|
Plagegeister aller Art und deren Bekämpfung: mystart.indredibar bei Chorme.newTabWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.09.2012, 23:07 | #1 |
| mystart.indredibar bei Chorme.newTab Hallo zusammen, es scheint so, als hätte ich mir was eingefangen. Wenn ich in Chrome einen neuen Tab öffne taucht die mystart.indredibar Seite auf. Aus der System Steuerung habe ich das Programm entfernt und ich habe es auch geschafft, dass sich Chrome wieder normal verhält. Ich glaube aber nicht, dass der Mist schon komplett vom Rechner ist. Hier das Log vom OTL scan: HTML-Code: [CODE] OTL logfile created on: 19.09.2012 23:16:16 - Run 1 OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\jens\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy 3,97 Gb Total Physical Memory | 1,66 Gb Available Physical Memory | 41,94% Memory free 7,93 Gb Paging File | 5,37 Gb Available in Paging File | 67,72% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 218,41 Gb Total Space | 28,29 Gb Free Space | 12,95% Space Free | Partition Type: NTFS Drive D: | 232,88 Gb Total Space | 68,98 Gb Free Space | 29,62% Space Free | Partition Type: NTFS Drive E: | 14,28 Gb Total Space | 2,36 Gb Free Space | 16,53% Space Free | Partition Type: NTFS Computer Name: HP_NOTEBOOK | User Name: jskadmin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012.09.19 22:49:33 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\jens\Downloads\OTL.exe PRC - [2012.08.28 17:09:56 | 000,188,760 | ---- | M] () -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe PRC - [2012.08.27 21:32:54 | 000,059,280 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe PRC - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe PRC - [2012.08.09 23:12:18 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.07.23 20:37:36 | 000,686,280 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe PRC - [2012.06.17 19:52:09 | 006,380,440 | ---- | M] (BitTorrent, Inc.) -- D:\Applications\BitTorrent\bittorrent.exe PRC - [2012.02.23 13:22:56 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe PRC - [2011.09.22 02:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe PRC - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe PRC - [2009.12.01 13:37:48 | 000,322,624 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012.08.30 04:58:45 | 000,442,392 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll MOD - [2012.08.30 04:58:44 | 012,237,336 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll MOD - [2012.08.30 04:58:42 | 003,997,720 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll MOD - [2012.08.30 04:57:27 | 000,526,872 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\libglesv2.dll MOD - [2012.08.30 04:57:26 | 000,104,984 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\libegl.dll MOD - [2012.08.30 04:57:15 | 000,144,424 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\avutil-51.dll MOD - [2012.08.30 04:57:13 | 000,266,792 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\avformat-54.dll MOD - [2012.08.30 04:57:12 | 002,480,680 | ---- | M] () -- C:\Users\jens\AppData\Local\Google\Chrome\Application\21.0.1180.89\avcodec-54.dll MOD - [2012.08.28 17:09:56 | 000,167,256 | ---- | M] () -- C:\Program Files\Web Assistant\Extension32.dll MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012.08.28 17:09:56 | 000,188,760 | ---- | M] () [Auto | Running] -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant Updater) SRV:[b]64bit:[/b] - [2010.03.23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe -- (STacSV) SRV:[b]64bit:[/b] - [2009.07.30 18:42:34 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV:[b]64bit:[/b] - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009.07.08 14:49:02 | 000,030,520 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv) SRV:[b]64bit:[/b] - [2009.07.02 23:16:00 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2009.06.03 03:13:02 | 000,721,712 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\SysNative\vfsFPService.exe -- (vfsFPService) SRV:[b]64bit:[/b] - [2009.03.02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters) SRV:[b]64bit:[/b] - [2008.07.29 14:20:28 | 004,737,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90) SRV - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.04.21 03:16:42 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011.09.22 02:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe -- (Norton Internet Security) SRV - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service) SRV - [2010.10.22 14:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\Hp\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC) SRV - [2010.10.12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService) SRV - [2010.04.10 00:07:36 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010.03.23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe -- (STacSV) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.12.01 13:37:48 | 000,322,624 | ---- | M] (DigitalPersona, Inc.) [Auto | Running] -- C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe -- (DpHost) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.06.03 03:12:50 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vfsFPService.exe -- (vfsFPService) SRV - [2009.03.02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters) SRV - [2009.02.22 12:00:00 | 000,129,584 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\SysWOW64\ezsvc7.dll -- (ezSharedSvc) SRV - [2007.05.31 18:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 18:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012.07.09 13:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:[b]64bit:[/b] - [2012.07.04 00:15:56 | 000,090,232 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR162.SYS -- (SMR162) DRV:[b]64bit:[/b] - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011.10.15 01:18:33 | 000,561,800 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\cchpx64.sys -- (ccHP) DRV:[b]64bit:[/b] - [2011.09.22 02:35:58 | 000,279,160 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symtdi.sys -- (SYMTDI) DRV:[b]64bit:[/b] - [2011.09.22 02:35:58 | 000,120,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symfw.sys -- (SYMFW) DRV:[b]64bit:[/b] - [2011.09.22 02:35:58 | 000,056,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symndisv.sys -- (SYMNDISV) DRV:[b]64bit:[/b] - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt) DRV:[b]64bit:[/b] - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt) DRV:[b]64bit:[/b] - [2011.08.17 13:58:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt) DRV:[b]64bit:[/b] - [2011.08.17 13:58:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:[b]64bit:[/b] - [2011.08.17 13:58:20 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc) DRV:[b]64bit:[/b] - [2011.08.17 13:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd) DRV:[b]64bit:[/b] - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010.11.20 12:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:[b]64bit:[/b] - [2010.11.20 11:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:[b]64bit:[/b] - [2010.06.25 17:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot) DRV:[b]64bit:[/b] - [2010.06.15 16:53:58 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt) DRV:[b]64bit:[/b] - [2010.06.15 16:53:42 | 000,041,272 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer) DRV:[b]64bit:[/b] - [2010.05.27 22:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2010.03.23 14:53:06 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA) DRV:[b]64bit:[/b] - [2010.01.23 18:52:22 | 000,172,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:[b]64bit:[/b] - [2010.01.13 16:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) DRV:[b]64bit:[/b] - [2009.12.18 00:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:[b]64bit:[/b] - [2009.11.01 20:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64) DRV:[b]64bit:[/b] - [2009.09.04 10:36:15 | 000,031,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM) DRV:[b]64bit:[/b] - [2009.08.22 09:25:17 | 000,476,720 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtsp64.sys -- (SRTSP) DRV:[b]64bit:[/b] - [2009.08.22 09:25:17 | 000,402,992 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\SymEFA64.sys -- (SymEFA) DRV:[b]64bit:[/b] - [2009.08.22 09:25:17 | 000,334,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\BHDrvx64.sys -- (BHDrvx64) DRV:[b]64bit:[/b] - [2009.08.22 09:25:17 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtspx64.sys -- (SRTSPX) DRV:[b]64bit:[/b] - [2009.08.09 23:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:[b]64bit:[/b] - [2009.07.21 05:39:00 | 000,140,712 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR) DRV:[b]64bit:[/b] - [2009.07.21 01:33:42 | 007,058,432 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NETw1v64.sys -- (NETw1v64) DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam) DRV:[b]64bit:[/b] - [2009.07.14 02:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx) DRV:[b]64bit:[/b] - [2009.07.14 00:31:00 | 000,233,472 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009.07.02 23:51:00 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2009.07.01 22:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio) DRV:[b]64bit:[/b] - [2009.07.01 22:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt) DRV:[b]64bit:[/b] - [2009.07.01 22:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid) DRV:[b]64bit:[/b] - [2009.06.29 20:17:00 | 000,070,656 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir) DRV:[b]64bit:[/b] - [2009.06.29 19:00:00 | 000,116,752 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:[b]64bit:[/b] - [2009.06.10 23:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92) DRV:[b]64bit:[/b] - [2009.06.10 23:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac) DRV:[b]64bit:[/b] - [2009.06.10 23:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA) DRV:[b]64bit:[/b] - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2009.06.10 22:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:[b]64bit:[/b] - [2009.06.10 22:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009.04.29 08:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV:[b]64bit:[/b] - [2009.04.08 01:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap) DRV - [2012.09.06 04:54:30 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120918.001\IDSviA64.sys -- (IDSVia64) DRV - [2012.09.06 00:50:43 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120919.002\ex64.sys -- (NAVEX15) DRV - [2012.09.06 00:50:41 | 000,126,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120919.002\eng64.sys -- (NAVENG) DRV - [2012.08.01 02:34:25 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2012.08.01 02:34:21 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2009.07.23 21:45:28 | 000,146,928 | ---- | M] (CyberLink Corp.) [2010/01/23 11:25:46] [Kernel | Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49}) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_CH&c=94&bd=Pavilion&pf=cnnb IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_CH&c=94&bd=Pavilion&pf=cnnb IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {E1F5534B-D60D-457F-AB87-FE55E1AFE096} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{E1F5534B-D60D-457F-AB87-FE55E1AFE096}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1452&query={searchTerms}&invocationType=tb50hpcnnbie7-de-ch IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.maxiwe.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.maxiwe.com IE - HKLM\..\SearchScopes,DefaultScope = {E1F5534B-D60D-457F-AB87-FE55E1AFE096} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{E1F5534B-D60D-457F-AB87-FE55E1AFE096}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1452&query={searchTerms}&invocationType=tb50hpcnnbie7-de-ch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.maxiwe.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://mystart.incredibar.com/mb174?a=6R8FtPBMt5&i=26 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKCU\..\URLSearchHook: {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - No CLSID value found IE - HKCU\..\URLSearchHook: {ca4d8f4d-8eac-43a3-96d1-ee2949c907c0} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{3EB49D30-0F05-455C-AFC6-28208010B6E8}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6R8FtPBMt5&i=26 IE - HKCU\..