:59:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Local Settings [2012.08.12 17:36:57 | 000,000,000 | ---D | C] -- C:\Users\Marcel\Desktop\Adobe Photoshop CS6 [2012.08.12 17:35:03 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Download Assistant [2012.08.03 18:53:39 | 000,000,000 | ---D | C] -- C:\Users\Marcel\Documents\WB Games [2012.08.03 18:49:02 | 000,034,304 | ---- | C] (AMD, Inc.) -- C:\Windows\System32\drivers\AmdLLD.sys [2012.08.03 18:48:56 | 000,000,000 | ---D | C] -- C:\Program Files\AMD [2012.08.03 18:48:54 | 000,000,000 | ---D | C] -- C:\Users\Marcel\AppData\Local\Downloaded Installations [2012.08.03 18:46:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive [2012.08.03 18:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace [2012.08.03 18:46:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games for Windows - LIVE [2012.07.31 22:13:20 | 000,000,000 | R--D | C] -- C:\Users\Marcel\Documents\Scanned Documents [2012.07.31 22:13:19 | 000,000,000 | ---D | C] -- C:\Users\Marcel\Documents\Fax [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== File not found -- C:\Windows\System32\ [2012.08.16 01:29:14 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.08.16 01:29:12 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012.08.16 01:29:12 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012.08.16 01:21:01 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.08.16 01:14:53 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.08.16 01:14:53 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.08.16 01:06:50 | 000,001,231 | ---- | M] () -- C:\Windows\System32\bscs.ini [2012.08.16 01:06:50 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.08.16 01:06:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.08.16 01:06:32 | 2415,173,632 | -HS- | M] () -- C:\hiberfil.sys [2012.08.15 17:32:06 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.15 17:13:11 | 000,732,488 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012.08.15 17:13:11 | 000,717,018 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2012.08.15 17:13:11 | 000,706,274 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2012.08.15 17:13:11 | 000,700,130 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.08.15 17:13:11 | 000,654,842 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.08.15 17:13:11 | 000,649,248 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2012.08.15 17:13:11 | 000,155,120 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012.08.15 17:13:11 | 000,150,000 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2012.08.15 17:13:11 | 000,148,926 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.08.15 17:13:11 | 000,147,000 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2012.08.15 17:13:11 | 000,139,398 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2012.08.15 17:13:11 | 000,121,714 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.08.13 19:47:33 | 003,844,688 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.08.12 18:28:22 | 000,001,616 | ---- | M] () -- C:\Users\Marcel\Desktop\Photoshop - Verknüpfung.lnk [2012.08.05 04:08:36 | 002,195,113 | ---- | M] () -- C:\Users\Marcel\Documents\IMAG0146.jpg [2012.08.03 02:02:52 | 733,999,104 | ---- | M] () -- C:\Users\Marcel\Documents\2000-Kanak_Attack-cineonws894.avi [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== File not found -- C:\Windows\System32\ [2012.08.15 17:32:06 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.15 15:26:06 | 000,001,712 | ---- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ [2012.08.14 10:50:33 | 000,013,312 | ---- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ [2012.08.12 19:35:49 | 000,013,312 | ---- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ [2012.08.12 18:36:07 | 000,001,712 | ---- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ [2012.08.12 18:28:22 | 000,001,616 | ---- | C] () -- C:\Users\Marcel\Desktop\Photoshop - Verknüpfung.lnk [2012.08.12 18:15:51 | 000,001,165 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk [2012.08.12 18:14:58 | 000,001,127 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk [2012.08.12 18:13:31 | 000,001,311 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk [2012.08.12 18:13:25 | 000,001,477 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk [2012.08.05 04:08:16 | 002,195,113 | ---- | C] () -- C:\Users\Marcel\Documents\IMAG0146.jpg [2012.08.03 18:46:12 | 000,001,338 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk [2012.08.03 00:03:07 | 733,999,104 | ---- | C] () -- C:\Users\Marcel\Documents\2000-Kanak_Attack-cineonws894.avi [2012.06.03 21:25:13 | 000,050,403 | ---- | C] () -- C:\Users\Marcel\381252_308030342566659_270632237_n.jpg [2012.06.03 21:25:13 | 000,050,391 | ---- | C] () -- C:\Users\Marcel\195875_1962987638224_4962101_n.jpg [2012.04.07 15:14:58 | 000,000,367 | ---- | C] () -- C:\Users\Marcel\Heimnetzgruppe - Verknüpfung.lnk [2012.03.15 22:22:05 | 001,877,912 | ---- | C] () -- C:\Users\Marcel\IMGP0329.JPG [2012.03.15 22:22:05 | 001,809,365 | ---- | C] () -- C:\Users\Marcel\IMGP0335.JPG [2012.03.15 22:22:05 | 000,569,342 | ---- | C] () -- C:\Users\Marcel\IMGP0334 - Kopie - Kopie.JPG [2012.02.26 17:39:51 | 000,000,637 | ---- | C] () -- C:\Windows\System32\SHORTCUT.INI [2012.02.26 17:39:22 | 000,000,104 | ---- | C] () -- C:\Windows\System32\REMOTEDEVICE.INI [2012.02.26 17:38:43 | 000,006,510 | ---- | C] () -- C:\Windows\System32\LOCALSERVICE.INI [2012.02.26 17:38:35 | 000,000,101 | ---- | C] () -- C:\Windows\System32\LOCALDEVICE.INI [2012.02.26 17:30:48 | 000,000,000 | ---- | C] () -- C:\Windows\System32\BSPRINT.INI [2012.02.12 19:35:43 | 000,307,068 | ---- | C] () -- C:\Users\Marcel\Picture 37.jpg [2012.02.12 19:35:43 | 000,305,218 | ---- | C] () -- C:\Users\Marcel\Picture 36.jpg [2012.01.14 13:30:19 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ [2012.01.14 13:30:19 | 000,002,048 | -HS- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ [2011.12.28 20:30:24 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat [2011.12.18 20:07:37 | 001,819,267 | ---- | C] () -- C:\Users\Marcel\IMGP0318.JPG [2011.12.18 20:07:37 | 001,791,707 | ---- | C] () -- C:\Users\Marcel\IMGP0317.JPG [2011.12.01 22:19:04 | 001,958,237 | ---- | C] () -- C:\Users\Marcel\IMGP0303.JPG [2011.12.01 22:19:04 | 001,789,216 | ---- | C] () -- C:\Users\Marcel\IMGP0302.JPG [2011.11.18 20:46:19 | 000,040,960 | R--- | C] () -- C:\Windows\IGLobbyReg.exe [2011.11.06 23:11:10 | 003,360,624 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2011.10.26 23:41:53 | 000,004,608 | ---- | C] () -- C:\Users\Marcel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.09.29 21:29:23 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011.09.29 21:29:23 | 000,138,056 | ---- | C] () -- C:\Users\Marcel\AppData\Roaming\PnkBstrK.sys [2011.09.29 21:28:49 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2011.09.29 21:28:48 | 002,601,752 | ---- | C] () -- C:\Windows\System32\pbsvc_moh.exe [2011.09.29 21:28:48 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2011.09.09 22:24:51 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2011.09.09 22:24:50 | 000,732,488 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2011.09.09 22:24:50 | 000,155,120 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2011.09.09 22:24:50 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2011.09.09 22:17:23 | 000,717,018 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2011.09.09 22:17:23 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2011.09.09 22:17:23 | 000,150,000 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2011.09.09 22:17:23 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2011.09.09 22:09:34 | 000,706,274 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2011.09.09 22:09:34 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2011.09.09 22:09:34 | 000,147,000 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2011.09.09 22:09:34 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2011.09.09 21:46:08 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2011.09.09 21:46:07 | 000,649,248 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2011.09.09 21:46:07 | 000,139,398 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2011.09.09 21:46:07 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2011.09.02 19:14:34 | 000,000,280 | ---- | C] () -- C:\Windows\game.ini [2011.08.16 19:47:16 | 000,001,231 | ---- | C] () -- C:\Windows\System32\bscs.ini [2011.08.16 15:47:44 | 000,028,672 | ---- | C] () -- C:\Windows\System32\BsMobileCSps.dll [2011.08.14 10:03:12 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2011.08.14 10:02:20 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat ========== LOP Check ========== [2012.04.09 21:53:12 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\.minecraft [2011.12.11 21:33:45 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\AllVideoDownloader [2012.02.11 14:08:05 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Amazon [2011.10.22 22:00:04 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Audacity [2011.09.08 17:00:48 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Bandoo [2012.05.22 21:12:05 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\CBS Interactive [2012.04.27 19:36:46 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2012.05.02 19:53:47 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\DVDVideoSoft [2011.08.28 09:22:32 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\DVDVideoSoftIEHelpers [2011.10.12 17:30:13 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\FreeScreenToVideo [2012.08.15 17:03:14 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\hellomoto [2012.08.15 15:34:01 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\ICQ [2012.02.15 00:23:26 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Nokia [2011.12.12 23:48:57 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\OpenOffice.org [2012.02.15 00:28:00 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\PC Suite [2012.08.12 18:28:27 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\PDAppFlex [2011.11.04 00:07:18 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\TeamViewer [2012.03.27 22:29:23 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Teeworlds [2012.03.05 18:40:55 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Tema [2011.09.24 23:14:18 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\The Creative Assembly [2012.05.14 20:28:15 | 000,000,000 | ---D | M] -- C:\Users\Marcel\AppData\Roaming\Yrto [2012.06.22 18:18:29 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
