![]() |
Der Computer ist für die Verletzung der Gesetze der Republik Österreich blockiert worden Hallo, jetzt haben wir auch eine Blockierung des Computers und wir soll mit "Ucash" bezahlen € 100, Ich kann den Rechner nur noch im abgesicherten Modus starten. Ich habe OLT.exe auf Desktop installiert und gestartet und zwei logfiles erstellt. Nebenbei gefragt. Hat schon jemand Anzeige gegen Ukash, die Partner von Ukash und gegen die Behörden gestellt? Dankbar für jede Mitteilung. Werde jetzt die Logfiles senden und hoffe es kann uns jemand halfen. gent OTL Logfile: Code: OTL Extras logfile created on: 04.08.2012 18:25:05 - Run 1 ------------------ OTL Logfile: Code: OTL logfile created on: 04.08.2012 18:25:05 - Run 1 |
:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Ersetze die *** Sternchen wieder in den Benutzernamen zurück! Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Hallo lieber Helfer, perfekte Arbeit - hat auf Anhieb funktioniert. Familie ist Happy - Was sollen wir installieren für Prävention - oder gibt es noch nichts? gent P.S. Wir spenden gerne 50,-- Euro gespendet |
Wir sind noch nicht fertig! :) Bitte das erzeugte Log posten! Mit dem Rechner noch nicht surfen! 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
# AdwCleaner v1.800 - Logfile created 08/07/2012 at 11:36:34 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium (64 bits) # User : Alexander Bell - A_BELL # Running from : C:\Users\Alexander Bell\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Alexander Bell\AppData\Local\APN Folder Found : C:\Users\Alexander Bell\AppData\Local\Conduit Folder Found : C:\Users\Alexander Bell\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\Conduit Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\NCH_EN Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\PriceGong Folder Found : C:\Users\Alexander Bell\AppData\LocalLow\softonic-de3 Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Babylon Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Media Finder Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\Conduit Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\ConduitCommon Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\ConduitEngine Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\CT2801948 Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\extensions\{37483b40-c254-4a72-bda4-22ee90182c1e} Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\extensions\crossriderapp2258@crossrider.com Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\extensions\engine@conduit.com Folder Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\extensions\ffxtlbr@babylon.com Folder Found : C:\ProgramData\Babylon Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\BabylonToolbar Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\ConduitEngine Folder Found : C:\Program Files (x86)\I Want This Folder Found : C:\Program Files (x86)\NCH_EN Folder Found : C:\Program Files (x86)\softonic-de3 Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Found : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\searchplugins\Conduit.xml File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2801948 Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\I Want This Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\BabylonToolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Cr_Installer Key Found : HKCU\Software\MediaFinder Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Babylon Key Found : HKLM\SOFTWARE\BabylonToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL Key Found : HKLM\SOFTWARE\Classes\b Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\IEPlugin.IEWebHook Key Found : HKLM\SOFTWARE\Classes\IEPlugin.IEWebHook.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\MF Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NCH_EN Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic-de3 Toolbar Key Found : HKLM\SOFTWARE\NCH_EN Key Found : HKLM\SOFTWARE\softonic-de3 [x64] Key Found : HKCU\Software\APN [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\conduitEngine [x64] Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes [x64] Key Found : HKCU\Software\AppDataLow\Software\I Want This [x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\BabylonToolbar [x64] Key Found : HKCU\Software\Conduit [x64] Key Found : HKCU\Software\Cr_Installer [x64] Key Found : HKCU\Software\MediaFinder [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\b [x64] Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd [x64] Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore [x64] Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 [x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine [x64] Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane [x64] Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 [x64] Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 [x64] Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc [x64] Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 [x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd [x64] Key Found : HKLM\SOFTWARE\Classes\IEPlugin.IEWebHook [x64] Key Found : HKLM\SOFTWARE\Classes\IEPlugin.IEWebHook.1 [x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF [x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF [x64] Key Found : HKLM\SOFTWARE\Classes\MF [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF [x64] Key Found : HKLM\SOFTWARE\Software ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Found : HKLM\SOFTWARE\Classes\AppID\{3F39D17D-50C7-4AC4-A63A-CDF6CDBD0C61} Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Key Found : HKLM\SOFTWARE\Classes\CLSID\{125B7A09-B405-46FB-95FB-96CF6B72992D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BFC4DBF3-6B86-4ABB-8CCF-47BD70595BB2} Key Found : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Key Found : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Key Found : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758} Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Found : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\Interface\{AE9908C1-3400-4B10-9061-C6C04D96E3D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Key Found : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Key Found : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Key Found : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Key Found : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Key Found : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Found : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Key Found : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{71E3A30E-9444-49D9-ABDB-B4B531D0BBA3} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F90D07F0-4F90-49AA-BBD5-B5BECA04A4FF} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5BD68C4-1007-43EA-9B2A-684013BE9CA2} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9320C965-C965-4959-BB7B-8932C29AA607} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0792F87A-A7C9-4682-98AB-4BE731816CF9} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29E71584-08D7-4078-8C1D-E02D98557257} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{125B7A09-B405-46FB-95FB-96CF6B72992D} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BFC4DBF3-6B86-4ABB-8CCF-47BD70595BB2} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{125B7A09-B405-46FB-95FB-96CF6B72992D} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFC4DBF3-6B86-4ABB-8CCF-47BD70595BB2} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{3F39D17D-50C7-4AC4-A63A-CDF6CDBD0C61} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} [x64] Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055225558} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AE9908C1-3400-4B10-9061-C6C04D96E3D2} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{71E3A30E-9444-49D9-ABDB-B4B531D0BBA3} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{125B7A09-B405-46FB-95FB-96CF6B72992D} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFC4DBF3-6B86-4ABB-8CCF-47BD70595BB2} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Alexander Bell\AppData\Roaming\Mozilla\Firefox\Profiles\8dzoh320.default\prefs.js Found : user_pref("CT2431245..clientLogIsEnabled", false); Found : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2431245.CTID", "CT2431245"); Found : user_pref("CT2431245.CurrentServerDate", "8-3-2011"); Found : user_pref("CT2431245.DialogsAlignMode", "LTR"); Found : user_pref("CT2431245.DownloadReferralCookieData", ""); Found : user_pref("CT2431245.EMailNotifierPollDate", "Tue Mar 08 2011 09:01:50 GMT+0100"); Found : user_pref("CT2431245.FeedLastCount129009402595187825", 721); Found : user_pref("CT2431245.FeedPollDate7470634014180506963", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634014269327586", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634014329599698", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634014537505092", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634014970726540", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634015410831318", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634015483395460", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634015636754705", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634015768347545", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634015855543602", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016030710453", "Tue