\SearchScopes\{E1F5534B-D60D-457F-AB87-FE55E1AFE096}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1452&query={searchTerms}&invocationType=tb50hpcnnbie7-de-ch IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "MyStart Search" FF - prefs.js..browser.startup.homepage: "hxxp://mystart.incredibar.com/mb174?a=6R8FtPBMt5&i=26" FF - prefs.js..extensions.enabledAddons: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.15 FF - prefs.js..extensions.enabledAddons: {ca4d8f4d-8eac-43a3-96d1-ee2949c907c0}:3.13.0.6 FF - prefs.js..extensions.enabledAddons: firebug@software.joehewitt.com:1.9.2 FF - prefs.js..extensions.enabledAddons: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.13.0.6 FF - prefs.js..extensions.enabledAddons: {f64a409c-f9d6-4795-8889-181314c5dff1}:3.13.0.6 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.1 FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.12 FF - prefs.js..extensions.enabledItems: {f64a409c-f9d6-4795-8889-181314c5dff1}:2.5.6.0 FF - prefs.js..extensions.enabledItems: otis@digitalpersona.com:5.0.0.3790 FF - prefs.js..keyword.URL: "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FtPBMt5&&i=26&search=" FF - prefs.js..browser.search.defaultenginename: "MyStart Search" FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\10\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\jskadmin\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\jskadmin\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012.09.17 23:23:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2011.10.15 01:42:20 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.03.07 22:27:45 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\otis@digitalpersona.com: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010.05.25 22:34:09 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012.09.17 23:23:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.05.31 18:48:12 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.15 16:32:11 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\otis@digitalpersona.com: C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2010.05.25 22:34:09 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.03.07 22:27:45 | 000,000,000 | ---D | M] [2010.01.24 00:05:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Extensions [2012.09.17 23:23:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions [2012.05.31 18:49:25 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2012.05.31 18:49:32 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2012.05.31 18:49:27 | 000,000,000 | ---D | M] (Reganam-DE Community Toolbar) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\{ca4d8f4d-8eac-43a3-96d1-ee2949c907c0} [2012.05.31 18:49:35 | 000,000,000 | ---D | M] (ST Deutsch PCM Community Toolbar) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\{f64a409c-f9d6-4795-8889-181314c5dff1} [2011.01.14 22:47:11 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\engine@conduit.com [2012.09.17 23:23:40 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\jskadmin\AppData\Roaming\mozilla\Firefox\Profiles\3t7efed7.default\extensions\ffxtlbr@incredibar.com [2012.05.31 18:49:28 | 001,335,949 | ---- | M] () (No name found) -- C:\Users\jskadmin\AppData\Roaming\mozilla\firefox\profiles\3t7efed7.default\extensions\firebug@software.joehewitt.com.xpi [2012.05.30 08:27:12 | 000,000,931 | ---- | M] () -- C:\Users\jskadmin\AppData\Roaming\mozilla\firefox\profiles\3t7efed7.default\searchplugins\conduit.xml [2012.09.17 23:23:13 | 000,002,203 | ---- | M] () -- C:\Users\jskadmin\AppData\Roaming\mozilla\firefox\profiles\3t7efed7.default\searchplugins\MyStart Search.xml [2012.09.19 06:41:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2012.08.24 07:03:20 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012.09.19 06:41:50 | 000,000,000 | ---D | M] (Norton IPS) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NORTON\IPSFFPLGN [2012.04.21 03:18:00 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2012.04.21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.04.21 03:54:08 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.04.21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.04.21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.04.21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.04.21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll CHR - plugin: Injovo Extension Plugin (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.100_0\npbrowserext.dll CHR - plugin: Perion plugin (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll CHR - plugin: Skype Click to Call (Enabled) = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.2.0.10687_0\npSkypeChromePlugin.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\10\NP_wtapp.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: Web Assistant = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.100_0\ CHR - Extension: New tab for Chrome\u2122 = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\ CHR - Extension: Skype Click to Call = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.2.0.10687_0\ CHR - Extension: Reganam-DE = C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfechmceobphigkbhldpobegoajallll\2.3.4.2_0\ O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll () O2:[b]64bit:[/b] - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll () O2 - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4:[b]64bit:[/b] - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe () O4:[b]64bit:[/b] - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.) O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe File not found O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files (x86)\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe () O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.) O4:[b]64bit:[/b] - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\SysNative\WerFault.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [awchvlcmediaplayer18818] File not found O4 - HKLM..\RunOnce: [SymInstallStub] C:\Windows\SysWOW64\Adobe\Shockwave 11\SymInstallStub.exe (Symantec Corporation) O4 - HKCU..\RunOnce: [*NMRUI] C:\Users\jens\Downloads\de_cleaner.exe (Symantec Corporation) O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe (Adobe Systems Incorporated) O4 - Startup: C:\Users\jskadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2 O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:[b]64bit:[/b] - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8:[b]64bit:[/b] - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:[b]64bit:[/b] - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O9:[b]64bit:[/b] - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 10.5.1) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3681C02E-CDEA-4ECD-83FB-9EA2D3A4BFE3}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D5E39921-29C4-40CA-987F-44DC06EE29CA}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O18:[b]64bit:[/b] - Protocol\Handler\symres - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012.09.19 22:22:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012.09.19 22:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012.09.19 22:21:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012.09.19 22:21:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2012.09.19 22:21:22 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2012.09.19 21:58:28 | 000,000,000 | ---D | C] -- C:\Windows\LastGood [2012.09.19 00:03:36 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys [2012.09.17 23:31:06 | 000,000,000 | ---D | C] -- C:\Users\jskadmin\AppData\Local\NokiaAccount [2012.09.17 23:28:11 | 000,000,000 | ---D | C] -- C:\Users\jskadmin\AppData\Roaming\HPAppData [2012.09.17 23:26:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012.09.17 23:24:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN [2012.09.17 23:23:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perion [2012.09.17 23:23:26 | 000,000,000 | ---D | C] -- C:\Program Files\Web Assistant [2012.09.12 07:11:43 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys [2012.09.12 07:11:41 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll [2012.09.12 07:11:35 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys [2012.09.12 07:11:34 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [3 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ] [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012.09.19 23:04:00 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job [2012.09.19 22:46:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1001UA.job [2012.09.19 22:40:02 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1003Core.job [2012.09.19 22:40:01 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1003UA.job [2012.09.19 22:25:15 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.09.19 22:22:47 | 000,001,745 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.09.19 22:03:13 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.09.19 22:03:13 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.09.19 21:57:39 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.09.19 14:46:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1001Core.job [2012.09.19 06:41:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.09.19 06:41:14 | 3195,420,672 | -HS- | M] () -- C:\hiberfil.sys [2012.09.17 23:26:02 | 000,001,028 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012.09.17 23:23:49 | 000,000,455 | ---- | M] () -- C:\user.js [2012.09.16 11:08:19 | 001,805,210 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012.09.16 11:08:19 | 000,765,904 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012.09.16 11:08:19 | 000,720,576 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012.09.16 11:08:19 | 000,173,758 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012.09.16 11:08:19 | 000,146,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012.08.27 00:03:08 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012.08.27 00:03:08 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012.08.22 20:12:40 | 000,376,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys [2012.08.22 20:12:33 | 000,288,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2012.08.21 13:01:20 | 000,125,872 | ---- | M] (GEAR Software Inc.) -- C:\Windows\SysNative\GEARAspi64.dll [2012.08.21 13:01:20 | 000,106,928 | ---- | M] (GEAR Software Inc.) -- C:\Windows\SysWow64\GEARAspi.dll [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys [3 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ] [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012.09.19 22:35:38 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1003UA.job [2012.09.19 22:35:37 | 000,000,852 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-917402851-959443760-3657049255-1003Core.job [2012.09.19 22:22:47 | 000,001,745 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.09.17 23:26:02 | 000,001,028 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012.09.17 23:23:44 | 000,000,455 | ---- | C] () -- C:\user.js [2012.07.04 00:16:08 | 000,000,740 | ---- | C] () -- C:\Users\jskadmin\AppData\Roaming\SMRBackup162.dat [2012.02.12 00:57:14 | 000,007,663 | ---- | C] () -- C:\Users\jskadmin\AppData\Local\Resmon.ResmonCfg [2012.02.01 23:31:52 | 000,000,873 | ---- | C] () -- C:\Windows\hpomdl31.dat.temp [2011.02.22 22:25:34 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\psfind.dll [2011.01.07 22:46:08 | 000,000,096 | ---- | C] () -- C:\Users\jskadmin\.asadminpass [color=#E56717]========== ZeroAccess Check ==========[/color] [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 164 bytes -> C:\Users\Public\Documents\Ruben_Wunschzettel.jpeg:3or4kl4x13tuuug3Byamue2s4b @Alternate Data Stream - 164 bytes -> C:\Users\Public\Documents\Kira_Wunschzettel.jpeg:3or4kl4x13tuuug3Byamue2s4b < End of report > [/CODE] Jens |
20.09.2012, 08:25 | #2 |
/// Malwareteam | mystart.indredibar bei Chorme.newTabMein Name ist Marius und ich werde dir bei deinem Problem helfen. Eines vorneweg: Hinweis: Wir können hier nie dafür garantieren, dass wir sämtliche Reste von Schadsoftware gefunden haben. Eine Formatierung ist meist der schnellste und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass dein Rechner clean ist. Eine Bereinigung ist mitunter mit viel Arbeit für dich verbunden.