16.08.2012, 01:27 | #4 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL PRC - C:\Programme\Ask.com\Updater\Updater.exe (Ask) PRC - C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () PRC - C:\Programme\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe () PRC - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) MOD - C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () SRV - (OpenVPNAccessClient) -- C:\Programme\OpenVPN Technologies\OpenVPN Client\core\capiws.exe () DRV - (VGPU) -- System32\drivers\rdvgkmd.sys File not found DRV - (tsusbhub) -- system32\drivers\tsusbhub.sys File not found DRV - (Synth3dVsc) -- System32\drivers\synth3dvsc.sys File not found DRV - (EagleXNt) -- C:\Users\Marcel\AppData\Local\Temp\EagleXNt.sys File not found IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com IE - HKLM\..\URLSearchHook: {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2319825 IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2319825 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\URLSearchHook: {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{2A6D7DF9-855C-4D40-8CDB-18EBA6276A57}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3242337 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - prefs.js..browser.search.defaultenginename: "SweetIM Search" FF - prefs.js..browser.search.defaultthis.engineName: "servershare Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "servershare Customized Web Search" FF - prefs.js..browser.startup.homepage: "http://www.google.de/" FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=2&q=" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "" FF - prefs.js..browser.startup.homepage: "http://google.de" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties" CHR - Extension: Facemoods = C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0\ O2 - BHO: (WiseConvert 1.3 Toolbar) - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (WiseConvert 1.3 Toolbar) - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll (facemoods.com) O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\Toolbar\WebBrowser: (WiseConvert 1.3 Toolbar) - {213C8ED6-1D78-4D8F-8729-25006AA86A76} - C:\Programme\WiseConvert_1.3\prxtbWise.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe (facemoods.com) O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [] File not found O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3179908731-3108579351-641879906-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CNET TechTracker.lnk = C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.01.13 22:02:44 | 000,000,053 | R--- | M] () - D:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe -- [2005.01.13 22:02:44 | 000,049,152 | R--- | M] () [2012.08.13 14:41:12 | 000,000,000 | ---D | C] -- C:\ProgramData\036DFF8602D474E4DAF5BBD4F875EF7E [2012.08.12 18:16:02 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe [2012.08.12 17:59:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Local Settings [2012.08.03 18:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [2012.08.15 15:03:22 | 000,000,000 | ---D | C] -- C:\Users\Marcel\AppData\Roaming\hellomoto [2012.08.03 18:46:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive [2012.08.16 01:29:14 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.08.16 01:21:01 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.08.16 01:06:50 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.08.15 15:26:06 | 000,001,712 | ---- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ [2012.08.14 10:50:33 | 000,013,312 | ---- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ [2012.08.12 19:35:49 | 000,013,312 | ---- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ [2012.08.12 18:36:07 | 000,001,712 | ---- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ [2012.01.14 13:30:19 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ [2012.01.14 13:30:19 | 000,002,048 | -HS- | C] () -- C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ :Files ipconfig /flushdns /c :Commands [purity] [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
16.08.2012, 12:09 | #5 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Ich hoffe ich habe das mit den code tags richtig gemacht Ist das Problem damit beseitigt? Code:
ATTFilter All processes killed ========== OTL ========== No active process named Updater.exe was found! No active process named TechTracker.exe was found! No active process named ovpntray.exe was found! No active process named SweetIM.exe was found! Service OpenVPNAccessClient stopped successfully! Service OpenVPNAccessClient deleted successfully! C:\Programme\OpenVPN Technologies\OpenVPN Client\core\capiws.exe moved successfully. Service VGPU stopped successfully! Service VGPU deleted successfully! File System32\drivers\rdvgkmd.sys File not found not found. Service tsusbhub stopped successfully! Service tsusbhub deleted successfully! File system32\drivers\tsusbhub.sys File not found not found. Service Synth3dVsc stopped successfully! Service Synth3dVsc deleted successfully! File System32\drivers\synth3dvsc.sys File not found not found. Service EagleXNt stopped successfully! Service EagleXNt deleted successfully! File C:\Users\Marcel\AppData\Local\Temp\EagleXNt.sys File not found not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{213c8ed6-1d78-4d8f-8729-25006aa86a76} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\ deleted successfully. C:\Programme\WiseConvert_1.3\prxtbWise.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{40c3cc16-7269-4b32-9531-17f2950fb06f} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40c3cc16-7269-4b32-9531-17f2950fb06f}\ deleted successfully. C:\Programme\Winload\prxtbWinl.dll moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{213c8ed6-1d78-4d8f-8729-25006aa86a76} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\ not found. File C:\Programme\WiseConvert_1.3\prxtbWise.dll not found. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{40c3cc16-7269-4b32-9531-17f2950fb06f} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40c3cc16-7269-4b32-9531-17f2950fb06f}\ not found. File C:\Programme\Winload\prxtbWinl.dll not found. HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{2A6D7DF9-855C-4D40-8CDB-18EBA6276A57}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A6D7DF9-855C-4D40-8CDB-18EBA6276A57}\ not found. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. HKU\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. HKU\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "SweetIM Search" removed from browser.search.defaultenginename Prefs.js: "servershare Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "servershare Customized Web Search" removed from browser.search.selectedEngine Prefs.js: "hxxp://www.google.de/" removed from browser.startup.homepage Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=2&q=" removed from keyword.URL Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.defaultenginename Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.defaulturl Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.selectedEngine Prefs.js: "hxxp://google.de" removed from browser.startup.homepage Prefs.js: "chrome://browser-region/locale/region.properties" removed from sweetim.toolbar.previous.keyword.URL C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0\style folder moved successfully. C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0\js folder moved successfully. C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0\img folder moved successfully. C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.2.1_0 folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\ not found. File C:\Programme\WiseConvert_1.3\prxtbWise.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. C:\Programme\ConduitEngine\prxConduitEngine.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40c3cc16-7269-4b32-9531-17f2950fb06f}\ not found. File C:\Programme\Winload\prxtbWinl.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64182481-4F71-486b-A045-B233BD0DA8FC}\ deleted successfully. C:\Programme\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. C:\Programme\Ask.com\GenericAskToolbar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully. C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{213c8ed6-1d78-4d8f-8729-25006aa86a76} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\ not found. File C:\Programme\WiseConvert_1.3\prxtbWise.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Programme\ConduitEngine\prxConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{40c3cc16-7269-4b32-9531-17f2950fb06f} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40c3cc16-7269-4b32-9531-17f2950fb06f}\ not found. File C:\Programme\Winload\prxtbWinl.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}\ deleted successfully. C:\Programme\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ deleted successfully. File C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{213C8ED6-1D78-4D8F-8729-25006AA86A76} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{213C8ED6-1D78-4D8F-8729-25006AA86A76}\ not found. File C:\Programme\WiseConvert_1.3\prxtbWise.dll not found. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Programme\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\facemoods deleted successfully. C:\Programme\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM deleted successfully. C:\Programme\SweetIM\Messenger\SweetIM.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CNET TechTracker.lnk moved successfully. C:\Users\Marcel\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully. Registry value HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-3179908731-3108579351-641879906-1001\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. File move failed. D:\autorun.inf scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a4e75f43-c59b-11e0-99f6-806e6f6e6963}\ not found. File move failed. D:\Setup.exe scheduled to be moved on reboot. Folder C:\ProgramData\036DFF8602D474E4DAF5BBD4F875EF7E\ not found. C:\ProgramData\regid.1986-12.com.adobe folder moved successfully. C:\ProgramData\Local Settings\Temp folder moved successfully. C:\ProgramData\Local Settings folder moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace folder moved successfully. C:\Windows\System32\SETA0F.tmp deleted successfully. C:\Users\Marcel\AppData\Roaming\hellomoto folder moved successfully. C:\Windows\System32\xlive folder moved successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ moved successfully. C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ moved successfully. C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ moved successfully. C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ moved successfully. C:\Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ moved successfully. C:\Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\@ moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Marcel\Desktop\cmd.bat deleted successfully. C:\Users\Marcel\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 400807 bytes ->Flash cache emptied: 56466 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Marcel ->Temp folder emptied: 1810211540 bytes ->Temporary Internet Files folder emptied: 278114150 bytes ->Java cache emptied: 46479615 bytes ->FireFox cache emptied: 886209438 bytes ->Google Chrome cache emptied: 6895861 bytes ->Flash cache emptied: 217604 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 356352 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2789725534 bytes RecycleBin emptied: 5376485372 bytes Total Files Cleaned = 10.677,00 mb OTL by OldTimer - Version 3.2.55.0 log created on 08162012_125110 Files\Folders moved on Reboot... File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. File move failed. D:\autorun.inf scheduled to be moved on reboot. File move failed. D:\Setup.exe scheduled to be moved on reboot. PendingFileRenameOperations files... [2009.07.14 03:14:23 | 000,093,696 | ---- | M] (Microsoft Corporation) C:\Windows\System32\mctadmin.exe : MD5=BBA1A5B86134F496B926DDAF247DB871 [2005.01.13 22:02:44 | 000,000,053 | R--- | M] () D:\autorun.inf : MD5=1EF5DD767CDD6204BDB941E11A19F59A [2005.01.13 22:02:44 | 000,049,152 | R--- | M] () D:\Setup.exe : MD5=AEE6E62192E4B117D59DABEFECB7F0C0 Registry entries deleted on Reboot... |