Mar 08 2011 08:34:36 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016114705611", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016129205152", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016143724791", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016271239162", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016568520719", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634016726993788", "Tue Mar 08 2011 08:34:36 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017109031809", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017132743740", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017299547668", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017302327846", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017344111490", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017478360748", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017732797593", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634017821686064", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedPollDate7470634018090228721", "Tue Mar 08 2011 08:34:39 GMT+0100"); Found : user_pref("CT2431245.FeedTTL7470634014269327586", 5); Found : user_pref("CT2431245.FeedTTL7470634014537505092", 5); Found : user_pref("CT2431245.FeedTTL7470634014970726540", 2); Found : user_pref("CT2431245.FeedTTL7470634015636754705", 5); Found : user_pref("CT2431245.FeedTTL7470634016568520719", 30); Found : user_pref("CT2431245.FirstServerDate", "7-3-2011"); Found : user_pref("CT2431245.FirstTime", true); Found : user_pref("CT2431245.FirstTimeFF3", true); Found : user_pref("CT2431245.FixPageNotFoundErrors", true); Found : user_pref("CT2431245.GroupingServerCheckInterval", 1440); Found : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2431245.HasUserGlobalKeys", true); Found : user_pref("CT2431245.Initialize", true); Found : user_pref("CT2431245.InitializeCommonPrefs", true); Found : user_pref("CT2431245.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2431245.InstallationId", "Unknown"); Found : user_pref("CT2431245.InstallationType", "ExternalIntegration"); Found : user_pref("CT2431245.InstalledDate", "Mon Mar 07 2011 16:21:15 GMT+0100"); Found : user_pref("CT2431245.InvalidateCache", false); Found : user_pref("CT2431245.IsGrouping", false); Found : user_pref("CT2431245.IsMulticommunity", false); Found : user_pref("CT2431245.IsOpenThankYouPage", false); Found : user_pref("CT2431245.IsOpenUninstallPage", true); Found : user_pref("CT2431245.LanguagePackLastCheckTime", "Mon Mar 07 2011 16:21:15 GMT+0100"); Found : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2431245.LastLogin_3.2.5.2", "Tue Mar 08 2011 08:34:36 GMT+0100"); Found : user_pref("CT2431245.LatestVersion", "3.2.5.2"); Found : user_pref("CT2431245.Locale", "de-de"); Found : user_pref("CT2431245.MCDetectTooltipHeight", "83"); Found : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2431245.MCDetectTooltipWidth", "295"); Found : user_pref("CT2431245.RadioIsPodcast", false); Found : user_pref("CT2431245.RadioLastCheckTime", "Mon Mar 07 2011 16:21:17 GMT+0100"); Found : user_pref("CT2431245.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000"); Found : user_pref("CT2431245.RadioMediaID", "20503672"); Found : user_pref("CT2431245.RadioMediaType", "Media Player"); Found : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672"); Found : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland"); Found : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u"); Found : user_pref("CT2431245.SavedHomepage", "hxxp://www.uschibell.at/"); Found : user_pref("CT2431245.SearchFromAddressBarIsInit", true); Found : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...] Found : user_pref("CT2431245.SearchInNewTabEnabled", true); Found : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Mon Mar 07 2011 16:21:15 GMT+0100"); Found : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT2431245.ServiceMapLastCheckTime", "Mon Mar 07 2011 16:21:13 GMT+0100"); Found : user_pref("CT2431245.SettingsLastCheckTime", "Tue Mar 08 2011 08:34:35 GMT+0100"); Found : user_pref("CT2431245.SettingsLastUpdate", "1299543701"); Found : user_pref("CT2431245.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Mon Mar 07 2011 16:21:13 GMT+0100"); Found : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1255348257"); Found : user_pref("CT2431245.