Vista und Win7 User Alle Tools mit Rechtsklick --> "als Administrator ausführen" starten. Wenns nur DAS ist...^^ Scan mit adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ |
20.09.2012, 20:49 | #3 |
| mystart.indredibar bei Chorme.newTab Hallo,
__________________der Scan mit dem AdwCleaner hat folgendes Ergebnis gebracht: Code:
ATTFilter # AdwCleaner v2.002 - Datei am 09/20/2012 um 21:45:51 erstellt # Aktualisiert am 16/09/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : jskadmin - HP_NOTEBOOK # Bootmodus : Normal # Ausgeführt unter : C:\Users\jens\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** Gefunden : Web Assistant Updater ***** [Dateien / Ordner] ***** Datei Gefunden : \user.js Datei Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\searchplugins\Conduit.xml Datei Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\searchplugins\MyStart Search.xml Ordner Gefunden : C:\Program Files (x86)\Conduit Ordner Gefunden : C:\Program Files\Web Assistant Ordner Gefunden : C:\ProgramData\boost_interprocess Ordner Gefunden : C:\Users\daniela\AppData\Local\Temp\boost_interprocess Ordner Gefunden : C:\Users\daniela\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\daniela\AppData\LocalLow\ConduitEngine Ordner Gefunden : C:\Users\daniela\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\jens\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\jens\AppData\LocalLow\ConduitEngine Ordner Gefunden : C:\Users\jens\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\Conduit Ordner Gefunden : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\ConduitCommon Ordner Gefunden : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\CT2849855 Ordner Gefunden : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\extensions\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4} Ordner Gefunden : C:\Users\jskadmin\AppData\Local\Conduit Ordner Gefunden : C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Ordner Gefunden : C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfechmceobphigkbhldpobegoajallll Ordner Gefunden : C:\Users\jskadmin\AppData\Local\Temp\CT2691089 Ordner Gefunden : C:\Users\jskadmin\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\jskadmin\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\Conduit Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\ConduitCommon Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\CT2269050 Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\CT2281940 Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\CT2691089 Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\CT2849855 Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\extensions\{ca4d8f4d-8eac-43a3-96d1-ee2949c907c0} Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\extensions\{f64a409c-f9d6-4795-8889-181314c5dff1} Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\extensions\engine@conduit.com Ordner Gefunden : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\extensions\ffxtlbr@incredibar.com ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gefunden : HKCU\Software\IM Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2691089 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2849855 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gefunden : HKLM\Software\Web Assistant Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nfechmceobphigkbhldpobegoajallll Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Schlüssel Gefunden : HKLM\SOFTWARE\Web Assistant Schlüssel Gefunden : HKU\S-1-5-21-917402851-959443760-3657049255-1001\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gefunden : HKU\S-1-5-21-917402851-959443760-3657049255-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb174?a=6R8FtPBMt5&i=26 -\\ Mozilla Firefox v12.0 (de) Profilname : default Datei : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\prefs.js Gefunden : user_pref("CT2269050..clientLogIsEnabled", false); Gefunden : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gefunden : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gefunden : user_pref("CT2269050.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Gefunden : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gefunden : user_pref("CT2269050.BrowserCompStateIsOpen_1000515", true); Gefunden : user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true); Gefunden : user_pref("CT2269050.CT2269050", "CT2269050"); Gefunden : user_pref("CT2269050.CurrentServerDate", "31-5-2012"); Gefunden : user_pref("CT2269050.DSInstall", true); Gefunden : user_pref("CT2269050.DialogsAlignMode", "LTR"); Gefunden : user_pref("CT2269050.DialogsGetterLastCheckTime", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2269050.DownloadReferralCookieData", ""); Gefunden : user_pref("CT2269050.EMailNotifierPollDate", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2269050.FirstServerDate", "31-5-2012"); Gefunden : user_pref("CT2269050.FirstTime", true); Gefunden : user_pref("CT2269050.FirstTimeFF3", true); Gefunden : user_pref("CT2269050.FirstTimeHiddenVer", true); Gefunden : user_pref("CT2269050.FixPageNotFoundErrors", true); Gefunden : user_pref("CT2269050.GroupingServerCheckInterval", 1440); Gefunden : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gefunden : user_pref("CT2269050.HPInstall", true); Gefunden : user_pref("CT2269050.HasUserGlobalKeys", true); Gefunden : user_pref("CT2269050.HomePageProtectorEnabled", true); Gefunden : user_pref("CT2269050.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=[...] Gefunden : user_pref("CT2269050.Initialize", true); Gefunden : user_pref("CT2269050.InitializeCommonPrefs", true); Gefunden : user_pref("CT2269050.InstallationAndCookieDataSentCount", 1); Gefunden : user_pref("CT2269050.InstallationType", "Unknown"); Gefunden : user_pref("CT2269050.InstalledDate", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2269050.InvalidateCache", false); Gefunden : user_pref("CT2269050.IsGrouping", false); Gefunden : user_pref("CT2269050.IsInitSetupIni", true); Gefunden : user_pref("CT2269050.IsMulticommunity", false); Gefunden : user_pref("CT2269050.IsOpenThankYouPage", true); Gefunden : user_pref("CT2269050.IsOpenUninstallPage", true); Gefunden : user_pref("CT2269050.IsProtectorsInit", true); Gefunden : user_pref("CT2269050.LanguagePackLastCheckTime", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440); Gefunden : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gefunden : user_pref("CT2269050.LastLogin_3.13.0.6", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2269050.LatestVersion", "3.13.0.6"); Gefunden : user_pref("CT2269050.Locale", "en"); Gefunden : user_pref("CT2269050.MCDetectTooltipHeight", "83"); Gefunden : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gefunden : user_pref("CT2269050.MCDetectTooltipWidth", "295"); Gefunden : user_pref("CT2269050.MyStuffEnabledAtInstallation", true); Gefunden : user_pref("CT2269050.OriginalFirstVersion", "3.13.0.6"); Gefunden : user_pref("CT2269050.RadioIsPodcast", false); Gefunden : user_pref("CT2269050.RadioLastCheckTime", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2269050.RadioLastUpdateIPServer", "3"); Gefunden : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000"); Gefunden : user_pref("CT2269050.RadioMediaID", "12473383"); Gefunden : user_pref("CT2269050.RadioMediaType", "Media Player"); Gefunden : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383"); Gefunden : user_pref("CT2269050.RadioShrinkedFromSetup", false); Gefunden : user_pref("CT2269050.RadioStationName", "Hotmix%20108"); Gefunden : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082"); Gefunden : user_pref("CT2269050.SavedHomepage", "hxxp://search.conduit.com/?ctid=CT2281940&SearchSource=13"); Gefunden : user_pref("CT2269050.SearchCaption", "DVDVideoSoftTB Customized Web Search"); Gefunden : user_pref("CT2269050.SearchEngineBeforeUnload", "DVDVideoSoftTB Customized Web Search"); Gefunden : user_pref("CT2269050.SearchFromAddressBarIsInit", true); Gefunden : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...] Gefunden : user_pref("CT2269050.SearchInNewTabEnabled", true); Gefunden : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440); Gefunden : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gefunden : user_pref("CT2269050.SearchProtectorEnabled", true); Gefunden : user_pref("CT2269050.SearchProtectorToolbarDisabled", false); Gefunden : user_pref("CT2269050.SendProtectorDataViaLogin", true); Gefunden : user_pref("CT2269050.ServiceMapLastCheckTime", "Thu May 31 2012 18:49:52 GMT+0200"); Gefunden : user_pref("CT2269050.SettingsLastCheckTime", "Thu May 31 2012 18:49:55 GMT+0200"); Gefunden : user_pref("CT2269050.SettingsLastUpdate", "1337169810"); Gefunden : user_pref("CT2269050.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13"); Gefunden : user_pref("CT2269050.ThirdPartyComponentsInterval", 504); Gefunden : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Thu May 31 2012 18:49:52 GMT+0200"); Gefunden : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1331805997"); Gefunden : user_pref("CT2269050.ToolbarShrinkedFromSetup", false); Gefunden : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2269050"); Gefunden : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gefunden : user_pref("CT2269050.UserID", "UN08674428420583657"); Gefunden : user_pref("CT2269050.WeatherNetwork", ""); Gefunden : user_pref("CT2269050.WeatherPollDate", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2269050.WeatherUnit", "C"); Gefunden : user_pref("CT2269050.alertChannelId", "666138"); Gefunden : user_pref("CT2269050.backendstorage.cbfirsttime", "546875204D617920333120323031322031383A35303A30342[...] Gefunden : user_pref("CT2269050.backendstorage.shoppingapp.gk.exipres", "547565204A756E20303520323031322031383A[...] Gefunden : user_pref("CT2269050.backendstorage.shoppingapp.gk.geolocation", "737769747A65726C616E64"); Gefunden : user_pref("CT2269050.components.1000515", true); Gefunden : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gefunden : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2269050.homepageProtectorEnableByLogin", true); Gefunden : user_pref("CT2269050.initDone", true); Gefunden : user_pref("CT2269050.isAppTrackingManagerOn", true); Gefunden : user_pref("CT2269050.isFirstRadioInstallation", false); Gefunden : user_pref("CT2269050.myStuffEnabled", true); Gefunden : user_pref("CT2269050.myStuffPublihserMinWidth", 400); Gefunden : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gefunden : user_pref("CT2269050.myStuffServiceIntervalMM", 1440); Gefunden : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gefunden : user_pref("CT2269050.navigateToUrlOnSearch", false); Gefunden : user_pref("CT2269050.revertSettingsEnabled", true); Gefunden : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10); Gefunden : user_pref("CT2269050.searchProtectorEnableByLogin", true); Gefunden : user_pref("CT2269050.testingCtid", ""); Gefunden : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Thu May 31 2012 18:49:59 GMT+0200"); Gefunden : user_pref("CT2281940..clientLogIsEnabled", false); Gefunden : user_pref("CT2281940..