16.08.2012, 12:24 | #6 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ --> Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt |
16.08.2012, 20:29 | #7 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Der PC läuft bis jetzt ohne Probleme :) Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/16/2012 at 21:24:23 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (32 bits) # User : Marcel - MARCEL-PC # Boot Mode : Normal # Running from : C:\Users\Marcel\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** Found : Bandoo Coordinator ***** [Files / Folders] ***** Folder Found : C:\Users\Marcel\AppData\Local\APN Folder Found : C:\Users\Marcel\AppData\Local\AskToolbar Folder Found : C:\Users\Marcel\AppData\Local\Conduit Folder Found : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif Folder Found : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk Folder Found : C:\Users\Marcel\AppData\Local\Ilivid Player Folder Found : C:\Users\Marcel\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Marcel\AppData\LocalLow\Bandoo Folder Found : C:\Users\Marcel\AppData\LocalLow\Conduit Folder Found : C:\Users\Marcel\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Marcel\AppData\LocalLow\facemoods.com Folder Found : C:\Users\Marcel\AppData\LocalLow\PriceGong Folder Found : C:\Users\Marcel\AppData\LocalLow\Winload Folder Found : C:\Users\Marcel\AppData\LocalLow\WiseConvert_1.3 Folder Found : C:\Users\Marcel\AppData\Roaming\Bandoo Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\ConduitCommon Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\CT2319825 Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\CT2990218 Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\SweetIMToolbarData Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{6571950c-6eb2-4d8b-975e-5a25053ff845} Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffox@bandoo.com Folder Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffxtlbr@Facemoods.com Folder Found : C:\ProgramData\Bandoo Folder Found : C:\ProgramData\InstallMate Folder Found : C:\ProgramData\SweetIM Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandoo Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid Folder Found : C:\Program Files\Ask.com Folder Found : C:\Program Files\Bandoo Folder Found : C:\Program Files\Conduit Folder Found : C:\Program Files\ConduitEngine Folder Found : C:\Program Files\facemoods.com Folder Found : C:\Program Files\Ilivid Folder Found : C:\Program Files\SweetIM Folder Found : C:\Program Files\Trymedia Folder Found : C:\Program Files\Winload Folder Found : C:\Program Files\WiseConvert_1.3 Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Folder Found : C:\ProgramData\Premium File Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\Conduit.xml File Found : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\SweetIm.xml ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2319825[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3242337 Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Ask.com.tmp Key Found : HKCU\Software\AskToolbar Key Found : HKCU\Software\facemoods.com Key Found : HKCU\Software\ilivid Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\SweetIm Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\bandoo Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier Key Found : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin Key Found : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl Key Found : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Key Found : HKLM\SOFTWARE\Classes\sim-packages Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\facemoods.com Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dloejdefkancmfajekobpfoacecnhpgp Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandoo Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winload Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WiseConvert_1.3 Toolbar Key Found : HKLM\SOFTWARE\Software Key Found : HKLM\SOFTWARE\SweetIM Key Found : HKLM\SOFTWARE\Winload Key Found : HKLM\SOFTWARE\WiseConvert_1.3 Value Found : HKCU\Software\Mozilla\Firefox\Extensions [ffox@bandoo.com] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Found : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{074E4EFE-81BB-4EA4-866E-082CB0E01070} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0CE5B352-9D9C-41E1-9551-FCCD92820217} Key Found : HKLM\SOFTWARE\Classes\CLSID\{167B2B5F-2757-434A-BBDA-2FDB2003F14F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531} Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF2B6317-C367-401B-83B8-80302D6588A7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F5379B4B-24D8-432A-9A96-BE75EE5117DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4DF2927E-63DB-4E43-A3F6-1259808CD6D7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D51392A5-3A08-41E6-AC05-C3B0FB94C41B} Key Found : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Found : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Key Found : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Found : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A742D5D2-30D8-48FA-BE5F-3B978A69D70A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFF5C317-9E75-4E68-AA2A-F8335395CF7F} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EF3BA6C-A88B-4848-B469-35D4C3130AC5} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EC184D9-82C3-407D-8982-5623348A5E54} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{05AE71FE-0161-4CAB-83BC-5E7191281EBF} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4DF2927E-63DB-4E43-A3F6-1259808CD6D7} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D51392A5-3A08-41E6-AC05-C3B0FB94C41B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\prefs.js Found : user_pref("CT2319825..clientLogIsEnabled", false); Found : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2319825.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2319825.AppTrackingLastCheckTime", "Tue Oct 18 2011 15:36:16 GMT+0200"); Found : user_pref("CT2319825.BrowserCompStateIsOpen_129714600517272937", true); Found : user_pref("CT2319825.CTID", "CT2319825"); Found : user_pref("CT2319825.CurrentServerDate", "16-8-2012"); Found : user_pref("CT2319825.DSInstall", true); Found : user_pref("CT2319825.DialogsAlignMode", "LTR"); Found : user_pref("CT2319825.DialogsGetterLastCheckTime", "Thu Aug 16 2012 21:22:51 GMT+0200"); Found : user_pref("CT2319825.DownloadReferralCookieData", ""); Found : user_pref("CT2319825.EMailNotifierPollDate", "Sun Jan 29 2012 12:48:13 GMT+0100"); Found : user_pref("CT2319825.FeedPollDate11908299", "Sun Jan 29 2012 22:18:25 GMT+0100"); Found : user_pref("CT2319825.FirstServerDate", "17-10-2011"); Found : user_pref("CT2319825.FirstTime", true); Found : user_pref("CT2319825.FirstTimeFF3", true); Found : user_pref("CT2319825.FixPageNotFoundErrors", true); Found : user_pref("CT2319825.GroupingServerCheckInterval", 1440); Found : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2319825.HPInstall", false); Found : user_pref("CT2319825.HasUserGlobalKeys", true); Found : user_pref("CT2319825.HomePageProtectorEnabled", false); Found : user_pref("CT2319825.HomepageBeforeUnload", "hxxp://www.google.de/"); Found : user_pref("CT2319825.Initialize", true); Found : user_pref("CT2319825.InitializeCommonPrefs", true); Found : user_pref("CT2319825.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2319825.InstallationType", "ConduitIntegration"); Found : user_pref("CT2319825.InstalledDate", "Mon Oct 17 2011 11:29:25 GMT+0200"); Found : user_pref("CT2319825.InvalidateCache", false); Found : user_pref("CT2319825.IsAlertDBUpdated", true); Found : user_pref("CT2319825.IsGrouping", false); Found : user_pref("CT2319825.IsInitSetupIni", true); Found : user_pref("CT2319825.IsMulticommunity", false); Found : user_pref("CT2319825.IsOpenThankYouPage", false); Found : user_pref("CT2319825.IsOpenUninstallPage", true); Found : user_pref("CT2319825.IsProtectorsInit", true); Found : user_pref("CT2319825.LanguagePackLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2319825.LastLogin_3.13.0.6", "Sun Jul 15 2012 23:29:23 GMT+0200"); Found : user_pref("CT2319825.LastLogin_3.14.1.0", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2319825.LastLogin_3.7.0.6", "Tue Oct 18 2011 15:36:06 GMT+0200"); Found : user_pref("CT2319825.LastLogin_3.9.0.3", "Sun Jan 29 2012 20:18:25 GMT+0100"); Found : user_pref("CT2319825.LatestVersion", "3.14.1.0"); Found : user_pref("CT2319825.Locale", "de"); Found : user_pref("CT2319825.MCDetectTooltipHeight", "83"); Found : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2319825.MCDetectTooltipWidth", "295"); Found : user_pref("CT2319825.MyStuffEnabledAtInstallation", true); Found : user_pref("CT2319825.OriginalFirstVersion", "3.7.0.6"); Found : user_pref("CT2319825.RadioIsPodcast", false); Found : user_pref("CT2319825.RadioLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Found : user_pref("CT2319825.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000"); Found : user_pref("CT2319825.RadioMediaID", "11949532"); Found : user_pref("CT2319825.RadioMediaType", "Media Player"); Found : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532"); Found : user_pref("CT2319825.RadioShrinkedFromSetup", false); Found : user_pref("CT2319825.RadioStationName", "1Live"); Found : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_ei[...] Found : user_pref("CT2319825.SavedHomepage", "hxxp://www.google.de/"); Found : user_pref("CT2319825.SearchCaption", "Winload Customized Web Search"); Found : user_pref("CT2319825.SearchEngineBeforeUnload", "servershare Customized Web Search"); Found : user_pref("CT2319825.SearchFromAddressBarIsInit", true); Found : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT231[...] Found : user_pref("CT2319825.SearchInNewTabEnabled", true); Found : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Found : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Found : user_pref("CT2319825.SearchProtectorEnabled", false); Found : user_pref("CT2319825.