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Found : user_pref("CT2431245.UserID", "UN17250414063437802"); Found : user_pref("CT2431245.WeatherNetwork", ""); Found : user_pref("CT2431245.WeatherPollDate", "Tue Mar 08 2011 08:34:38 GMT+0100"); Found : user_pref("CT2431245.WeatherUnit", "C"); Found : user_pref("CT2431245.alertChannelId", "825452"); Found : user_pref("CT2431245.backendstorage._fb_dailyactivity", "31323939353131323739333333"); Found : user_pref("CT2431245.backendstorage._fb_lifetimesent", "54525545"); Found : user_pref("CT2431245.backendstorage.facebook_ctid_connect_send", "73656E646564"); Found : user_pref("CT2431245.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Found : user_pref("CT2431245.backendstorage.li_dailyactivity", "31323939353639363738343630"); Found : user_pref("CT2431245.backendstorage.li_lifetimesent", "54525545"); Found : user_pref("CT2431245.components.1000034", false); Found : user_pref("CT2431245.components.1000234", false); Found : user_pref("CT2431245.components.129009402593156547", false); Found : user_pref("CT2431245.components.129009402595656583", false); Found : user_pref("CT2431245.components.3101995424177833784", false); Found : user_pref("CT2431245.components.5605168323123821535", false); Found : user_pref("CT2431245.myStuffEnabled", true); Found : user_pref("CT2431245.myStuffPublihserMinWidth", 400); Found : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2431245.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2431245.testingCtid", ""); Found : user_pref("CT2431245.toolbarAppMetaDataLastCheckTime", "Mon Mar 07 2011 16:21:14 GMT+0100"); Found : user_pref("CT2431245.toolbarContextMenuLastCheckTime", "Mon Mar 07 2011 16:21:15 GMT+0100"); Found : user_pref("CT2431245.usagesFlag", 2); Found : user_pref("CT2801948..clientLogIsEnabled", false); Found : user_pref("CT2801948..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2801948..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2801948.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2801948.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2801948.AppTrackingLastCheckTime", "Fri Jul 13 2012 08:11:13 GMT+0200"); Found : user_pref("CT2801948.BrowserCompStateIsOpen_129797777221477754", true); Found : user_pref("CT2801948.BrowserCompStateIsOpen_129797786124759251", true); Found : user_pref("CT2801948.BrowserCompStateIsOpen_129798077186217960", true); Found : user_pref("CT2801948.BrowserCompStateIsOpen_129799503686523541", true); Found : user_pref("CT2801948.BrowserCompStateIsOpen_129815072111847605", true); Found : user_pref("CT2801948.CTID", "CT2801948"); Found : user_pref("CT2801948.CurrentServerDate", "7-8-2012"); Found : user_pref("CT2801948.DSChangedManually", false); Found : user_pref("CT2801948.DSInstall", true); Found : user_pref("CT2801948.DSProtectChoice", true); Found : user_pref("CT2801948.DSProtectCount", 1); Found : user_pref("CT2801948.DialogsAlignMode", "LTR"); Found : user_pref("CT2801948.DialogsGetterLastCheckTime", "Mon Aug 06 2012 14:43:42 GMT+0200"); Found : user_pref("CT2801948.DownloadReferralCookieData", ""); Found : user_pref("CT2801948.EMailNotifierPollDate", "Tue Aug 07 2012 11:32:06 GMT+0200"); Found : user_pref("CT2801948.FirstServerDate", "24-12-2011"); Found : user_pref("CT2801948.FirstTime", true); Found : user_pref("CT2801948.FirstTimeFF3", true); Found : user_pref("CT2801948.FixPageNotFoundErrors", true); Found : user_pref("CT2801948.GroupingServerCheckInterval", 1440); Found : user_pref("CT2801948.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2801948.HPInstall", true); Found : user_pref("CT2801948.HPProtectChoice", true); Found : user_pref("CT2801948.HPProtectCount", 1); Found : user_pref("CT2801948.HasUserGlobalKeys", true); Found : user_pref("CT2801948.HomePageProtectorEnabled", false); Found : user_pref("CT2801948.HomepageBeforeUnload", "hxxp://search.avira.com/?l=dis&o=APN10397&gct=hp&dc=EU&[...] Found : user_pref("CT2801948.Initialize", true); Found : user_pref("CT2801948.InitializeCommonPrefs", true); Found : user_pref("CT2801948.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2801948.InstallationId", "ConduitNSISIntegration"); Found : user_pref("CT2801948.InstallationType", "ConduitXPEIntegration"); Found : user_pref("CT2801948.InstalledDate", "Sat Dec 24 2011 10:27:04 GMT+0100"); Found : user_pref("CT2801948.InvalidateCache", false); Found : user_pref("CT2801948.IsAlertDBUpdated", true); Found : user_pref("CT2801948.IsGrouping", false); Found : user_pref("CT2801948.IsInitSetupIni", true); Found : user_pref("CT2801948.IsMulticommunity", false); Found : user_pref("CT2801948.IsOpenThankYouPage", false); Found : user_pref("CT2801948.IsOpenUninstallPage", true); Found : user_pref("CT2801948.IsProtectorsInit", true); Found : user_pref("CT2801948.LanguagePackLastCheckTime", "Tue Aug 07 2012 09:14:05 GMT+0200"); Found : user_pref("CT2801948.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2801948.