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gefunden : user_pref("CT2281940..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gefunden : user_pref("CT2281940.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Gefunden : user_pref("CT2281940.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gefunden : user_pref("CT2281940.BrowserCompStateIsOpen_129453391147632181", true); Gefunden : user_pref("CT2281940.BrowserCompStateIsOpen_129694516337434874", true); Gefunden : user_pref("CT2281940.BrowserCompStateIsOpen_129780211565817334", true); Gefunden : user_pref("CT2281940.CTID", "CT2281940"); Gefunden : user_pref("CT2281940.CurrentServerDate", "31-5-2012"); Gefunden : user_pref("CT2281940.DialogsAlignMode", "LTR"); Gefunden : user_pref("CT2281940.DialogsGetterLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2281940.DownloadReferralCookieData", ""); Gefunden : user_pref("CT2281940.EMailNotifierPollDate", "Thu May 31 2012 18:49:53 GMT+0200"); Gefunden : user_pref("CT2281940.FeedLastCount4666143058520471408", 480); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128870", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128876", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128882", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128888", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128894", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128900", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128906", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128912", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128918", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128924", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128930", "Thu May 31 2012 18:51:23 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128936", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128942", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128948", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128954", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672128960", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285216", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285222", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285228", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285234", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285240", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285246", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285252", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285258", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285264", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedPollDate129212076672285270", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.FeedTTL129212076672128882", 5); Gefunden : user_pref("CT2281940.FeedTTL129212076672128888", 5); Gefunden : user_pref("CT2281940.FeedTTL129212076672128894", 30); Gefunden : user_pref("CT2281940.FeedTTL129212076672128918", 2); Gefunden : user_pref("CT2281940.FeedTTL129212076672128942", 2); Gefunden : user_pref("CT2281940.FeedTTL129212076672128948", 5); Gefunden : user_pref("CT2281940.FeedTTL129212076672128960", 30); Gefunden : user_pref("CT2281940.FirstServerDate", "13-7-2010"); Gefunden : user_pref("CT2281940.FirstTime", true); Gefunden : user_pref("CT2281940.FirstTimeFF3", true); Gefunden : user_pref("CT2281940.GroupingServerCheckInterval", 1440); Gefunden : user_pref("CT2281940.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gefunden : user_pref("CT2281940.HPChangedManually", true); Gefunden : user_pref("CT2281940.HasUserGlobalKeys", true); Gefunden : user_pref("CT2281940.HomePageProtectorEnabled", false); Gefunden : user_pref("CT2281940.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=[...] Gefunden : user_pref("CT2281940.Initialize", true); Gefunden : user_pref("CT2281940.InitializeCommonPrefs", true); Gefunden : user_pref("CT2281940.InstallationAndCookieDataSentCount", 1); Gefunden : user_pref("CT2281940.InstallationType", "Unknown"); Gefunden : user_pref("CT2281940.InstalledDate", "Tue Jul 13 2010 20:16:38 GMT+0200"); Gefunden : user_pref("CT2281940.InvalidateCache", false); Gefunden : user_pref("CT2281940.IsAlertDBUpdated", true); Gefunden : user_pref("CT2281940.IsGrouping", false); Gefunden : user_pref("CT2281940.IsMulticommunity", false); Gefunden : user_pref("CT2281940.IsOpenThankYouPage", true); Gefunden : user_pref("CT2281940.IsOpenUninstallPage", true); Gefunden : user_pref("CT2281940.LanguagePackLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2281940.LanguagePackReloadIntervalMM", 1440); Gefunden : user_pref("CT2281940.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gefunden : user_pref("CT2281940.LastLogin_2.5.6.0", "Tue Jul 13 2010 20:16:49 GMT+0200"); Gefunden : user_pref("CT2281940.LastLogin_3.13.0.6", "Thu May 31 2012 18:49:56 GMT+0200"); Gefunden : user_pref("CT2281940.LatestVersion", "3.13.0.6"); Gefunden : user_pref("CT2281940.Locale", "de-de"); Gefunden : user_pref("CT2281940.LoginCache", 4); Gefunden : user_pref("CT2281940.MCDetectTooltipHeight", "83"); Gefunden : user_pref("CT2281940.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gefunden : user_pref("CT2281940.MCDetectTooltipWidth", "295"); Gefunden : user_pref("CT2281940.MyStuffEnabledAtInstallation", true); Gefunden : user_pref("CT2281940.RadioIsPodcast", false); Gefunden : user_pref("CT2281940.RadioLastCheckTime", "Thu May 31 2012 18:51:22 GMT+0200"); Gefunden : user_pref("CT2281940.RadioLastUpdateIPServer", "3"); Gefunden : user_pref("CT2281940.RadioLastUpdateServer", "128929877726170000"); Gefunden : user_pref("CT2281940.RadioMediaID", "11333891"); Gefunden : user_pref("CT2281940.RadioMediaType", "Media Player"); Gefunden : user_pref("CT2281940.RadioMenuSelectedID", "EBRadioMenu_CT228194011333891"); Gefunden : user_pref("CT2281940.RadioShrinkedFromSetup", false); Gefunden : user_pref("CT2281940.RadioStationName", "Antenne%20Bayern%20Top%2040"); Gefunden : user_pref("CT2281940.RadioStationURL", "hxxp://channels.webradio.antenne.de/top-40"); Gefunden : user_pref("CT2281940.SHRINK_TOOLBAR", 1); Gefunden : user_pref("CT2281940.SavedHomepage", "resource:/browserconfig.properties"); Gefunden : user_pref("CT2281940.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...] Gefunden : user_pref("CT2281940.SearchEngineBeforeUnload", "DVDVideoSoftTB Customized Web Search"); Gefunden : user_pref("CT2281940.SearchFromAddressBarIsInit", true); Gefunden : user_pref("CT2281940.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT228[...] Gefunden : user_pref("CT2281940.SearchInNewTabEnabled", true); Gefunden : user_pref("CT2281940.SearchInNewTabIntervalMM", 1440); Gefunden : user_pref("CT2281940.SearchInNewTabLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2281940.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gefunden : user_pref("CT2281940.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Gefunden : user_pref("CT2281940.SearchProtectorEnabled", false); Gefunden : user_pref("CT2281940.SearchProtectorToolbarDisabled", false); Gefunden : user_pref("CT2281940.ServiceMapLastCheckTime", "Thu May 31 2012 18:49:52 GMT+0200"); Gefunden : user_pref("CT2281940.SettingsCheckIntervalMin", 120); Gefunden : user_pref("CT2281940.SettingsLastCheckTime", "Thu May 31 2012 18:49:53 GMT+0200"); Gefunden : user_pref("CT2281940.SettingsLastUpdate", "1337169810"); Gefunden : user_pref("CT2281940.ThirdPartyComponentsInterval", 504); Gefunden : user_pref("CT2281940.ThirdPartyComponentsLastCheck", "Thu May 31 2012 18:49:52 GMT+0200"); Gefunden : user_pref("CT2281940.ThirdPartyComponentsLastUpdate", "1331806000"); Gefunden : user_pref("CT2281940.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2281940"); Gefunden : user_pref("CT2281940.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gefunden : user_pref("CT2281940.UserID", "UN66374190160716521"); Gefunden : user_pref("CT2281940.ValidationData_Toolbar", 1); Gefunden : user_pref("CT2281940.WeatherNetwork", ""); Gefunden : user_pref("CT2281940.WeatherPollDate", "Thu May 31 2012 18:51:24 GMT+0200"); Gefunden : user_pref("CT2281940.WeatherUnit", "C"); Gefunden : user_pref("CT2281940.alertChannelId", "678794"); Gefunden : user_pref("CT2281940.backendstorage.autocompletepro_enable", "31"); Gefunden : user_pref("CT2281940.backendstorage.autocompletepro_enable_auto", "31"); Gefunden : user_pref("CT2281940.clientLogIsEnabled", false); Gefunden : user_pref("CT2281940.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...] Gefunden : user_pref("CT2281940.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gefunden : user_pref("CT2281940.globalFirstTimeInfoLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2281940.homepageProtectorEnableByLogin", true); Gefunden : user_pref("CT2281940.initDone", true); Gefunden : user_pref("CT2281940.isAppTrackingManagerOn", true); Gefunden : user_pref("CT2281940.isFirstRadioInstallation", false); Gefunden : user_pref("CT2281940.myStuffEnabled", true); Gefunden : user_pref("CT2281940.myStuffPublihserMinWidth", 400); Gefunden : user_pref("CT2281940.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gefunden : user_pref("CT2281940.myStuffServiceIntervalMM", 1440); Gefunden : user_pref("CT2281940.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gefunden : user_pref("CT2281940.oldAppsList", "128325851945531999,128541998593412748,111,4005356738516295502,12[...] Gefunden : user_pref("CT2281940.revertSettingsEnabled", true); Gefunden : user_pref("CT2281940.searchProtectorDialogDelayInSec", 10); Gefunden : user_pref("CT2281940.searchProtectorEnableByLogin", true); Gefunden : user_pref("CT2281940.testingCtid", ""); Gefunden : user_pref("CT2281940.toolbarAppMetaDataLastCheckTime", "Thu May 31 2012 18:49:57 GMT+0200"); Gefunden : user_pref("CT2281940.