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2319825.SendProtectorDataViaLogin", true); Found : user_pref("CT2319825.ServiceMapLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2319825.SettingsLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Found : user_pref("CT2319825.SettingsLastUpdate", "1345033693"); Found : user_pref("CT2319825.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=13"); Found : user_pref("CT2319825.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Sun Jan 29 2012 12:48:13 GMT+0100"); Found : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255344657"); Found : user_pref("CT2319825.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2319825.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2319825"); Found : user_pref("CT2319825.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2319825.UserID", "UN65887214923830073"); Found : user_pref("CT2319825.ValidationData_Toolbar", 0); Found : user_pref("CT2319825.WeatherNetwork", ""); Found : user_pref("CT2319825.WeatherPollDate", "Sun Jan 29 2012 12:48:14 GMT+0100"); Found : user_pref("CT2319825.WeatherUnit", "C"); Found : user_pref("CT2319825.alertChannelId", "715912"); Found : user_pref("CT2319825.backendstorage.id", "3236363530323039"); Found : user_pref("CT2319825.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2319825.globalFirstTimeInfoLastCheckTime", "Sun Jan 29 2012 20:18:25 GMT+0100"); Found : user_pref("CT2319825.homepageProtectorEnableByLogin", true); Found : user_pref("CT2319825.initDone", true); Found : user_pref("CT2319825.isAppTrackingManagerOn", true); Found : user_pref("CT2319825.isFirstRadioInstallation", false); Found : user_pref("CT2319825.myStuffEnabled", true); Found : user_pref("CT2319825.myStuffPublihserMinWidth", 400); Found : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2319825.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2319825.oldAppsList", "128898076802619665,128898076802619666,111,1000082,12945346285535[...] Found : user_pref("CT2319825.revertSettingsEnabled", true); Found : user_pref("CT2319825.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2319825.searchProtectorEnableByLogin", true); Found : user_pref("CT2319825.testingCtid", ""); Found : user_pref("CT2319825.toolbarAppMetaDataLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2319825.toolbarContextMenuLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Found : user_pref("CT2319825.usagesFlag", 2); Found : user_pref("CT2990218..clientLogIsEnabled", false); Found : user_pref("CT2990218..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2990218..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2990218.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2990218.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2990218.AppTrackingLastCheckTime", "Wed May 23 2012 16:19:02 GMT+0200"); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129473677946131396", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129773572938675051", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129773574219941454", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780905110786675", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780905202661677", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780905289224178", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780905335630475", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780905377192976", true); Found : user_pref("CT2990218.BrowserCompStateIsOpen_129780909624536121", true); Found : user_pref("CT2990218.CT2990218", "CT2990218"); Found : user_pref("CT2990218.CurrentServerDate", "16-8-2012"); Found : user_pref("CT2990218.DSChangedManually", false); Found : user_pref("CT2990218.DSInstall", true); Found : user_pref("CT2990218.DSProtectChoice", true); Found : user_pref("CT2990218.DSProtectCount", 1); Found : user_pref("CT2990218.DialogsAlignMode", "LTR"); Found : user_pref("CT2990218.DialogsGetterLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2990218.DownloadReferralCookieData", ""); Found : user_pref("CT2990218.EMailNotifierPollDate", "Sun Jun 10 2012 20:18:20 GMT+0200"); Found : user_pref("CT2990218.FirstServerDate", "23-11-2011"); Found : user_pref("CT2990218.FirstTime", true); Found : user_pref("CT2990218.FirstTimeFF3", true); Found : user_pref("CT2990218.FixPageNotFoundErrors", false); Found : user_pref("CT2990218.GroupingServerCheckInterval", 1440); Found : user_pref("CT2990218.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2990218.HPInstall", false); Found : user_pref("CT2990218.HPProtectChoice", true); Found : user_pref("CT2990218.HPProtectCount", 6); Found : user_pref("CT2990218.HasUserGlobalKeys", true); Found : user_pref("CT2990218.HomePageProtectorEnabled", false); Found : user_pref("CT2990218.HomepageBeforeUnload", "hxxp://www.google.de/"); Found : user_pref("CT2990218.Initialize", true); Found : user_pref("CT2990218.InitializeCommonPrefs", true); Found : user_pref("CT2990218.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2990218.InstallationType", "Unknown"); Found : user_pref("CT2990218.InstalledDate", "Wed Nov 23 2011 14:35:22 GMT+0100"); Found : user_pref("CT2990218.InvalidateCache", false); Found : user_pref("CT2990218.IsAlertDBUpdated", true); Found : user_pref("CT2990218.IsGrouping", false); Found : user_pref("CT2990218.IsInitSetupIni", true); Found : user_pref("CT2990218.IsMulticommunity", false); Found : user_pref("CT2990218.IsOpenThankYouPage", true); Found : user_pref("CT2990218.IsOpenUninstallPage", true); Found : user_pref("CT2990218.IsProtectorsInit", true); Found : user_pref("CT2990218.LanguagePackLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2990218.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2990218.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2990218.LastLogin_3.10.0.1", "Sat Apr 28 2012 21:03:30 GMT+0200"); Found : user_pref("CT2990218.LastLogin_3.11.0.3", "Sun May 06 2012 20:00:38 GMT+0200"); Found : user_pref("CT2990218.LastLogin_3.12.2.3", "Mon May 21 2012 14:34:00 GMT+0200"); Found : user_pref("CT2990218.LastLogin_3.13.0.6", "Mon Jul 09 2012 15:11:25 GMT+0200"); Found : user_pref("CT2990218.LastLogin_3.14.1.0", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2990218.LastLogin_3.8.0.8", "Mon Dec 05 2011 18:23:20 GMT+0100"); Found : user_pref("CT2990218.LastLogin_3.8.1.0", "Fri Jan 06 2012 22:59:13 GMT+0100"); Found : user_pref("CT2990218.LastLogin_3.9.0.3", "Mon Feb 13 2012 19:22:41 GMT+0100"); Found : user_pref("CT2990218.LatestVersion", "3.14.1.0"); Found : user_pref("CT2990218.Locale", "en"); Found : user_pref("CT2990218.MAX_NUMBER_OF_ALERTS_129780905335630475", "1_1335277192072"); Found : user_pref("CT2990218.MCDetectTooltipHeight", "83"); Found : user_pref("CT2990218.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2990218.MCDetectTooltipWidth", "295"); Found : user_pref("CT2990218.MyStuffEnabledAtInstallation", true); Found : user_pref("CT2990218.OriginalFirstVersion", "3.8.0.8"); Found : user_pref("CT2990218.RadioIsPodcast", false); Found : user_pref("CT2990218.RadioLastCheckTime", "Sun Jun 10 2012 18:18:18 GMT+0200"); Found : user_pref("CT2990218.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2990218.RadioLastUpdateServer", "0"); Found : user_pref("CT2990218.RadioMediaID", "8546"); Found : user_pref("CT2990218.RadioMediaType", "Media Player"); Found : user_pref("CT2990218.RadioMenuSelectedID", "EBRadioMenu_CT29902188546"); Found : user_pref("CT2990218.RadioShrinkedFromSetup", false); Found : user_pref("CT2990218.RadioStationName", "Radio%208"); Found : user_pref("CT2990218.RadioStationURL", "hxxp://stream.radio8.de:8000/live.m3u"); Found : user_pref("CT2990218.SearchBoxWidth", 150); Found : user_pref("CT2990218.SearchCaption", "servershare Customized Web Search"); Found : user_pref("CT2990218.SearchEngineBeforeUnload", "servershare Customized Web Search"); Found : user_pref("CT2990218.SearchFromAddressBarIsInit", true); Found : user_pref("CT2990218.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT299[...] Found : user_pref("CT2990218.SearchInNewTabEnabled", true); Found : user_pref("CT2990218.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2990218.SearchInNewTabLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Found : user_pref("CT2990218.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2990218.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Found : user_pref("CT2990218.SearchProtectorEnabled", true); Found : user_pref("CT2990218.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2990218.SendProtectorDataViaLogin", true); Found : user_pref("CT2990218.ServiceMapLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2990218.SettingsLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Found : user_pref("CT2990218.SettingsLastUpdate", "1345033695"); Found : user_pref("CT2990218.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2990218&SearchSource=13"); Found : user_pref("CT2990218.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2990218.ThirdPartyComponentsLastCheck", "Fri Jun 01 2012 18:07:36 GMT+0200"); Found : user_pref("CT2990218.ThirdPartyComponentsLastUpdate", "1331805997"); Found : user_pref("CT2990218.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2990218.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2990218"); Found : user_pref("CT2990218.