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2801948.LastLogin_3.10.0.1", "Wed Apr 18 2012 08:13:26 GMT+0200"); Found : user_pref("CT2801948.LastLogin_3.12.0.7", "Wed Apr 25 2012 12:40:05 GMT+0200"); Found : user_pref("CT2801948.LastLogin_3.12.2.3", "Wed May 30 2012 12:39:36 GMT+0200"); Found : user_pref("CT2801948.LastLogin_3.13.0.6", "Mon Jul 16 2012 13:26:22 GMT+0200"); Found : user_pref("CT2801948.LastLogin_3.14.1.0", "Tue Aug 07 2012 09:14:05 GMT+0200"); Found : user_pref("CT2801948.LastLogin_3.8.1.0", "Wed Jan 11 2012 12:32:49 GMT+0100"); Found : user_pref("CT2801948.LastLogin_3.9.0.3", "Wed Mar 07 2012 07:57:52 GMT+0100"); Found : user_pref("CT2801948.LatestVersion", "3.14.1.0"); Found : user_pref("CT2801948.Locale", "en-us"); Found : user_pref("CT2801948.MCDetectTooltipHeight", "83"); Found : user_pref("CT2801948.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2801948.MCDetectTooltipWidth", "295"); Found : user_pref("CT2801948.MyStuffEnabledAtInstallation", true); Found : user_pref("CT2801948.OriginalFirstVersion", "3.8.1.0"); Found : user_pref("CT2801948.RadioIsPodcast", false); Found : user_pref("CT2801948.RadioLastCheckTime", "Tue Aug 07 2012 09:14:04 GMT+0200"); Found : user_pref("CT2801948.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2801948.RadioLastUpdateServer", "129307496595170000"); Found : user_pref("CT2801948.RadioMediaID", "21435220"); Found : user_pref("CT2801948.RadioMediaType", "Media Player"); Found : user_pref("CT2801948.RadioMenuSelectedID", "EBRadioMenu_CT280194821435220"); Found : user_pref("CT2801948.RadioShrinkedFromSetup", false); Found : user_pref("CT2801948.RadioStationName", "Virgin%20Radio%20Classic%20Rock"); Found : user_pref("CT2801948.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[...] Found : user_pref("CT2801948.SHRINK_TOOLBAR", 1); Found : user_pref("CT2801948.SavedHomepage", "hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=6654c29f0000000[...] Found : user_pref("CT2801948.SearchCaption", "NCH EN Customized Web Search"); Found : user_pref("CT2801948.SearchEngineBeforeUnload", "NCH EN Customized Web Search"); Found : user_pref("CT2801948.SearchFromAddressBarIsInit", true); Found : user_pref("CT2801948.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT280[...] Found : user_pref("CT2801948.SearchInNewTabEnabled", true); Found : user_pref("CT2801948.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2801948.SearchInNewTabLastCheckTime", "Tue Aug 07 2012 09:14:04 GMT+0200"); Found : user_pref("CT2801948.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2801948.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Found : user_pref("CT2801948.SearchProtectorEnabled", true); Found : user_pref("CT2801948.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2801948.SendProtectorDataViaLogin", true); Found : user_pref("CT2801948.ServiceMapLastCheckTime", "Tue Aug 07 2012 09:14:04 GMT+0200"); Found : user_pref("CT2801948.SettingsLastCheckTime", "Tue Aug 07 2012 11:26:22 GMT+0200"); Found : user_pref("CT2801948.SettingsLastUpdate", "1343176900"); Found : user_pref("CT2801948.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2801948&SearchSource=13"); Found : user_pref("CT2801948.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2801948.ThirdPartyComponentsLastCheck", "Wed Jul 25 2012 13:52:24 GMT+0200"); Found : user_pref("CT2801948.ThirdPartyComponentsLastUpdate", "1331805997"); Found : user_pref("CT2801948.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2801948.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2801948"); Found : user_pref("CT2801948.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2801948.UserID", "UN71313007027839873"); Found : user_pref("CT2801948.ValidationData_Search", 2); Found : user_pref("CT2801948.ValidationData_Toolbar", 2); Found : user_pref("CT2801948.WeatherNetwork", ""); Found : user_pref("CT2801948.WeatherPollDate", "Tue Aug 07 2012 11:26:27 GMT+0200"); Found : user_pref("CT2801948.WeatherUnit", "C"); Found : user_pref("CT2801948.alertChannelId", "1194029"); Found : user_pref("CT2801948.autoDisableScopes", -1); Found : user_pref("CT2801948.backendstorage.amazonnew_all", "323534383737312C323630333032312C3230323436312C3[...] Found : user_pref("CT2801948.backendstorage.cbcountry_000", "4154"); Found : user_pref("CT2801948.backendstorage.cbfirsttime", "5765642041707220323520323031322031323A34303A30382[...] Found : user_pref("CT2801948.backendstorage.dealplyhardid", "363034333136393335363538313633313730"); Found : user_pref("CT2801948.backendstorage.dealplyheartbitdate", "3131325F335F3237"); Found : user_pref("CT2801948.backendstorage.dealplywasshownctsettingswidget", "31"); Found : user_pref("CT2801948.backendstorage.hxxp://pinterest_aot_im.isenabled", "59"); Found : user_pref("CT2801948.backendstorage.shoppingapp.gk.exipres", "4D6F6E2041707220333020323031322031323A[...] Found : user_pref("CT2801948.backendstorage.shoppingapp.gk.geolocation", "61757374726961"); Found : user_pref("CT2801948.backendstorage.twitter_v1.8.0_twitter_app_open_t_f", "66616C7365"); Found : user_pref("CT2801948.backendstorage.twitter_v1.9.0_twitter_app_open_t_f", "66616C7365"); Found : user_pref("CT2801948.backendstorage.url_history0001", "68747470733A2F2F706F7274616C2E73706B2D74732E6[...] Found : user_pref("CT2801948.