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...] Gefunden : user_pref("CT2281940.usagesFlag", 2); Gefunden : user_pref("CT2691089..clientLogIsEnabled", false); Gefunden : user_pref("CT2691089..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gefunden : user_pref("CT2691089..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gefunden : user_pref("CT2691089.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Gefunden : user_pref("CT2691089.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gefunden : user_pref("CT2691089.BrowserCompStateIsOpen_7998054208784116753", true); Gefunden : user_pref("CT2691089.CTID", "CT2691089"); Gefunden : user_pref("CT2691089.CurrentServerDate", "31-5-2012"); Gefunden : user_pref("CT2691089.DSInstall", true); Gefunden : user_pref("CT2691089.DialogsAlignMode", "LTR"); Gefunden : user_pref("CT2691089.DialogsGetterLastCheckTime", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2691089.DownloadReferralCookieData", ""); Gefunden : user_pref("CT2691089.FirstServerDate", "1-5-2012"); Gefunden : user_pref("CT2691089.FirstTime", true); Gefunden : user_pref("CT2691089.FirstTimeFF3", true); Gefunden : user_pref("CT2691089.FirstTimeHiddenVer", true); Gefunden : user_pref("CT2691089.FixPageNotFoundErrors", true); Gefunden : user_pref("CT2691089.GroupingServerCheckInterval", 1440); Gefunden : user_pref("CT2691089.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gefunden : user_pref("CT2691089.HPInstall", false); Gefunden : user_pref("CT2691089.HasUserGlobalKeys", true); Gefunden : user_pref("CT2691089.HomePageProtectorEnabled", false); Gefunden : user_pref("CT2691089.HomepageBeforeUnload", "hxxp://www.de.maxiwe.com"); Gefunden : user_pref("CT2691089.Initialize", true); Gefunden : user_pref("CT2691089.InitializeCommonPrefs", true); Gefunden : user_pref("CT2691089.InstallationAndCookieDataSentCount", 3); Gefunden : user_pref("CT2691089.InstallationId", "ConduitStubGeneric"); Gefunden : user_pref("CT2691089.InstallationType", "ConduitIntegration"); Gefunden : user_pref("CT2691089.InstalledDate", "Tue May 01 2012 00:27:06 GMT+0200"); Gefunden : user_pref("CT2691089.InvalidateCache", false); Gefunden : user_pref("CT2691089.IsAlertDBUpdated", true); Gefunden : user_pref("CT2691089.IsGrouping", false); Gefunden : user_pref("CT2691089.IsInitSetupIni", true); Gefunden : user_pref("CT2691089.IsMulticommunity", false); Gefunden : user_pref("CT2691089.IsOpenThankYouPage", false); Gefunden : user_pref("CT2691089.IsOpenUninstallPage", true); Gefunden : user_pref("CT2691089.IsProtectorsInit", true); Gefunden : user_pref("CT2691089.LanguagePackLastCheckTime", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2691089.LanguagePackReloadIntervalMM", 1440); Gefunden : user_pref("CT2691089.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gefunden : user_pref("CT2691089.LastLogin_3.12.2.3", "Tue May 01 2012 00:27:11 GMT+0200"); Gefunden : user_pref("CT2691089.LastLogin_3.13.0.6", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2691089.LatestVersion", "3.13.0.6"); Gefunden : user_pref("CT2691089.Locale", "de"); Gefunden : user_pref("CT2691089.MCDetectTooltipHeight", "83"); Gefunden : user_pref("CT2691089.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gefunden : user_pref("CT2691089.MCDetectTooltipWidth", "295"); Gefunden : user_pref("CT2691089.MyStuffEnabledAtInstallation", true); Gefunden : user_pref("CT2691089.OriginalFirstVersion", "3.12.2.3"); Gefunden : user_pref("CT2691089.RadioIsPodcast", false); Gefunden : user_pref("CT2691089.RadioLastCheckTime", "Thu May 31 2012 18:49:50 GMT+0200"); Gefunden : user_pref("CT2691089.RadioLastUpdateIPServer", "3"); Gefunden : user_pref("CT2691089.RadioLastUpdateServer", "3"); Gefunden : user_pref("CT2691089.RadioMediaID", "9962"); Gefunden : user_pref("CT2691089.RadioMediaType", "Media Player"); Gefunden : user_pref("CT2691089.RadioMenuSelectedID", "EBRadioMenu_CT26910899962"); Gefunden : user_pref("CT2691089.RadioShrinkedFromSetup", false); Gefunden : user_pref("CT2691089.RadioStationName", "California%20Rock"); Gefunden : user_pref("CT2691089.RadioStationURL", "hxxp://feedlive.net/california.asx"); Gefunden : user_pref("CT2691089.SearchCaption", "Reganam-DE Customized Web Search"); Gefunden : user_pref("CT2691089.SearchEngineBeforeUnload", "DVDVideoSoftTB Customized Web Search"); Gefunden : user_pref("CT2691089.SearchFromAddressBarIsInit", true); Gefunden : user_pref("CT2691089.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT269[...] Gefunden : user_pref("CT2691089.SearchInNewTabEnabled", true); Gefunden : user_pref("CT2691089.SearchInNewTabIntervalMM", 1440); Gefunden : user_pref("CT2691089.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 22:59:58 GMT+0200"); Gefunden : user_pref("CT2691089.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gefunden : user_pref("CT2691089.SearchProtectorEnabled", false); Gefunden : user_pref("CT2691089.SearchProtectorToolbarDisabled", false); Gefunden : user_pref("CT2691089.SendProtectorDataViaLogin", true); Gefunden : user_pref("CT2691089.ServiceMapLastCheckTime", "Tue Jul 10 2012 22:59:58 GMT+0200"); Gefunden : user_pref("CT2691089.SettingsLastCheckTime", "Tue Jul 10 2012 22:59:58 GMT+0200"); Gefunden : user_pref("CT2691089.SettingsLastUpdate", "1337169810"); Gefunden : user_pref("CT2691089.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2691089&SearchSource=13"); Gefunden : user_pref("CT2691089.ThirdPartyComponentsInterval", 504); Gefunden : user_pref("CT2691089.ThirdPartyComponentsLastCheck", "Tue Jul 10 2012 22:59:57 GMT+0200"); Gefunden : user_pref("CT2691089.ThirdPartyComponentsLastUpdate", "1331806000"); Gefunden : user_pref("CT2691089.ToolbarShrinkedFromSetup", false); Gefunden : user_pref("CT2691089.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2691089"); Gefunden : user_pref("CT2691089.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gefunden : user_pref("CT2691089.UserID", "UN61083524721326235"); Gefunden : user_pref("CT2691089.alertChannelId", "1083484"); Gefunden : user_pref("CT2691089.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gefunden : user_pref("CT2691089.globalFirstTimeInfoLastCheckTime", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2691089.homepageProtectorEnableByLogin", true); Gefunden : user_pref("CT2691089.initDone", true); Gefunden : user_pref("CT2691089.isAppTrackingManagerOn", true); Gefunden : user_pref("CT2691089.isFirstRadioInstallation", false); Gefunden : user_pref("CT2691089.myStuffEnabled", true); Gefunden : user_pref("CT2691089.myStuffPublihserMinWidth", 400); Gefunden : user_pref("CT2691089.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gefunden : user_pref("CT2691089.myStuffServiceIntervalMM", 1440); Gefunden : user_pref("CT2691089.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gefunden : user_pref("CT2691089.navigateToUrlOnSearch", false); Gefunden : user_pref("CT2691089.oldAppsList", "129225375545950428,129225375546262932,111,129225375548137984,504[...] Gefunden : user_pref("CT2691089.revertSettingsEnabled", true); Gefunden : user_pref("CT2691089.searchProtectorDialogDelayInSec", 10); Gefunden : user_pref("CT2691089.searchProtectorEnableByLogin", true); Gefunden : user_pref("CT2691089.testingCtid", ""); Gefunden : user_pref("CT2691089.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2691089.toolbarContextMenuLastCheckTime", "Tue Jul 10 2012 22:59:59 GMT+0200"); Gefunden : user_pref("CT2849855..clientLogIsEnabled", false); Gefunden : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gefunden : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gefunden : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gefunden : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true); Gefunden : user_pref("CT2849855.CT2849855", "CT2849855"); Gefunden : user_pref("CT2849855.CurrentServerDate", "1-5-2012"); Gefunden : user_pref("CT2849855.DSInstall", true); Gefunden : user_pref("CT2849855.DialogsAlignMode", "LTR"); Gefunden : user_pref("CT2849855.DialogsGetterLastCheckTime", "Tue May 01 2012 00:27:04 GMT+0200"); Gefunden : user_pref("CT2849855.DownloadReferralCookieData", ""); Gefunden : user_pref("CT2849855.EMailNotifierPollDate", "Tue May 01 2012 00:27:00 GMT+0200"); Gefunden : user_pref("CT2849855.FeedLastCount129349796701375473", 377); Gefunden : user_pref("CT2849855.FeedPollDate129313974171006416", "Tue May 01 2012 00:27:01 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313975698350231", "Tue May 01 2012 00:27:01 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313976370850190", "Tue May 01 2012 00:27:01 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313976648818968", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313977444757117", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980389131455", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980655381977", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980886163259", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313981234756535", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313983226631720", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313983607725691", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.FeedTTL129313974171006416", 10); Gefunden : user_pref("CT2849855.FeedTTL129313977444757117", 15); Gefunden : user_pref("CT2849855.FeedTTL129313980655381977", 5); Gefunden : user_pref("CT2849855.FeedTTL129313981234756535", 5); Gefunden : user_pref("CT2849855.FirstServerDate", "23-10-2011"); Gefunden : user_pref("CT2849855.FirstTime", true); Gefunden : user_pref("CT2849855.FirstTimeFF3", true); Gefunden : user_pref("CT2849855.FixPageNotFoundErrors", false); Gefunden : user_pref("CT2849855.GroupingServerCheckInterval", 1440); Gefunden : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gefunden : user_pref("CT2849855.HPInstall", false); Gefunden : user_pref("CT2849855.HPProtectChoice", true); Gefunden : user_pref("CT2849855.HPProtectCount", 1); Gefunden : user_pref("CT2849855.HasUserGlobalKeys", true); Gefunden : user_pref("CT2849855.HomePageProtectorEnabled", false); Gefunden : user_pref("CT2849855.