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2990218.UserID", "UN66506179217539276"); Found : user_pref("CT2990218.ValidationData_Search", 0); Found : user_pref("CT2990218.ValidationData_Toolbar", 2); Found : user_pref("CT2990218.WeatherNetwork", ""); Found : user_pref("CT2990218.WeatherPollDate", "Sun Jun 10 2012 20:18:24 GMT+0200"); Found : user_pref("CT2990218.WeatherUnit", "C"); Found : user_pref("CT2990218.alertChannelId", "1381953"); Found : user_pref("CT2990218.backendstorage.autocompletepro_enable", "31"); Found : user_pref("CT2990218.backendstorage.autocompletepro_enable_auto", "31"); Found : user_pref("CT2990218.backendstorage.cb_firstuse0100", "31"); Found : user_pref("CT2990218.backendstorage.cb_user_id_000", "43423138383331323836393431395F46697265666F78")[...] Found : user_pref("CT2990218.backendstorage.cbcountry_000", "4445"); Found : user_pref("CT2990218.backendstorage.cbfirsttime", "5468752041707220303520323031322031343A30303A34322[...] Found : user_pref("CT2990218.backendstorage.conduitehowfirsttime", "55623374436840"); Found : user_pref("CT2990218.backendstorage.conduitehowinfo", "7B2274696D65456C6170736564223A22313336222C227[...] Found : user_pref("CT2990218.backendstorage.conduitehowloadidx", "30"); Found : user_pref("CT2990218.backendstorage.conduitehowloadtab", "7472656E64696E67"); Found : user_pref("CT2990218.backendstorage.conduitehowmain", "7B226C6F636174696F6E223A22636F6E6475697445686[...] Found : user_pref("CT2990218.backendstorage.conduitehowmainold", "7B226C6F636174696F6E223A22636F6E6475697445[...] Found : user_pref("CT2990218.backendstorage.conduitehowtoastershown", "3235"); Found : user_pref("CT2990218.backendstorage.conduitehowtrending", "7B226C6F636174696F6E223A22636F6E647569744[...] Found : user_pref("CT2990218.backendstorage.conduitehowtrendingold", "7B226C6F636174696F6E223A22636F6E647569[...] Found : user_pref("CT2990218.backendstorage.conduitehowupdated", "31333335333839373939303630"); Found : user_pref("CT2990218.backendstorage.facebbok_user_cuid_100002511723621", "31633635303030312D61363330[...] Found : user_pref("CT2990218.backendstorage.facebbok_user_id", "6E6F6E65"); Found : user_pref("CT2990218.backendstorage.facebook_conduit_social_sskey_100002511723621", "4472434F2D55536[...] Found : user_pref("CT2990218.backendstorage.facebook_ctid_connect_send_n", "73656E646564"); Found : user_pref("CT2990218.backendstorage.facebook_ctid_connect_send_new", "73656E646564"); Found : user_pref("CT2990218.backendstorage.facebook_first_visit", "6E6F744669727374"); Found : user_pref("CT2990218.backendstorage.facebook_last_message_choice", "656D707479"); Found : user_pref("CT2990218.backendstorage.facebook_loggedin", ""); Found : user_pref("CT2990218.backendstorage.facebook_login_refresh", "302E3432383532333037393630373733353137[...] Found : user_pref("CT2990218.backendstorage.facebook_login_status", "30"); Found : user_pref("CT2990218.backendstorage.facebook_lust_recieve", "343837373630392C"); Found : user_pref("CT2990218.backendstorage.facebook_lust_recievegadet", "343837373630392C"); Found : user_pref("CT2990218.backendstorage.facebook_mode", "32"); Found : user_pref("CT2990218.backendstorage.facebook_permission_lastshow_100002511723621", "3133323334353635[...] Found : user_pref("CT2990218.backendstorage.facebook_toolbar_not_numer", "31"); Found : user_pref("CT2990218.backendstorage.facebook_user_locale", "656E"); Found : user_pref("CT2990218.backendstorage.facebook_user_name", "6E6F6E65"); Found : user_pref("CT2990218.backendstorage.facebook_user_token", "6E6F6E65"); Found : user_pref("CT2990218.backendstorage.facebooknotifications", "30"); Found : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebook_last_visit_tab", [...] Found : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebook_permission_showsn[...] Found : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebooklanguagebyuser", "[...] Found : user_pref("CT2990218.backendstorage.printitgreenstatus", "74727565"); Found : user_pref("CT2990218.backendstorage.sf_just_installed", "46414C5345"); Found : user_pref("CT2990218.backendstorage.sf_status", "454E41424C4544"); Found : user_pref("CT2990218.backendstorage.sf_user_got_first_time_window", "54525545"); Found : user_pref("CT2990218.backendstorage.sf_user_id", "6369645F353432303132313430343232323233353338"); Found : user_pref("CT2990218.backendstorage.url_history0001", "687474703A2F2F7777772E66616365626F6F6B2E636F6[...] Found : user_pref("CT2990218.components.1000034", true); Found : user_pref("CT2990218.components.1000082", true); Found : user_pref("CT2990218.components.1000234", true); Found : user_pref("CT2990218.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2990218.globalFirstTimeInfoLastCheckTime", "Thu Jun 07 2012 17:56:36 GMT+0200"); Found : user_pref("CT2990218.homepageProtectorEnableByLogin", true); Found : user_pref("CT2990218.initDone", true); Found : user_pref("CT2990218.isAppTrackingManagerOn", true); Found : user_pref("CT2990218.isFirstRadioInstallation", false); Found : user_pref("CT2990218.myStuffEnabled", true); Found : user_pref("CT2990218.myStuffPublihserMinWidth", 400); Found : user_pref("CT2990218.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2990218.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2990218.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2990218.oldAppsList", "129473675475275497,129473675475275498,111,129473675475431751,129[...] Found : user_pref("CT2990218.revertSettingsEnabled", true); Found : user_pref("CT2990218.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2990218.searchProtectorEnableByLogin", true); Found : user_pref("CT2990218.testingCtid", ""); Found : user_pref("CT2990218.toolbarAppMetaDataLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Found : user_pref("CT2990218.toolbarContextMenuLastCheckTime", "Fri Jun 08 2012 16:04:35 GMT+0200"); Found : user_pref("CT2990218.usagesFlag", 2); Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2319825&Search[...] Found : user_pref("CommunityToolbar.ConduitSearchList", "Winload Customized Web Search,servershare Customize[...] Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2319825/CT2319825[...] Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2990218/CT2990218[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1381953/1377612/DE", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/715912/711772/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2319825", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2990218", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2319825",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2990218",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2319825&octid=[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2990218&octid=[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"cc4[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"7ae[...] Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Marcel\\AppData\\Roaming\\Mozilla\\[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Found : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://storage.conduit.com/MarketPlace/47/ca/47c[...] Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://scripts.demandmedia.com/conduit/ehow/gadget.h[...] Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://storage.conduit.com/MarketPlace/47/ca/47cb29c[...] Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.sweetim.com/search.asp?src[...] Found : user_pref("CommunityToolbar.ToolbarsList", "CT2319825,CT2990218"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825,CT2990218"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2319825,CT2990218"); Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Found : user_pref("CommunityToolbar.globalUserId", "b791c6e9-5593-4b1c-adeb-761ff8d8a115"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2990218"); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Jun 04 2012 18:05:1[...] Found : user_pref("CommunityToolbar.notifications.alertEnabled", true); Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Jun 10 2012 12:56:00 GMT+020[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jun 10 2012 19:58:22 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "794ac78d-e562-4a9e-a69e-add0c166dc56"); Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/"); Found : user_pref("CommunityToolbar.originalSearchEngine", "SweetIM Search"); Found : user_pref("extensions.enabledAddons", "ffox@bandoo.com:5.1,ffxtlbr@Facemoods.com:1.2.1,{ACAA314B-EEB[...] Found : user_pref("extensions.facemoods.aflt", "_#ddrnw"); Found : user_pref("extensions.facemoods.firstRun", false); Found : user_pref("extensions.facemoods.lastActv", "16"); Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=2&q=[...] Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Found : user_pref("sweetim.toolbar.mode.debug", "false"); Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Found : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", ""); Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Found : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...] Found : user_pref("sweetim.toolbar.search.history.capacity", "10"); Found : user_pref("sweetim.toolbar.searchguard.enable", "true"); Found : user_pref("sweetim.toolbar.simapp_id", "{EC185B61-D171-11E0-8D6D-00248C0D4FD2}"); Found : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={EC185B61-D171-11E0-8D6D-[...] Found : user_pref("sweetim.toolbar.version", "1.2.0.2"); -\\ Google Chrome v21.0.1180.79 File : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "explicit_host": [ "hxxp://igor.facemoods.com/*", "hxxp://reports.facemoods.com/*" ], Found : "css": [ "style/facemoods_chrome_1.0.1.css" ], Found : "name": "Facemoods", Found : "permissions": [ "tabs", "hxxp://igor.facemoods.com/", "hxxp://reports.facemoods.com/[...] Found : "update_url": "hxxp://facemoods.com/public/download/chrome/update.xml", Found : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT231982[...] ************************* AdwCleaner[R1].txt - [51135 octets] - [16/08/2012 21:24:23] ########## EOF - C:\AdwCleaner[R1].txt - [51264 octets] ########## |
17.08.2012, 01:01 | #8 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
17.08.2012, 15:09 | #9 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt 1 "adwcleaner" Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/17/2012 at 12:03:09 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (32 bits) # User : Marcel - MARCEL-PC # Boot Mode : Normal # Running from : C:\Users\Marcel\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : Bandoo Coordinator ***** [Files / Folders] ***** Folder Deleted : C:\Users\Marcel\AppData\Local\APN Folder Deleted : C:\Users\Marcel\AppData\Local\AskToolbar Folder Deleted : C:\Users\Marcel\AppData\Local\Conduit Folder Deleted : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif Folder Deleted : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk Folder Deleted : C:\Users\Marcel\AppData\Local\Ilivid Player Folder Deleted : C:\Users\Marcel\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Marcel\AppData\LocalLow\Bandoo Folder Deleted : C:\Users\Marcel\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Marcel\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Marcel\AppData\LocalLow\facemoods.com Folder Deleted : C:\Users\Marcel\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Marcel\AppData\LocalLow\Winload Folder Deleted : C:\Users\Marcel\AppData\LocalLow\WiseConvert_1.3 Folder Deleted : C:\Users\Marcel\AppData\Roaming\Bandoo Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\ConduitCommon Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\CT2319825 Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\CT2990218 Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\SweetIMToolbarData Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{6571950c-6eb2-4d8b-975e-5a25053ff845} Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffox@bandoo.com Folder Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\extensions\ffxtlbr@Facemoods.com Folder Deleted : C:\ProgramData\Bandoo Folder Deleted : C:\ProgramData\InstallMate Folder Deleted : C:\ProgramData\SweetIM Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandoo Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\Program Files\Bandoo Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\ConduitEngine Folder Deleted : C:\Program Files\facemoods.com Folder Deleted : C:\Program Files\Ilivid Folder Deleted : C:\Program Files\SweetIM Folder Deleted : C:\Program Files\Trymedia Folder Deleted : C:\Program Files\Winload Folder Deleted : C:\Program Files\WiseConvert_1.3 Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Folder Deleted : C:\ProgramData\Premium File Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\Conduit.xml File Deleted : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\searchplugins\SweetIm.xml ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2319825[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3242337 Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Ask.com.tmp Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\facemoods.com Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\SweetIm Key Deleted : HKLM\SOFTWARE\APN Key Deleted : HKLM\SOFTWARE\AskToolbar Key Deleted : HKLM\SOFTWARE\bandoo Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCoordinator.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.BandooCoordinator.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.CoordinatorUI.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.hxxpAsyncResult.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier Key Deleted : HKLM\SOFTWARE\Classes\BandooCoordinator.PlugInNotifier.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin Key Deleted : HKLM\SOFTWARE\Classes\BandooIEPlugin.BandooIEPlugin.1 Key Deleted : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl Key Deleted : HKLM\SOFTWARE\Classes\BFlashAnimator.BFlashAnimatorCtrl.1 Key Deleted : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl Key Deleted : HKLM\SOFTWARE\Classes\BGIFAnimator.BGIFAnimatorCtrl.1 Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Key Deleted : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Key Deleted : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Key Deleted : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Key Deleted : HKLM\SOFTWARE\Classes\sim-packages Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\conduitEngine Key Deleted : HKLM\SOFTWARE\facemoods.com Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dloejdefkancmfajekobpfoacecnhpgp Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandoo Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winload Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WiseConvert_1.3 Toolbar Key Deleted : HKLM\SOFTWARE\Software Key Deleted : HKLM\SOFTWARE\SweetIM Key Deleted : HKLM\SOFTWARE\Winload Key Deleted : HKLM\SOFTWARE\WiseConvert_1.3 Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [ffox@bandoo.com] ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A01A3335-0C30-4312-A430-92356CC37A92} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EDE2C296-2458-4E3B-A846-4B512C0703B5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{074E4EFE-81BB-4EA4-866E-082CB0E01070} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0CE5B352-9D9C-41E1-9551-FCCD92820217} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{167B2B5F-2757-434A-BBDA-2FDB2003F14F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF2B6317-C367-401B-83B8-80302D6588A7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F5379B4B-24D8-432A-9A96-BE75EE5117DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4DF2927E-63DB-4E43-A3F6-1259808CD6D7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D51392A5-3A08-41E6-AC05-C3B0FB94C41B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01222E21-6BD0-4EB3-94F1-967EB09CCED5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{33DDFC61-F531-4982-8C32-4212B7835D44} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3AD7A5B6-610D-4A82-979E-0AED20920690} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4410C118-B23C-406C-9F52-9CDABD90A5EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C123289-82E1-4DA7-A3C2-B8D28AAD114B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A742D5D2-30D8-48FA-BE5F-3B978A69D70A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFF5C317-9E75-4E68-AA2A-F8335395CF7F} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EF3BA6C-A88B-4848-B469-35D4C3130AC5} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EC184D9-82C3-407D-8982-5623348A5E54} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{05AE71FE-0161-4CAB-83BC-5E7191281EBF} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6087829B-114F-42A1-A72B-B4AEDCEA4E5B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CE1CB632-6817-47B3-8587-D05AF75D6D5A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4DF2927E-63DB-4E43-A3F6-1259808CD6D7} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D51392A5-3A08-41E6-AC05-C3B0FB94C41B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB5CEE80-030A-4ED8-8E20-454E9C68380F} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\prefs.js C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\fr3c3nt2.default\user.js ... Deleted ! Deleted : user_pref("CT2319825..clientLogIsEnabled", false); Deleted : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2319825.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2319825.AppTrackingLastCheckTime", "Tue Oct 18 2011 15:36:16 GMT+0200"); Deleted : user_pref("CT2319825.BrowserCompStateIsOpen_129714600517272937", true); Deleted : user_pref("CT2319825.CTID", "CT2319825"); Deleted : user_pref("CT2319825.CurrentServerDate", "17-8-2012"); Deleted : user_pref("CT2319825.DSInstall", true); Deleted : user_pref("CT2319825.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2319825.DialogsGetterLastCheckTime", "Thu Aug 16 2012 21:22:51 GMT+0200"); Deleted : user_pref("CT2319825.DownloadReferralCookieData", ""); Deleted : user_pref("CT2319825.EMailNotifierPollDate", "Sun Jan 29 2012 12:48:13 GMT+0100"); Deleted : user_pref("CT2319825.FeedPollDate11908299", "Sun Jan 29 2012 22:18:25 GMT+0100"); Deleted : user_pref("CT2319825.FirstServerDate", "17-10-2011"); Deleted : user_pref("CT2319825.FirstTime", true); Deleted : user_pref("CT2319825.FirstTimeFF3", true); Deleted : user_pref("CT2319825.FixPageNotFoundErrors", true); Deleted : user_pref("CT2319825.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2319825.HPInstall", false); Deleted : user_pref("CT2319825.HasUserGlobalKeys", true); Deleted : user_pref("CT2319825.HomePageProtectorEnabled", false); Deleted : user_pref("CT2319825.HomepageBeforeUnload", "hxxp://www.google.de/"); Deleted : user_pref("CT2319825.Initialize", true); Deleted : user_pref("CT2319825.InitializeCommonPrefs", true); Deleted : user_pref("CT2319825.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2319825.InstallationType", "ConduitIntegration"); Deleted : user_pref("CT2319825.InstalledDate", "Mon Oct 17 2011 11:29:25 GMT+0200"); Deleted : user_pref("CT2319825.InvalidateCache", false); Deleted : user_pref("CT2319825.IsAlertDBUpdated", true); Deleted : user_pref("CT2319825.IsGrouping", false); Deleted : user_pref("CT2319825.IsInitSetupIni", true); Deleted : user_pref("CT2319825.IsMulticommunity", false); Deleted : user_pref("CT2319825.IsOpenThankYouPage", false); Deleted : user_pref("CT2319825.IsOpenUninstallPage", true); Deleted : user_pref("CT2319825.IsProtectorsInit", true); Deleted : user_pref("CT2319825.LanguagePackLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2319825.LastLogin_3.13.0.6", "Sun Jul 15 2012 23:29:23 GMT+0200"); Deleted : user_pref("CT2319825.LastLogin_3.14.1.0", "Fri Aug 17 2012 12:01:15 GMT+0200"); Deleted : user_pref("CT2319825.LastLogin_3.7.0.6", "Tue Oct 18 2011 15:36:06 GMT+0200"); Deleted : user_pref("CT2319825.LastLogin_3.9.0.3", "Sun Jan 29 2012 20:18:25 GMT+0100"); Deleted : user_pref("CT2319825.LatestVersion", "3.14.1.0"); Deleted : user_pref("CT2319825.Locale", "de"); Deleted : user_pref("CT2319825.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2319825.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2319825.MyStuffEnabledAtInstallation", true); Deleted : user_pref("CT2319825.OriginalFirstVersion", "3.7.0.6"); Deleted : user_pref("CT2319825.RadioIsPodcast", false); Deleted : user_pref("CT2319825.RadioLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Deleted : user_pref("CT2319825.RadioLastUpdateIPServer", "3"); Deleted : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000"); Deleted : user_pref("CT2319825.RadioMediaID", "11949532"); Deleted : user_pref("CT2319825.RadioMediaType", "Media Player"); Deleted : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532"); Deleted : user_pref("CT2319825.RadioShrinkedFromSetup", false); Deleted : user_pref("CT2319825.RadioStationName", "1Live"); Deleted : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_ei[...] Deleted : user_pref("CT2319825.SavedHomepage", "hxxp://www.google.de/"); Deleted : user_pref("CT2319825.SearchCaption", "Winload Customized Web Search"); Deleted : user_pref("CT2319825.SearchEngineBeforeUnload", "servershare Customized Web Search"); Deleted : user_pref("CT2319825.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT231[...] Deleted : user_pref("CT2319825.SearchInNewTabEnabled", true); Deleted : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Deleted : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Deleted : user_pref("CT2319825.SearchProtectorEnabled", false); Deleted : user_pref("CT2319825.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT2319825.SendProtectorDataViaLogin", true); Deleted : user_pref("CT2319825.ServiceMapLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2319825.SettingsLastCheckTime", "Fri Aug 17 2012 12:01:10 GMT+0200"); Deleted : user_pref("CT2319825.SettingsLastUpdate", "1345149429"); Deleted : user_pref("CT2319825.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2319825&SearchSource=13"); Deleted : user_pref("CT2319825.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Sun Jan 29 2012 12:48:13 GMT+0100"); Deleted : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255344657"); Deleted : user_pref("CT2319825.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT2319825.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2319825"); Deleted : user_pref("CT2319825.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Deleted : user_pref("CT2319825.UserID", "UN65887214923830073"); Deleted : user_pref("CT2319825.ValidationData_Toolbar", 0); Deleted : user_pref("CT2319825.WeatherNetwork", ""); Deleted : user_pref("CT2319825.WeatherPollDate", "Sun Jan 29 2012 12:48:14 GMT+0100"); Deleted : user_pref("CT2319825.WeatherUnit", "C"); Deleted : user_pref("CT2319825.alertChannelId", "715912"); Deleted : user_pref("CT2319825.backendstorage.id", "3236363530323039"); Deleted : user_pref("CT2319825.