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2801948.globalFirstTimeInfoLastCheckTime", "Wed Aug 01 2012 07:56:47 GMT+0200"); Found : user_pref("CT2801948.homepageProtectorEnableByLogin", true); Found : user_pref("CT2801948.initDone", true); Found : user_pref("CT2801948.isAppTrackingManagerOn", true); Found : user_pref("CT2801948.isFirstRadioInstallation", false); Found : user_pref("CT2801948.myStuffEnabled", true); Found : user_pref("CT2801948.myStuffPublihserMinWidth", 400); Found : user_pref("CT2801948.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2801948.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2801948.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2801948.oldAppsList", "129306881620344305,129306881621438061,111,129306881624250628,129[...] Found : user_pref("CT2801948.revertSettingsEnabled", true); Found : user_pref("CT2801948.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2801948.searchProtectorEnableByLogin", true); Found : user_pref("CT2801948.testingCtid", ""); Found : user_pref("CT2801948.toolbarAppMetaDataLastCheckTime", "Tue Aug 07 2012 09:14:05 GMT+0200"); Found : user_pref("CT2801948.toolbarContextMenuLastCheckTime", "Wed Jul 25 2012 11:00:57 GMT+0200"); Found : user_pref("CT2801948.usagesFlag", 2); Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2801948&Search[...] Found : user_pref("CommunityToolbar.ConduitSearchList", "NCH EN Customized Web Search"); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2801948/CT2801948[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1194029/1189706/AT", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/AT", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/AT", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2801948", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2801948",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/idel.gif", "[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/minimize.gif[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/play.gif", "[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/stop.gif", "[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/vol.gif", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...] Found : user_pref("CommunityToolbar.EngineOwner", "CT2431245"); Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "softonic-de3"); Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Alexander Bell\\AppData\\Roaming\\[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0"); Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2431245"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "softonic-de3"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2431245,CT2801948"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245,CT2801948"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2801948"); Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Apr 27 2011 08:42:27 GMT+0200"); Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.alert.locale", "en"); Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Apr 27 2011 08:42:27 GMT+0200"); Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927"); Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.alert.userId", "5a77ee70-d858-47e2-9250-af1cc0459a16"); Found : user_pref("CommunityToolbar.globalUserId", "4ced2ced-56ee-4e58-8b9b-42c59374f697"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2801948"); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jul 31 2012 15:15:4[...] Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Aug 07 2012 09:14:13 GMT+020[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Aug 07 2012 09:14:05 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "8768956e-4c2e-438c-911f-1fb3e28b6b87"); Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=6654c[...] Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...] Found : user_pref("ConduitEngine.FirstServerDate", "03/07/2011 18"); Found : user_pref("ConduitEngine.FirstTime", true); Found : user_pref("ConduitEngine.FirstTimeFF3", true); Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Found : user_pref("ConduitEngine.Initialize", true); Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Found : user_pref("ConduitEngine.InstalledDate", "Mon Mar 07 2011 16:21:14 GMT+0100"); Found : user_pref("ConduitEngine.IsMulticommunity", false); Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Found : user_pref("ConduitEngine.IsOpenUninstallPage", true); Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Mar 07 2011 16:21:14 GMT+0100"); Found : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("ConduitEngine.PublisherContainerWidth", 0); Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Tue Mar 08 2011 08:34:37 GMT+0100"); Found : user_pref("ConduitEngine.UserID", "UN51157367057178923"); Found : user_pref("ConduitEngine.engineLocale", "de"); Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Mar 07 2011 16:21:14 GMT+0100"); Found : user_pref("ConduitEngine.initDone", true); Found : user_pref("ConduitEngine.usagesFlag", 1); Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Found : user_pref("browser.newtab.url", "hxxp://search.babylon.com/?affID=113480&tt=010712_1&babsrc=NT_ss&mn[...] Found : user_pref("browser.search.defaultengine", "Ask.com"); Found : user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); Found : user_pref("browser.search.defaultthis.engineName", "NCH EN Customized Web Search"); Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&Sea[...] Found : user_pref("browser.search.order.1", "Search the web (Babylon)"); Found : user_pref("browser.search.selectedEngine", "NCH EN Customized Web Search"); Found : user_pref("extensions.BabylonToolbar.bbDpng", 27); Found : user_pref("extensions.BabylonToolbar.cntry", "AT"); Found : user_pref("extensions.BabylonToolbar.firstRun", false); Found : user_pref("extensions.BabylonToolbar.hdrMd5", "0FE659510CB275944ED85D7A71EA40B1"); Found : user_pref("extensions.BabylonToolbar.lastActv", "27"); Found : user_pref("extensions.BabylonToolbar.lastDP", 27); Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113480&tt=010712_1"); Found : user_pref("extensions.BabylonToolbar_i.hardId", "6654c29f000000000000000000000000"); Found : user_pref("extensions.BabylonToolbar_i.id", "6654c29f000000000000000000000000"); Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15526"); Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar_i.newTab", true); Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=113480&tt=01071[...] Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1712:41:15"); Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Found : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?cti[...] Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&q="); -\\ Google Chrome v21.0.1180.60 File : C:\Users\Alexander Bell\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "homepage": "hxxp://search.babylon.com/?affID=113480&tt=010712_1&babsrc=HP_ss&mntrId=6654c29f0[...] Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=113480&tt=010712_1&babsrc[...] Found : "icon_url": "hxxp://facemoods.com/favicon.ico", Found : "keyword": "babylontoolbar", Found : "name": "Search the web (Babylon)", Found : "search_url": "hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=6654c29f00000000[...] Found : "scriptable_host": [ "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*.childrenschorus.[...] Found : "matches": [ "*://*.google.com/*", "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*[...] Found : "update_url": "hxxp://apnmedia.ask.com/media/toolbar/supertoolbar/chrome/manifest.php[...] Found : "description": "The plug-in from the General-Crawler.com website which lets the users[...] Found : "homepage_url": "hxxp://www.general-crawler.com", Found : "name": "General Crawler", Found : "update_url": "hxxp://1.update.general-crawler.com/updates/update_chrome.xml", Found : "description": "Babylon tool translates texts from within your Google Chrome in a sin[...] Found : "128": "babylon48.png", Found : "48": "babylon48.png" Found : "name": "Babylon Translator", Found : "path": "BabylonChromePI.dll", Found : "homepage": "hxxp://search.babylon.com/?affID=113480&tt=010712_1&babsrc=HP_ss&mntrId=6654c29f0000[...] Found : "name": "Babylon Chrome Plugin", Found : "path": "C:\\Users\\Alexander Bell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Ex[...] Found : "name": "Babylon Chrome Plugin" Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=113480&tt=010712_1&babsrc=HP[...] ************************* AdwCleaner[R1].txt - [53989 octets] - [07/08/2012 11:36:34] ########## EOF - C:\AdwCleaner[R1].txt - [54118 octets] ########## Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2012.08.07.02 Windows 7 x64 FAT32 Internet Explorer 9.0.8112.16421 Alexander Bell :: A_BELL [Administrator] Schutz: Aktiviert 07.08.2012 09:37:40 mbam-log-2012-08-07 (11-18-39).