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT2281940&SearchSource=[...] Gefunden : user_pref("CT2849855.Initialize", true); Gefunden : user_pref("CT2849855.InitializeCommonPrefs", true); Gefunden : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3); Gefunden : user_pref("CT2849855.InstallationType", "Unknown"); Gefunden : user_pref("CT2849855.InstalledDate", "Sun Oct 23 2011 14:37:56 GMT+0200"); Gefunden : user_pref("CT2849855.IsAlertDBUpdated", true); Gefunden : user_pref("CT2849855.IsGrouping", false); Gefunden : user_pref("CT2849855.IsInitSetupIni", true); Gefunden : user_pref("CT2849855.IsMulticommunity", false); Gefunden : user_pref("CT2849855.IsOpenThankYouPage", true); Gefunden : user_pref("CT2849855.IsOpenUninstallPage", true); Gefunden : user_pref("CT2849855.IsProtectorsInit", true); Gefunden : user_pref("CT2849855.LanguagePackLastCheckTime", "Tue May 01 2012 00:27:04 GMT+0200"); Gefunden : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440); Gefunden : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gefunden : user_pref("CT2849855.LastLogin_3.7.0.6", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.LatestVersion", "3.12.2.3"); Gefunden : user_pref("CT2849855.Locale", "de"); Gefunden : user_pref("CT2849855.MCDetectTooltipHeight", "83"); Gefunden : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gefunden : user_pref("CT2849855.MCDetectTooltipWidth", "295"); Gefunden : user_pref("CT2849855.MyStuffEnabledAtInstallation", true); Gefunden : user_pref("CT2849855.OriginalFirstVersion", "3.7.0.6"); Gefunden : user_pref("CT2849855.SearchCaption", "BittorrentBar_DE Customized Web Search"); Gefunden : user_pref("CT2849855.SearchEngineBeforeUnload", "Reganam-DE Customized Web Search"); Gefunden : user_pref("CT2849855.SearchFromAddressBarIsInit", true); Gefunden : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...] Gefunden : user_pref("CT2849855.SearchInNewTabEnabled", true); Gefunden : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440); Gefunden : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Tue May 01 2012 00:27:00 GMT+0200"); Gefunden : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gefunden : user_pref("CT2849855.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Gefunden : user_pref("CT2849855.SearchProtectorEnabled", false); Gefunden : user_pref("CT2849855.SearchProtectorToolbarDisabled", false); Gefunden : user_pref("CT2849855.SendProtectorDataViaLogin", true); Gefunden : user_pref("CT2849855.ServiceMapLastCheckTime", "Tue May 01 2012 00:27:00 GMT+0200"); Gefunden : user_pref("CT2849855.SettingsLastCheckTime", "Tue May 01 2012 00:26:59 GMT+0200"); Gefunden : user_pref("CT2849855.SettingsLastUpdate", "1334673334"); Gefunden : user_pref("CT2849855.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2849855&SearchSource=13"); Gefunden : user_pref("CT2849855.ThirdPartyComponentsInterval", 504); Gefunden : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Sat Apr 21 2012 11:16:17 GMT+0200"); Gefunden : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1255344657"); Gefunden : user_pref("CT2849855.ToolbarShrinkedFromSetup", false); Gefunden : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855"); Gefunden : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gefunden : user_pref("CT2849855.UserID", "UN84448589435980311"); Gefunden : user_pref("CT2849855.WeatherNetwork", ""); Gefunden : user_pref("CT2849855.WeatherPollDate", "Tue May 01 2012 00:27:03 GMT+0200"); Gefunden : user_pref("CT2849855.WeatherUnit", "C"); Gefunden : user_pref("CT2849855.alertChannelId", "1241896"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e+x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e,x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e-x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e.x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e/x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6F72706E72727076"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473757876747878767C242F4B4947[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e0x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e1x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e2x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e3x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e4x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e5x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e6x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e7x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e8x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e9x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e:x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e;x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e<x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e=x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e>x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e?x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e@x305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7eax305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7ebx305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7ecx305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7edx305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b+7etx305", "2423"); Gefunden : user_pref("CT2849855.backendstorage./9b-0?3g>d", "396C6F71424271727A7572797320767C4C7B257B4F4F7E2A56[...] Gefunden : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", ""); Gefunden : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Gefunden : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677"); Gefunden : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...] Gefunden : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "6D6B3F3E3E7271437A43727773754748497E78204E"); Gefunden : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6E6D6B72716E7475747974"); Gefunden : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A"); Gefunden : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E"); Gefunden : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443"); Gefunden : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Gefunden : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D"); Gefunden : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Gefunden : user_pref("CT2849855.backendstorage.cb_firstuse0100", "31"); Gefunden : user_pref("CT2849855.backendstorage.cbfirsttime", "53756E204F637420323320323031312031343A33373A35382[...] Gefunden : user_pref("CT2849855.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E63682F6368726[...] Gefunden : user_pref("CT2849855.backendstorage.url_history_time", "31333139333733363632303937"); Gefunden : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gefunden : user_pref("CT2849855.globalFirstTimeInfoLastCheckTime", "Sat Apr 21 2012 11:16:21 GMT+0200"); Gefunden : user_pref("CT2849855.homepageProtectorEnableByLogin", true); Gefunden : user_pref("CT2849855.initDone", true); Gefunden : user_pref("CT2849855.isAppTrackingManagerOn", true); Gefunden : user_pref("CT2849855.myStuffEnabled", true); Gefunden : user_pref("CT2849855.myStuffPublihserMinWidth", 400); Gefunden : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gefunden : user_pref("CT2849855.myStuffServiceIntervalMM", 1440); Gefunden : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gefunden : user_pref("CT2849855.oldAppsList", "129349796699187955,129349796699500456,1000234,129791468577270025[...] Gefunden : user_pref("CT2849855.revertSettingsEnabled", true); Gefunden : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10); Gefunden : user_pref("CT2849855.searchProtectorEnableByLogin", true); Gefunden : user_pref("CT2849855.testingCtid", ""); Gefunden : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Tue May 01 2012 00:27:04 GMT+0200"); Gefunden : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Sat Apr 21 2012 11:16:21 GMT+0200"); Gefunden : user_pref("CT2849855.usagesFlag", 1); Gefunden : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2269050&Search[...] Gefunden : user_pref("CommunityToolbar.ConduitSearchList", "BittorrentBar_DE Customized Web Search,Reganam-DE C[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2281940/CT2281940[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2691089/CT2691089[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1083484/1079188/CH", "\"0\"[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1241896/1237569/CH", "\"0\"[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/CH", "\"0\"")[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/678794/674655/CH", "\"0\"")[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", [...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2281940", [...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2691089", [...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2281940",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2691089",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2849855&octid=[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"b57[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"1c8[...] Gefunden : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\jskadmin\\AppData\\Roaming\\Mozilla[...] Gefunden : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); Gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT2281940,CT2849855,CT2691089,CT2269050"); Gefunden : user_pref("CommunityToolbar.ToolbarsList2", "CT2281940,CT2849855,CT2691089,CT2269050"); Gefunden : user_pref("CommunityToolbar.ToolbarsList4", "CT2849855,CT2691089,CT2269050"); Gefunden : user_pref("CommunityToolbar.alert.alertInfoInterval", 60); Gefunden : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Tue Jul 13 2010 20:16:37 GMT+0200"); Gefunden : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Gefunden : user_pref("CommunityToolbar.alert.locale", "en"); Gefunden : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Gefunden : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Tue Jul 13 2010 20:16:35 GMT+0200"); Gefunden : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1276093853"); Gefunden : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Gefunden : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Gefunden : user_pref("CommunityToolbar.alert.showTrayIcon", false); Gefunden : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Gefunden : user_pref("CommunityToolbar.alert.userId", "{1033898d-9c54-4b93-948e-09a621221bb5}"); Gefunden : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu May 31 2012 18:49:44 GMT+0200"); Gefunden : user_pref("CommunityToolbar.globalUserId", "b29f995c-484e-46f9-9b87-187fb69d6fb7"); Gefunden : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Gefunden : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Gefunden : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2269050"); Gefunden : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu May 31 2012 18:49:5[...] Gefunden : user_pref("CommunityToolbar.notifications.alertEnabled", true); Gefunden : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60); Gefunden : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu May 31 2012 18:50:00 GMT+020[...] Gefunden : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Gefunden : user_pref("CommunityToolbar.notifications.locale", "en"); Gefunden : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Gefunden : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu May 31 2012 18:49:52 GMT+0200"); Gefunden : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Gefunden : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Gefunden : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Gefunden : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Gefunden : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Gefunden : user_pref("CommunityToolbar.notifications.userId", "98051976-8b89-4b81-bf99-48da2277dd65"); Gefunden : user_pref("CommunityToolbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT2281940&SearchSour[...] Gefunden : user_pref("CommunityToolbar.originalSearchEngine", "Softonic Deutsch PCM Customized Web Search"); Gefunden : user_pref("browser.search.defaultthis.engineName", "DVDVideoSoftTB Customized Web Search"); Gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&Sea[...] Gefunden : user_pref("browser.search.selectedEngine", "MyStart Search"); Gefunden : user_pref("browser.startup.homepage", "hxxp://mystart.incredibar.com/mb174?a=6R8FtPBMt5&i=26"); Gefunden : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FtPBMt5&&i=26&search="[...] Gefunden : user_pref("browser.search.defaultenginename", "MyStart Search"); Gefunden : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb174?a=6R8FtPBMt5&loc=FF_NT"); Profilname : default Datei : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\prefs.js Gefunden : user_pref("CT2849855..clientLogIsEnabled", false); Gefunden : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gefunden : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gefunden : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Gefunden : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gefunden : user_pref("CT2849855.AppTrackingLastCheckTime", "Mon Dec 19 2011 19:59:14 GMT+0100"); Gefunden : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true); Gefunden : user_pref("CT2849855.BrowserCompStateIsOpen_7779213456676670576", true); Gefunden : user_pref("CT2849855.CTID", "CT2849855"); Gefunden : user_pref("CT2849855.CurrentServerDate", "26-8-2012"); Gefunden : user_pref("CT2849855.DialogsAlignMode", "LTR"); Gefunden : user_pref("CT2849855.DialogsGetterLastCheckTime", "Sun Aug 26 2012 12:11:50 GMT+0200"); Gefunden : user_pref("CT2849855.DownloadReferralCookieData", ""); Gefunden : user_pref("CT2849855.EMailNotifierPollDate", "Sun Feb 05 2012 20:57:06 GMT+0100"); Gefunden : user_pref("CT2849855.FeedLastCount129349796701375473", 550); Gefunden : user_pref("CT2849855.FeedPollDate129313974171006416", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313975698350231", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313976370850190", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313976648818968", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313977444757117", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980389131455", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980655381977", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313980886163259", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313981234756535", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313983226631720", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedPollDate129313983607725691", "Sun Aug 21 2011 22:46:21 GMT+0200"); Gefunden : user_pref("CT2849855.FeedTTL129313974171006416", 10); Gefunden : user_pref("CT2849855.FeedTTL129313977444757117", 15); Gefunden : user_pref("CT2849855.FeedTTL129313980655381977", 5); Gefunden : user_pref("CT2849855.FeedTTL129313981234756535", 5); Gefunden : user_pref("CT2849855.FirstServerDate", "17-1-2011"); Gefunden : user_pref("CT2849855.FirstTime", true); Gefunden : user_pref("CT2849855.FirstTimeFF3", true); Gefunden : user_pref("CT2849855.FixPageNotFoundErrors", false); Gefunden : user_pref("CT2849855.GroupingServerCheckInterval", 1440); Gefunden : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gefunden : user_pref("CT2849855.HasUserGlobalKeys", true); Gefunden : user_pref("CT2849855.HomePageProtectorEnabled", false); Gefunden : user_pref("CT2849855.Initialize", true); Gefunden : user_pref("CT2849855.InitializeCommonPrefs", true); Gefunden : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3); Gefunden : user_pref("CT2849855.InstallationType", "UnknownIntegration"); Gefunden : user_pref("CT2849855.InstalledDate", "Sun Jan 16 2011 23:41:53 GMT+0100"); Gefunden : user_pref("CT2849855.IsAlertDBUpdated", true); Gefunden : user_pref("CT2849855.IsGrouping", false); Gefunden : user_pref("CT2849855.IsMulticommunity", false); Gefunden : user_pref("CT2849855.IsOpenThankYouPage", true); Gefunden : user_pref("CT2849855.IsOpenUninstallPage", false); Gefunden : user_pref("CT2849855.LanguagePackLastCheckTime", "Sun Aug 26 2012 12:11:50 GMT+0200"); Gefunden : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440); Gefunden : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gefunden : user_pref("CT2849855.LastLogin_3.10.0.1", "Thu Apr 26 2012 21:53:14 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.12.2.3", "Mon Apr 30 2012 23:16:55 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.13.0.6", "Sun Jul 22 2012 23:01:04 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.14.1.0", "Sun Aug 26 2012 21:05:29 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.2.5.2", "Thu Mar 24 2011 15:41:03 GMT+0100"); Gefunden : user_pref("CT2849855.LastLogin_3.3.3.2", "Tue Jun 21 2011 22:31:54 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.5.0.12", "Wed Aug 17 2011 21:05:08 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.6.0.10", "Thu Sep 22 2011 20:55:08 GMT+0200"); Gefunden : user_pref("CT2849855.LastLogin_3.7.0.6", "Wed Nov 09 2011 20:34:51 GMT+0100"); Gefunden : user_pref("CT2849855.LastLogin_3.8.0.8", "Wed Dec 07 2011 20:17:56 GMT+0100"); Gefunden : user_pref("CT2849855.LastLogin_3.8.1.0", "Sat Dec 31 2011 01:06:30 GMT+0100"); Gefunden : user_pref("CT2849855.LastLogin_3.9.0.3", "Thu Mar 08 2012 21:44:16 GMT+0100"); Gefunden : user_pref("CT2849855.LatestVersion", "3.14.1.0"); Gefunden : user_pref("CT2849855.Locale", "de"); Gefunden : user_pref("CT2849855.MCDetectTooltipHeight", "83"); Gefunden : user_pref("CT2849855.MCDetectTooltipShow", false); Gefunden : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gefunden : user_pref("CT2849855.MCDetectTooltipWidth", "295"); Gefunden : user_pref("CT2849855.MyStuffEnabledAtInstallation", true); Gefunden : user_pref("CT2849855.SHRINK_TOOLBAR", 1); Gefunden : user_pref("CT2849855.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); Gefunden : user_pref("CT2849855.SearchFromAddressBarIsInit", true); Gefunden : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...] Gefunden : user_pref("CT2849855.SearchInNewTabEnabled", true); Gefunden : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440); Gefunden : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Sun Aug 26 2012 12:11:49 GMT+0200"); Gefunden : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gefunden : user_pref("CT2849855.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Gefunden : user_pref("CT2849855.SearchProtectorEnabled", false); Gefunden : user_pref("CT2849855.SearchProtectorToolbarDisabled", false); Gefunden : user_pref("CT2849855.ServiceMapLastCheckTime", "Sun Aug 26 2012 12:11:49 GMT+0200"); Gefunden : user_pref("CT2849855.SettingsLastCheckTime", "Mon Aug 27 2012 00:03:16 GMT+0200"); Gefunden : user_pref("CT2849855.SettingsLastUpdate", "1345149440"); Gefunden : user_pref("CT2849855.ThirdPartyComponentsInterval", 504); Gefunden : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Mon Aug 13 2012 20:46:16 GMT+0200"); Gefunden : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1331806000"); Gefunden : user_pref("CT2849855.ToolbarShrinkedFromSetup", false); Gefunden : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855"); Gefunden : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gefunden : user_pref("CT2849855.UserID", "UN03826800258761642"); Gefunden : user_pref("CT2849855.ValidationData_Search", 2); Gefunden : user_pref("CT2849855.ValidationData_Toolbar", 2); Gefunden : user_pref("CT2849855.WeatherNetwork", ""); Gefunden : user_pref("CT2849855.WeatherPollDate", "Sun Feb 05 2012 20:57:07 GMT+0100"); Gefunden : user_pref("CT2849855.WeatherUnit", "C"); Gefunden : user_pref("CT2849855.alertChannelId", "1241896"); Gefunden : user_pref("CT2849855.approveUntrustedApps", false); Gefunden : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "247E70756B74757945473D3E3C3D3F3B224D4245327A342[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6F6D716C6C6D6F78"); Gefunden : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473757377727273757E242F4B4947[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e31;cj6hddl@#mm", "247E61393F236B25736F75792A212C6E414F444D[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e31;cji68>;la<>\"!(rr", "247E61393F236B2576767329202B6D404E[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] Gefunden : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] Gefunden : user_pref("CT2849855.backendstorage./9b-0?3g>d", "3B3A683C6A6B41707A42717875204B797D7E25227C507E2A24[...] Gefunden : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", ""); Gefunden : user_pref("CT2849855.