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Deleted : user_pref("CT2319825.globalFirstTimeInfoLastCheckTime", "Sun Jan 29 2012 20:18:25 GMT+0100"); Deleted : user_pref("CT2319825.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT2319825.initDone", true); Deleted : user_pref("CT2319825.isAppTrackingManagerOn", true); Deleted : user_pref("CT2319825.isFirstRadioInstallation", false); Deleted : user_pref("CT2319825.myStuffEnabled", true); Deleted : user_pref("CT2319825.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2319825.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2319825.oldAppsList", "128898076802619665,128898076802619666,111,1000082,12945346285535[...] Deleted : user_pref("CT2319825.revertSettingsEnabled", true); Deleted : user_pref("CT2319825.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT2319825.searchProtectorEnableByLogin", true); Deleted : user_pref("CT2319825.testingCtid", ""); Deleted : user_pref("CT2319825.toolbarAppMetaDataLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2319825.toolbarContextMenuLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Deleted : user_pref("CT2319825.usagesFlag", 2); Deleted : user_pref("CT2990218..clientLogIsEnabled", false); Deleted : user_pref("CT2990218..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2990218..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2990218.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT2990218.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2990218.AppTrackingLastCheckTime", "Wed May 23 2012 16:19:02 GMT+0200"); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129473677946131396", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129773572938675051", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129773574219941454", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780905110786675", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780905202661677", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780905289224178", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780905335630475", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780905377192976", true); Deleted : user_pref("CT2990218.BrowserCompStateIsOpen_129780909624536121", true); Deleted : user_pref("CT2990218.CT2990218", "CT2990218"); Deleted : user_pref("CT2990218.CurrentServerDate", "17-8-2012"); Deleted : user_pref("CT2990218.DSChangedManually", false); Deleted : user_pref("CT2990218.DSInstall", true); Deleted : user_pref("CT2990218.DSProtectChoice", true); Deleted : user_pref("CT2990218.DSProtectCount", 1); Deleted : user_pref("CT2990218.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2990218.DialogsGetterLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2990218.DownloadReferralCookieData", ""); Deleted : user_pref("CT2990218.EMailNotifierPollDate", "Sun Jun 10 2012 20:18:20 GMT+0200"); Deleted : user_pref("CT2990218.FirstServerDate", "23-11-2011"); Deleted : user_pref("CT2990218.FirstTime", true); Deleted : user_pref("CT2990218.FirstTimeFF3", true); Deleted : user_pref("CT2990218.FixPageNotFoundErrors", false); Deleted : user_pref("CT2990218.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2990218.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2990218.HPInstall", false); Deleted : user_pref("CT2990218.HPProtectChoice", true); Deleted : user_pref("CT2990218.HPProtectCount", 6); Deleted : user_pref("CT2990218.HasUserGlobalKeys", true); Deleted : user_pref("CT2990218.HomePageProtectorEnabled", false); Deleted : user_pref("CT2990218.HomepageBeforeUnload", "hxxp://www.google.de/"); Deleted : user_pref("CT2990218.Initialize", true); Deleted : user_pref("CT2990218.InitializeCommonPrefs", true); Deleted : user_pref("CT2990218.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2990218.InstallationType", "Unknown"); Deleted : user_pref("CT2990218.InstalledDate", "Wed Nov 23 2011 14:35:22 GMT+0100"); Deleted : user_pref("CT2990218.InvalidateCache", false); Deleted : user_pref("CT2990218.IsAlertDBUpdated", true); Deleted : user_pref("CT2990218.IsGrouping", false); Deleted : user_pref("CT2990218.IsInitSetupIni", true); Deleted : user_pref("CT2990218.IsMulticommunity", false); Deleted : user_pref("CT2990218.IsOpenThankYouPage", true); Deleted : user_pref("CT2990218.IsOpenUninstallPage", true); Deleted : user_pref("CT2990218.IsProtectorsInit", true); Deleted : user_pref("CT2990218.LanguagePackLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2990218.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2990218.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2990218.LastLogin_3.10.0.1", "Sat Apr 28 2012 21:03:30 GMT+0200"); Deleted : user_pref("CT2990218.LastLogin_3.11.0.3", "Sun May 06 2012 20:00:38 GMT+0200"); Deleted : user_pref("CT2990218.LastLogin_3.12.2.3", "Mon May 21 2012 14:34:00 GMT+0200"); Deleted : user_pref("CT2990218.LastLogin_3.13.0.6", "Mon Jul 09 2012 15:11:25 GMT+0200"); Deleted : user_pref("CT2990218.LastLogin_3.14.1.0", "Fri Aug 17 2012 12:01:14 GMT+0200"); Deleted : user_pref("CT2990218.LastLogin_3.8.0.8", "Mon Dec 05 2011 18:23:20 GMT+0100"); Deleted : user_pref("CT2990218.LastLogin_3.8.1.0", "Fri Jan 06 2012 22:59:13 GMT+0100"); Deleted : user_pref("CT2990218.LastLogin_3.9.0.3", "Mon Feb 13 2012 19:22:41 GMT+0100"); Deleted : user_pref("CT2990218.LatestVersion", "3.14.1.0"); Deleted : user_pref("CT2990218.Locale", "en"); Deleted : user_pref("CT2990218.MAX_NUMBER_OF_ALERTS_129780905335630475", "1_1335277192072"); Deleted : user_pref("CT2990218.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2990218.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2990218.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2990218.MyStuffEnabledAtInstallation", true); Deleted : user_pref("CT2990218.OriginalFirstVersion", "3.8.0.8"); Deleted : user_pref("CT2990218.RadioIsPodcast", false); Deleted : user_pref("CT2990218.RadioLastCheckTime", "Sun Jun 10 2012 18:18:18 GMT+0200"); Deleted : user_pref("CT2990218.RadioLastUpdateIPServer", "3"); Deleted : user_pref("CT2990218.RadioLastUpdateServer", "0"); Deleted : user_pref("CT2990218.RadioMediaID", "8546"); Deleted : user_pref("CT2990218.RadioMediaType", "Media Player"); Deleted : user_pref("CT2990218.RadioMenuSelectedID", "EBRadioMenu_CT29902188546"); Deleted : user_pref("CT2990218.RadioShrinkedFromSetup", false); Deleted : user_pref("CT2990218.RadioStationName", "Radio%208"); Deleted : user_pref("CT2990218.RadioStationURL", "hxxp://stream.radio8.de:8000/live.m3u"); Deleted : user_pref("CT2990218.SearchBoxWidth", 150); Deleted : user_pref("CT2990218.SearchCaption", "servershare Customized Web Search"); Deleted : user_pref("CT2990218.SearchEngineBeforeUnload", "servershare Customized Web Search"); Deleted : user_pref("CT2990218.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2990218.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT299[...] Deleted : user_pref("CT2990218.SearchInNewTabEnabled", true); Deleted : user_pref("CT2990218.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2990218.SearchInNewTabLastCheckTime", "Thu Aug 16 2012 21:22:45 GMT+0200"); Deleted : user_pref("CT2990218.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2990218.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Deleted : user_pref("CT2990218.SearchProtectorEnabled", true); Deleted : user_pref("CT2990218.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT2990218.SendProtectorDataViaLogin", true); Deleted : user_pref("CT2990218.ServiceMapLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2990218.SettingsLastCheckTime", "Fri Aug 17 2012 12:01:10 GMT+0200"); Deleted : user_pref("CT2990218.SettingsLastUpdate", "1345149440"); Deleted : user_pref("CT2990218.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2990218&SearchSource=13"); Deleted : user_pref("CT2990218.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2990218.ThirdPartyComponentsLastCheck", "Fri Jun 01 2012 18:07:36 GMT+0200"); Deleted : user_pref("CT2990218.ThirdPartyComponentsLastUpdate", "1331805997"); Deleted : user_pref("CT2990218.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT2990218.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2990218"); Deleted : user_pref("CT2990218.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Deleted : user_pref("CT2990218.UserID", "UN66506179217539276"); Deleted : user_pref("CT2990218.ValidationData_Search", 0); Deleted : user_pref("CT2990218.ValidationData_Toolbar", 2); Deleted : user_pref("CT2990218.WeatherNetwork", ""); Deleted : user_pref("CT2990218.WeatherPollDate", "Sun Jun 10 2012 20:18:24 GMT+0200"); Deleted : user_pref("CT2990218.WeatherUnit", "C"); Deleted : user_pref("CT2990218.alertChannelId", "1381953"); Deleted : user_pref("CT2990218.backendstorage.autocompletepro_enable", "31"); Deleted : user_pref("CT2990218.backendstorage.autocompletepro_enable_auto", "31"); Deleted : user_pref("CT2990218.backendstorage.cb_firstuse0100", "31"); Deleted : user_pref("CT2990218.backendstorage.cb_user_id_000", "43423138383331323836393431395F46697265666F78")[...] Deleted : user_pref("CT2990218.backendstorage.cbcountry_000", "4445"); Deleted : user_pref("CT2990218.backendstorage.cbfirsttime", "5468752041707220303520323031322031343A30303A34322[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowfirsttime", "55623374436840"); Deleted : user_pref("CT2990218.backendstorage.conduitehowinfo", "7B2274696D65456C6170736564223A22313336222C227[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowloadidx", "30"); Deleted : user_pref("CT2990218.backendstorage.conduitehowloadtab", "7472656E64696E67"); Deleted : user_pref("CT2990218.backendstorage.conduitehowmain", "7B226C6F636174696F6E223A22636F6E6475697445686[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowmainold", "7B226C6F636174696F6E223A22636F6E6475697445[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowtoastershown", "3235"); Deleted : user_pref("CT2990218.backendstorage.conduitehowtrending", "7B226C6F636174696F6E223A22636F6E647569744[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowtrendingold", "7B226C6F636174696F6E223A22636F6E647569[...] Deleted : user_pref("CT2990218.backendstorage.conduitehowupdated", "31333335333839373939303630"); Deleted : user_pref("CT2990218.backendstorage.facebbok_user_cuid_100002511723621", "31633635303030312D61363330[...] Deleted : user_pref("CT2990218.backendstorage.facebbok_user_id", "6E6F6E65"); Deleted : user_pref("CT2990218.backendstorage.facebook_conduit_social_sskey_100002511723621", "4472434F2D55536[...] Deleted : user_pref("CT2990218.backendstorage.facebook_ctid_connect_send_n", "73656E646564"); Deleted : user_pref("CT2990218.backendstorage.facebook_ctid_connect_send_new", "73656E646564"); Deleted : user_pref("CT2990218.backendstorage.facebook_first_visit", "6E6F744669727374"); Deleted : user_pref("CT2990218.backendstorage.facebook_last_message_choice", "656D707479"); Deleted : user_pref("CT2990218.backendstorage.facebook_loggedin", ""); Deleted : user_pref("CT2990218.backendstorage.facebook_login_refresh", "302E3432383532333037393630373733353137[...] Deleted : user_pref("CT2990218.backendstorage.facebook_login_status", "30"); Deleted : user_pref("CT2990218.backendstorage.facebook_lust_recieve", "343837373630392C"); Deleted : user_pref("CT2990218.backendstorage.facebook_lust_recievegadet", "343837373630392C"); Deleted : user_pref("CT2990218.backendstorage.facebook_mode", "32"); Deleted : user_pref("CT2990218.backendstorage.facebook_permission_lastshow_100002511723621", "3133323334353635[...] Deleted : user_pref("CT2990218.backendstorage.facebook_toolbar_not_numer", "31"); Deleted : user_pref("CT2990218.backendstorage.facebook_user_locale", "656E"); Deleted : user_pref("CT2990218.backendstorage.facebook_user_name", "6E6F6E65"); Deleted : user_pref("CT2990218.backendstorage.facebook_user_token", "6E6F6E65"); Deleted : user_pref("CT2990218.backendstorage.facebooknotifications", "30"); Deleted : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebook_last_visit_tab", [...] Deleted : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebook_permission_showsn[...] Deleted : user_pref("CT2990218.backendstorage.hxxp://facebook_conduitapps_com/v3_12.facebooklanguagebyuser", "[...] Deleted : user_pref("CT2990218.backendstorage.printitgreenstatus", "74727565"); Deleted : user_pref("CT2990218.backendstorage.sf_just_installed", "46414C5345"); Deleted : user_pref("CT2990218.backendstorage.sf_status", "454E41424C4544"); Deleted : user_pref("CT2990218.backendstorage.sf_user_got_first_time_window", "54525545"); Deleted : user_pref("CT2990218.backendstorage.sf_user_id", "6369645F353432303132313430343232323233353338"); Deleted : user_pref("CT2990218.backendstorage.url_history0001", "687474703A2F2F7777772E66616365626F6F6B2E636F6[...] Deleted : user_pref("CT2990218.components.1000034", true); Deleted : user_pref("CT2990218.components.1000082", true); Deleted : user_pref("CT2990218.components.1000234", true); Deleted : user_pref("CT2990218.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Deleted : user_pref("CT2990218.globalFirstTimeInfoLastCheckTime", "Thu Jun 07 2012 17:56:36 GMT+0200"); Deleted : user_pref("CT2990218.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT2990218.initDone", true); Deleted : user_pref("CT2990218.isAppTrackingManagerOn", true); Deleted : user_pref("CT2990218.isFirstRadioInstallation", false); Deleted : user_pref("CT2990218.myStuffEnabled", true); Deleted : user_pref("CT2990218.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2990218.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2990218.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2990218.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2990218.oldAppsList", "129473675475275497,129473675475275498,111,129473675475431751,129[...] Deleted : user_pref("CT2990218.revertSettingsEnabled", true); Deleted : user_pref("CT2990218.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT2990218.searchProtectorEnableByLogin", true); Deleted : user_pref("CT2990218.testingCtid", ""); Deleted : user_pref("CT2990218.toolbarAppMetaDataLastCheckTime", "Thu Aug 16 2012 21:22:46 GMT+0200"); Deleted : user_pref("CT2990218.toolbarContextMenuLastCheckTime", "Fri Jun 08 2012 16:04:35 GMT+0200"); Deleted : user_pref("CT2990218.usagesFlag", 2); Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2319825&Search[...] Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Winload Customized Web Search,servershare Customize[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2319825/CT2319825[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2990218/CT2990218[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1381953/1377612/DE", "\"0\"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/715912/711772/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2319825", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2990218", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2319825",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2990218",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2319825&octid=[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2990218&octid=[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"cc4[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"7ae[...] Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Marcel\\AppData\\Roaming\\Mozilla\\[...] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://storage.conduit.com/MarketPlace/47/ca/47c[...] Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://scripts.demandmedia.com/conduit/ehow/gadget.h[...] Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://storage.conduit.com/MarketPlace/47/ca/47cb29c[...] Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.sweetim.com/search.asp?src[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2319825,CT2990218"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825,CT2990218"); Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2319825,CT2990218"); Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Jan 29 2012 12:48:13 GMT+0100"); Deleted : user_pref("CommunityToolbar.globalUserId", "b791c6e9-5593-4b1c-adeb-761ff8d8a115"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2990218"); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Jun 04 2012 18:05:1[...] Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true); Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Jun 10 2012 12:56:00 GMT+020[...] Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jun 10 2012 19:58:22 GMT+0200"); Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "794ac78d-e562-4a9e-a69e-add0c166dc56"); Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/"); Deleted : user_pref("CommunityToolbar.originalSearchEngine", "SweetIM Search"); Deleted : user_pref("extensions.enabledAddons", "ffox@bandoo.com:5.1,ffxtlbr@Facemoods.com:1.2.1,{ACAA314B-EEB[...] Deleted : user_pref("extensions.facemoods.aflt", "_#ddrnw"); Deleted : user_pref("extensions.facemoods.firstRun", false); Deleted : user_pref("extensions.facemoods.lastActv", "17"); Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2990218&SearchSource=2&q=[...] Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Deleted : user_pref("sweetim.toolbar.mode.debug", "false"); Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...] Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10"); Deleted : user_pref("sweetim.toolbar.searchguard.enable", "true"); Deleted : user_pref("sweetim.toolbar.simapp_id", "{EC185B61-D171-11E0-8D6D-00248C0D4FD2}"); Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={EC185B61-D171-11E0-8D6D-[...] Deleted : user_pref("sweetim.toolbar.version", "1.2.0.2"); -\\ Google Chrome v21.0.1180.79 File : C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "explicit_host": [ "hxxp://igor.facemoods.com/*", "hxxp://reports.facemoods.com/*" ], Deleted : "css": [ "style/facemoods_chrome_1.0.1.css" ], Deleted : "name": "Facemoods", Deleted : "permissions": [ "tabs", "hxxp://igor.facemoods.com/", "hxxp://reports.facemoods.com/[...] Deleted : "update_url": "hxxp://facemoods.com/public/download/chrome/update.xml", Deleted : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT231982[...] ************************* AdwCleaner[R1].txt - [51266 octets] - [16/08/2012 21:24:23] AdwCleaner[S1].txt - [52524 octets] - [17/08/2012 12:03:09] ########## EOF - C:\AdwCleaner[S1].txt - [52653 octets] ########## Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 17.08.2012 12:15:31 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 17.08.2012 12:15:55 c:\program files\gamespy arcade gefunden: Trace.File.gamespy arcade!E1 c:\program files\gamespy arcade\install.log gefunden: Trace.File.gamespy arcade!E1 Key: hkey_local_machine\software\trymedia systems gefunden: Trace.Registry.trymedia!E1 Key: hkey_local_machine\software\trymedia systems\activemark software gefunden: Trace.Registry.trymedia!E1 C:\_OTL\MovedFiles\08162012_125110\C_Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ gefunden: Trojan.Win32.Sirefef.AMN!E1 C:\_OTL\MovedFiles\08162012_125110\C_Windows\Installer\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ gefunden: Trojan.Win32.Sirefef.AMN!E1 C:\_OTL\MovedFiles\08162012_125110\C_Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\00000001.@ gefunden: Trojan.Win32.Sirefef.AMN!E1 C:\_OTL\MovedFiles\08162012_125110\C_Users\Marcel\AppData\Local\{50db3481-ad41-50f7-484a-762f72c2bf9f}\U\80000000.@ gefunden: Trojan.Win32.Sirefef.AMN!E1 C:\Users\Marcel\Downloads\cnet2_HOMM2GOLD-dm_exe.exe gefunden: Riskware.Win32.InstallCore.AMN!E1 C:\Users\Marcel\Downloads\cnet2_HOMM2GOLD-dm_exe(1).exe gefunden: Riskware.Win32.InstallCore.AMN!E1 Gescannt 875599 Gefunden 10 Scan Ende: 17.08.2012 15:43:06 Scan Zeit: 3:27:11 |
17.08.2012, 15:20 | #10 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Sehr gut! Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
20.08.2012, 12:50 | #11 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrtCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=673acbcc7d03bb48b87e6828adfc6285 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-18 01:52:57 # local_time=2012-08-18 03:52:57 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 13817231 13817231 0 0 # compatibility_mode=5893 16776574 66 94 499587 96920139 0 0 # compatibility_mode=8192 67108863 100 0 202 202 0 0 # scanned=376187 # found=2 # cleaned=2 # scan_time=9028 C:\Users\Marcel\Downloads\speedupmypc.exe Win32/SpeedUpMyPC application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Marcel\Downloads\vlc-1.1.1.exe Win32/Adware.ToolPlugin application (deleted - quarantined) 00000000000000000000000000000000 C |
20.08.2012, 13:24 | #12 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
20.08.2012, 15:24 | #13 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 14.0.1 ist aktuell Flash (11,3,300,271) ist aktuell. Java (1,7,0,6) ist aktuell. Adobe Reader 10,1,4,38 ist aktuell. |
20.08.2012, 17:30 | #14 |
/// Helfer-Team | Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
22.08.2012, 13:03 | #15 |
| Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt Danke, und damit meine ich nicht so ein 08/15 Danke sondern eins das wirklich vom Herzen kommt Danke, dass du mir und meinem PC geholfen hast MfG Marcel |
Themen zu Wegen Verstoß gegen das Gesetzt der BRD Computer gesperrt |
anhang, blockiert, computer, ergebnis, euro, falsch, gesetze, gesperrt, handy, heute, hoffe, länger, malwarebytes, meldung, schei, schnell, schreibfehler, seite, starte, starten, thema, viren, virus, wissen, zahlen |