![]() |
Attraps.Gen2 kann ich nicht entfernen Hallo zusammen, stehe vor einem Problem mit Attraps.Gen2. Dieser lässt sich nicht von AntiVir entfernen und taucht immer wieder auf. Hab schon versucht im Forum Hilfe zu finden und bin auch auf einige Themen gestossen. Es wurde aber davon abgeraten die dort geschilderten Maßnahmen am eigenen PC durchzufürhen. Ich hoffe das war so richtig. Vorweg damit ich nicht überfordert werde: ich hab nicht ziemlich viel Ahnung vom PC (bin froh wenn er läuft und ich damit arbeiten kann :singsing:) und hoffe auf verständliche Hilfe, damit ich den Plagegeist loswerde. Dafür schon mal Danke. Nun zum Problem. Seit einiger Zeit findet AntiVir Dateien die sich nicht löschen lassen: Diese sind Atraps.Gen2, attraps.Gen Wie werd ich diese Dinger los? |
:hallo: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. 2. Schritt Systemscan mit OTL (bebilderte Anleitung) |
Danke für die schnelle Antwort. Hier der logdatei von maleware: Malwarebytes Anti-Malware 1.62.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2012.08.09.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Stephan :: STEPHAN-THINK [Administrator] 09.08.2012 09:13:23 mbam-log-2012-08-09 (10-46-15).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 373060 Laufzeit: 54 Minute(n), 14 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Keine Aktion durchgeführt. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\000000cb.@ (Rootkit.0Access) -> Keine Aktion durchgeführt. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000032.@ (Rootkit.0Access) -> Keine Aktion durchgeführt. (Ende) |
OTL Logfile? |
Kommt. dauert noch etwas.... Hier der OTL logfile:OTL Logfile: Code: OTL logfile created on: 09.08.2012 12:47:00 - Run 1 |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
OTL verlangte Neustart. AV fand noch den Attrap beim Hochfahren. Beim Start erschien folgendes Protokoll: All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8DA28173-83DA-474F-B30E-7CBE2B0410DA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DA28173-83DA-474F-B30E-7CBE2B0410DA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully. C:\Program Files (x86)\softonic-de3\prxtbsof0.dll moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{28E8BEE8-9D76-44C4-80B9-78FDADF595D0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28E8BEE8-9D76-44C4-80B9-78FDADF595D0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found. File C:\Program Files (x86)\softonic-de3\prxtbsof0.dll not found. HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. HKU\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "www.google.de" removed from browser.startup.homepage Prefs.js: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:2.7.2.0 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems Prefs.js: 0 removed from network.proxy.type 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found. File C:\Program Files (x86)\softonic-de3\prxtbsof0.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found. File de3\prxtbsof0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}\ not found. File de3\prxtbsof0.dll not found. Registry value HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AcWin7Hlpr deleted successfully. C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avast5 deleted successfully. Registry value HKEY_USERS\S-1-5-21-2566526540-745546165-4001725246-1003\Software\Microsoft\Windows\CurrentVersion\Run\\JurisPortalDVD22 deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c03e4351-382a-11df-8390-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c03e4351-382a-11df-8390-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c03e4351-382a-11df-8390-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c03e4351-382a-11df-8390-806e6f6e6963}\ not found. Q:\LenovoQDrive.exe moved successfully. C:\Windows\SysWow64\ConduitEngine.tmp deleted successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\Tasks\SystemToolsDailyTest.job moved successfully. File C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000064.@ not found. File C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000032.@ not found. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000008.@ moved successfully. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\000000cb.@ moved successfully. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000000.@ moved successfully. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\L\00000004.@ moved successfully. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000004.@ moved successfully. C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\@ moved successfully. C:\Users\Stephan\AppData\Local\{0fad7129-7c25-c438-408e-33d7642b857e}\@ moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Stephan\Desktop\cmd.bat deleted successfully. C:\Users\Stephan\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Martina User: Public User: Stephan ->Temp folder emptied: 1093491 bytes ->Temporary Internet Files folder emptied: 69704643 bytes ->Java cache emptied: 357739 bytes ->FireFox cache emptied: 222227455 bytes ->Flash cache emptied: 1204 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3257170 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 283,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Martina User: Public User: Stephan ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.56.0 log created on 08092012_150415 Files\Folders moved on Reboot... C:\Users\Stephan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... File C:\Users\Stephan\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! Registry entries deleted on Reboot... |