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); Gefunden : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Gefunden : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677"); Gefunden : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...] Gefunden : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "3E3C6F726B7271457A70727A454878797D7B787924"); Gefunden : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6A706C6D746E7075767B"); Gefunden : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A"); Gefunden : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E"); Gefunden : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443"); Gefunden : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Gefunden : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D"); Gefunden : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Gefunden : user_pref("CT2849855.backendstorage.enableinj", ""); Gefunden : user_pref("CT2849855.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...] Gefunden : user_pref("CT2849855.backendstorage.smspunuid", "736D737031333038383139393137353333"); Gefunden : user_pref("CT2849855.backendstorage.url_history", "687474703A2F2F7777772E7061756C646972656B742E64652[...] Gefunden : user_pref("CT2849855.backendstorage.url_history_time", "31333133363038313734313036"); Gefunden : user_pref("CT2849855.components.1000034", false); Gefunden : user_pref("CT2849855.components.1000080", true); Gefunden : user_pref("CT2849855.components.1000234", false); Gefunden : user_pref("CT2849855.components.129349796699656708", false); Gefunden : user_pref("CT2849855.components.129349796699969211", false); Gefunden : user_pref("CT2849855.components.129349796701375473", false); Gefunden : user_pref("CT2849855.components.129349796701375474", false); Gefunden : user_pref("CT2849855.components.129349796701531725", false); Gefunden : user_pref("CT2849855.components.129544673678327919", false); Gefunden : user_pref("CT2849855.components.129640009348738015", false); Gefunden : user_pref("CT2849855.components.129791468577270025", false); Gefunden : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gefunden : user_pref("CT2849855.globalFirstTimeInfoLastCheckTime", "Sun Aug 26 2012 12:11:50 GMT+0200"); Gefunden : user_pref("CT2849855.homepageProtectorEnableByLogin", true); Gefunden : user_pref("CT2849855.initDone", true); Gefunden : user_pref("CT2849855.isAppTrackingManagerOn", false); Gefunden : user_pref("CT2849855.myStuffEnabled", true); Gefunden : user_pref("CT2849855.myStuffPublihserMinWidth", 400); Gefunden : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gefunden : user_pref("CT2849855.myStuffServiceIntervalMM", 1440); Gefunden : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gefunden : user_pref("CT2849855.oldAppsList", "129349796699187955,129349796699500456,1000234,129791468577270025[...] Gefunden : user_pref("CT2849855.revertSettingsEnabled", true); Gefunden : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10); Gefunden : user_pref("CT2849855.searchProtectorEnableByLogin", true); Gefunden : user_pref("CT2849855.testingCtid", ""); Gefunden : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Sun Aug 26 2012 12:11:50 GMT+0200"); Gefunden : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Mon Aug 13 2012 20:46:18 GMT+0200"); Gefunden : user_pref("CT2849855.usagesFlag", 2); Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1241896/1237569/CH", "\"0\"[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1248799/1244472/CH", "\"0\"[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CH", "\"0\"")[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/20[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2849855&octid=[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...] Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"2de[...] Gefunden : user_pref("CommunityToolbar.EngineOwner", ""); Gefunden : user_pref("CommunityToolbar.EngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}"); Gefunden : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar_de"); Gefunden : user_pref("CommunityToolbar.IsEngineShown", true); Gefunden : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Gefunden : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\jens\\AppData\\Roaming\\Mozilla\\Fi[...] Gefunden : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0"); Gefunden : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://cdn.triplegames.com/shared/apps/gamearcad[...] Gefunden : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://listen.grooveshark.com/ ", "517x130"); Gefunden : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...] Gefunden : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] Gefunden : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2849855"); Gefunden : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}"); Gefunden : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar_de"); Gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT2849855"); Gefunden : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2849855"); Gefunden : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Thu Mar 24 2011 16:00:44 GMT+01[...] Gefunden : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Gefunden : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jun 19 2011 22:08:12 GMT+0200"); Gefunden : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Gefunden : user_pref("CommunityToolbar.alert.locale", "en"); Gefunden : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Gefunden : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Tue Jun 21 2011 22:31:53 GMT+0200"); Gefunden : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Gefunden : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Gefunden : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Gefunden : user_pref("CommunityToolbar.alert.showTrayIcon", false); Gefunden : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Gefunden : user_pref("CommunityToolbar.alert.userId", "7b2a3c32-1e03-4967-9d6e-53cb895baab9"); Gefunden : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Feb 04 2012 21:44:55 GMT+0100"); Gefunden : user_pref("CommunityToolbar.globalUserId", "7a61f36c-e73b-4529-8a9e-1da9a701bf4c"); Gefunden : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Gefunden : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Gefunden : user_pref("CommunityToolbar.killedEngine", true); Gefunden : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Aug 26 2012 12:11:5[...] Gefunden : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Gefunden : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Aug 26 2012 12:11:58 GMT+020[...] Gefunden : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Gefunden : user_pref("CommunityToolbar.notifications.locale", "en"); Gefunden : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Gefunden : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Aug 26 2012 12:11:50 GMT+0200"); Gefunden : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Gefunden : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Gefunden : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Gefunden : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Gefunden : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Gefunden : user_pref("CommunityToolbar.notifications.userId", "b1d76bdf-5ebc-434f-97bf-6abb1fe84c61"); Gefunden : user_pref("CommunityToolbar.undefined", ""); Profilname : default Datei : C:\Users\daniela\AppData\Roaming\Mozilla\Firefox\Profiles\ujq88a1j.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v14.0.835.202 Datei : C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. Datei : C:\Users\jens\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [81890 octets] - [20/09/2012 21:45:51] ########## EOF - \AdwCleaner[R1].txt - [81951 octets] ########## Jens |
21.09.2012, 07:38 | #4 |
/// Malwareteam | mystart.indredibar bei Chorme.newTab Fix mit adwCleaner
Besteht das Problem immer noch?
__________________ Kein Asylrecht für Trojaner! Proud Member of UNITE Hinweis: Ich bin nur werktags erreichbar! Anfragen über PM werden ignoriert! Du bist zufrieden mit uns? Dann unterstütze das Trojaner-Board! |
21.09.2012, 20:11 | #5 |
| mystart.indredibar bei Chorme.newTab Hallo Psychotic, habe den Scan nochmals ausgeführt und dann den "Delete" ausgeführt. Es scheint alles wieder in Ordnung zu sein. Zur Sicherheit hier noch die Protokoll Datei: Code:
ATTFilter # AdwCleaner v2.002 - Datei am 09/21/2012 um 21:01:33 erstellt # Aktualisiert am 16/09/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : jskadmin - HP_NOTEBOOK # Bootmodus : Normal # Ausgeführt unter : C:\Users\jens\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 -\\ Mozilla Firefox v12.0 (de) Profilname : default Datei : C:\Users\jskadmin\AppData\Roaming\Mozilla\Firefox\Profiles\3t7efed7.default\prefs.js [OK] Die Datei ist sauber. Profilname : default Datei : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\yc2fh87x.default\prefs.js [OK] Die Datei ist sauber. Profilname : default Datei : C:\Users\daniela\AppData\Roaming\Mozilla\Firefox\Profiles\ujq88a1j.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v14.0.835.202 Datei : C:\Users\jskadmin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. Datei : C:\Users\jens\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [82797 octets] - [20/09/2012 22:00:06] AdwCleaner[S2].txt - [1454 octets] - [21/09/2012 21:01:33] AdwCleaner[R1].txt - [82003 octets] - [20/09/2012 21:45:51] AdwCleaner[R2].txt - [1686 octets] - [21/09/2012 21:01:08] ########## EOF - \AdwCleaner[S2].txt - [1635 octets] ########## Jens |
24.09.2012, 07:40 | #6 |
/// Malwareteam | mystart.indredibar bei Chorme.newTab Prima! Hier noch ein paar Tipps zur Absicherung deines Systems. Aktualität Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ --> mystart.indredibar bei Chorme.newTab |
29.09.2012, 19:40 | #7 |
/// Malwareteam | mystart.indredibar bei Chorme.newTab Schön, dass wir helfen konnten! Dieses Thema scheint erledigt und wurde aus meinen Abos gelöscht. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und ein eigenes Thema erstellen!
__________________ Kein Asylrecht für Trojaner! Proud Member of UNITE Hinweis: Ich bin nur werktags erreichbar! Anfragen über PM werden ignoriert! Du bist zufrieden mit uns? Dann unterstütze das Trojaner-Board! |
05.10.2012, 21:17 | #8 |
| mystart.indredibar bei Chorme.newTab Hallo Psychotic, vielen Dank für eure Hilfe. Alles wieder in Ordnung. Sorry für die späte Antwort, war ein paar Tage weg. Viele Grüsse und nochmals Danke jens |
Themen zu mystart.indredibar bei Chorme.newTab |
adobe, autorun, bho, bonjour, defender, explorer, firefox, format, google, helper, home, log, logfile, microsoft, mozilla, notebook, plug-in, programm, realtek, registry, scan, security, software, symantec, system, visual studio, wallpapers, wildtangent games, windows |