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 530086 Laufzeit: 1 Stunde(n), 39 Minute(n), 53 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 35 HKCR\CLSID\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.BHO.1 (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCR\CLSID\{22222222-2222-2222-2222-220022222258} (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.Sandbox.1 (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.Sandbox (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CLSID\{33333333-3333-3333-3333-330033223358} (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.FBApi.1 (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.FBApi (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UNINSTALL.EXE (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.BHO (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.BHO.1 (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.FBApi (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.FBApi.1 (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.Sandbox (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCR\CrossriderApp0002258.Sandbox.1 (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt. HKCU\Software\Cr_Installer\2258 (Adware.GamePlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\CLSID\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKCR\Interface\{55555555-5555-5555-5555-550055225558} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (PUP.GamePlayLab) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This|Publisher (Adware.GamePlayLab) -> Daten: 215 Apps -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\Users\Alexander Bell\AppData\Local\I Want This (Adware.GamePlayLab) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\AppData\Local\I Want This\Chrome (Adware.GamePlayLab) -> Keine Aktion durchgeführt. Infizierte Dateien: 16 C:\Program Files (x86)\I Want This\I Want This.dll (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. C:\Program Files (x86)\I Want This\I Want This.exe (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. C:\Program Files (x86)\I Want This\I Want ThisGui.exe (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. C:\Program Files (x86)\I Want This\Uninstall.exe (Adware.GamePlayLabs) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\AppData\Local\Microsoft\Windows\1071\SyncCenter.exe (Trojan.Cridex) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_artweaver-free.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_audio-converter.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_cdcovercreator.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_expressit.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_gimp(2).exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_gimp.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_nvu.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_switch-audio-file-converter.exe (PUP.BundleOffer.Downloader.S) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\Downloads\SoftonicDownloader_fuer_yahoo-sitebuilder.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\Alexander Bell\AppData\Local\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Keine Aktion durchgeführt. C:\Program Files (x86)\I Want This\I Want This.dll (PUP.GamePlayLab) -> Keine Aktion durchgeführt. (Ende) |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Emsisoft Anti-Malware - Version 6.6 quarantine log Datum Ursprung Vorgang Verhalten/Infektion 08.08.2012 10:46:29 C:\Program Files (x86)\Lugert Verlag\Forte 3000\Update.exe In Quarantäne gestellt Trojan.Win32.KillDisk.dw!E1 |
Das ist nicht vollstaendig! Siehe Anleitung, wo du logfiles findest! |
Emsisoft Anti-Malware - Version 6.6 Letztes Update: 08.08.2012 08:53:01 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\, Q:\ Archiv Scan: An ADS Scan: An Scan Beginn: 08.08.2012 08:54:04 C:\Program Files (x86)\Lugert Verlag\Forte 3000\Update.exe gefunden: Trojan.Win32.KillDisk.dw!E1 Gescannt 783007 Gefunden 1 Scan Ende: 08.08.2012 10:39:08 Scan Zeit: 1:45:04 C:\Program Files (x86)\Lugert Verlag\Forte 3000\Update.exe Quarantäne Trojan.Win32.KillDisk.dw!E1 Quarantäne 1 Emsisoft Anti-Malware - Version 6.6 Letztes Update: 08.08.2012 08:53:01 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\, Q:\ Archiv Scan: An ADS Scan: An Scan Beginn: 09.08.2012 10:27:12 Gescannt 783294 Gefunden 0 Scan Ende: 09.08.2012 12:06:05 Scan Zeit: 1:38:53 Wir hoffen daß das die Datein sind - wenn nicht bitten wir um kurze Info |
Wo ist das adwLog? |
Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:17 Uhr. |
Copyright ©2000-2025, Trojaner-Board