Die Frage is WO fand er ihn, wo is das Log? Sehr gut! :daumenhoc 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Hier die log datei des erneuten scans mit maleware. Habe die beiden gefundenen Dateien gelöscht. Im laufenden Betrieb fand Antivir die Attraps.gen, konnte ich diesmal mit AV Antivir entfernen und tauchte bisher nicht wieder auf. Die Antivir logdatei habe ich unter der Maleware- datei angefügt. Adware scan folgt. Malwarebytes Anti-Malware 1.62.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2012.08.10.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Stephan :: STEPHAN-THINK [Administrator] 10.08.2012 16:03:03 mbam-log-2012-08-10 (17-28-29).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 368090 Laufzeit: 1 Stunde(n), 24 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\_OTL\MovedFiles\08092012_150415\C_Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Keine Aktion durchgeführt. C:\_OTL\MovedFiles\08092012_150415\C_Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\000000cb.@ (Rootkit.0Access) -> Keine Aktion durchgeführt. (Ende) Avira Free Antivirus Erstellungsdatum der Reportdatei: Freitag, 10. August 2012 15:55 Es wird nach 4077586 Virenstämmen gesucht. Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira AntiVir Personal - Free Antivirus Seriennummer : 0000149996-ADJIE-0000001 Plattform : Windows 7 Home Premium Windowsversion : (Service Pack 1) [6.1.7601] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : STEPHAN-THINK Versionsinformationen: BUILD.DAT : 12.0.0.1167 40870 Bytes 18.07.2012 19:07:00 AVSCAN.EXE : 12.3.0.33 468472 Bytes 08.08.2012 14:37:18 AVSCAN.DLL : 12.3.0.15 66256 Bytes 09.05.2012 14:49:38 LUKE.DLL : 12.3.0.15 68304 Bytes 09.05.2012 14:49:39 AVSCPLR.DLL : 12.3.0.14 97032 Bytes 09.05.2012 14:49:39 AVREG.DLL : 12.3.0.17 232200 Bytes 11.05.2012 14:35:30 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 18:18:34 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 09:07:39 VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 13:54:59 VBASE003.VDF : 7.11.21.238 4472832 Bytes 01.02.2012 12:11:58 VBASE004.VDF : 7.11.26.44 4329472 Bytes 28.03.2012 15:10:09 VBASE005.VDF : 7.11.34.116 4034048 Bytes 29.06.2012 13:09:26 VBASE006.VDF : 7.11.34.117 2048 Bytes 29.06.2012 13:09:26 VBASE007.VDF : 7.11.34.118 2048 Bytes 29.06.2012 13:09:27 VBASE008.VDF : 7.11.34.119 2048 Bytes 29.06.2012 13:09:27 VBASE009.VDF : 7.11.34.120 2048 Bytes 29.06.2012 13:09:27 VBASE010.VDF : 7.11.34.121 2048 Bytes 29.06.2012 13:09:27 VBASE011.VDF : 7.11.34.122 2048 Bytes 29.06.2012 13:09:28 VBASE012.VDF : 7.11.34.123 2048 Bytes 29.06.2012 13:09:29 VBASE013.VDF : 7.11.34.124 2048 Bytes 29.06.2012 13:09:29 VBASE014.VDF : 7.11.38.18 2554880 Bytes 30.07.2012 10:11:49 VBASE015.VDF : 7.11.38.70 556032 Bytes 31.07.2012 10:12:19 VBASE016.VDF : 7.11.38.143 171008 Bytes 02.08.2012 13:17:03 VBASE017.VDF : 7.11.38.221 178176 Bytes 06.08.2012 14:18:16 VBASE018.VDF : 7.11.39.37 168448 Bytes 08.08.2012 14:33:17 VBASE019.VDF : 7.11.39.38 2048 Bytes 08.08.2012 14:33:18 VBASE020.VDF : 7.11.39.39 2048 Bytes 08.08.2012 14:33:18 VBASE021.VDF : 7.11.39.40 2048 Bytes 08.08.2012 14:33:18 VBASE022.VDF : 7.11.39.41 2048 Bytes 08.08.2012 14:33:18 VBASE023.VDF : 7.11.39.42 2048 Bytes 08.08.2012 14:33:19 VBASE024.VDF : 7.11.39.43 2048 Bytes 08.08.2012 14:33:19 VBASE025.VDF : 7.11.39.44 2048 Bytes 08.08.2012 14:33:19 VBASE026.VDF : 7.11.39.45 2048 Bytes 08.08.2012 14:33:19 VBASE027.VDF : 7.11.39.46 2048 Bytes 08.08.2012 14:33:20 VBASE028.VDF : 7.11.39.47 2048 Bytes 08.08.2012 14:33:20 VBASE029.VDF : 7.11.39.48 2048 Bytes 08.08.2012 14:33:20 VBASE030.VDF : 7.11.39.49 2048 Bytes 08.08.2012 14:33:20 VBASE031.VDF : 7.11.39.60 36352 Bytes 08.08.2012 14:33:37 Engineversion : 8.2.10.130 AEVDF.DLL : 8.1.2.10 102772 Bytes 13.07.2012 13:16:02 AESCRIPT.DLL : 8.1.4.38 455033 Bytes 03.08.2012 13:19:51 AESCN.DLL : 8.1.8.2 131444 Bytes 05.03.2012 12:13:37 AESBX.DLL : 8.2.5.12 606578 Bytes 14.06.2012 15:12:21 AERDL.DLL : 8.1.9.15 639348 Bytes 08.09.2011 21:16:06 AEPACK.DLL : 8.3.0.24 811381 Bytes 07.08.2012 14:19:19 AEOFFICE.DLL : 8.1.2.42 201083 Bytes 26.07.2012 10:57:43 AEHEUR.DLL : 8.1.4.84 5112182 Bytes 03.08.2012 13:19:45 AEHELP.DLL : 8.1.23.2 258422 Bytes 13.07.2012 13:12:32 AEGEN.DLL : 8.1.5.34 434548 Bytes 26.07.2012 10:56:10 AEEXP.DLL : 8.1.0.74 86387 Bytes 03.08.2012 13:19:52 AEEMU.DLL : 8.1.3.2 393587 Bytes 13.07.2012 13:12:14 AECORE.DLL : 8.1.27.4 201078 Bytes 07.08.2012 14:18:24 AEBB.DLL : 8.1.1.0 53618 Bytes 01.09.2011 21:46:01 AVWINLL.DLL : 12.3.0.15 27344 Bytes 09.05.2012 14:49:37 AVPREF.DLL : 12.3.0.15 51920 Bytes 09.05.2012 14:49:38 AVREP.DLL : 12.3.0.15 179208 Bytes 09.05.2012 14:49:39 AVARKT.DLL : 12.3.0.15 211408 Bytes 09.05.2012 14:49:38 AVEVTLOG.DLL : 12.3.0.15 169168 Bytes 09.05.2012 14:49:38 SQLITE3.DLL : 3.7.0.1 398288 Bytes 09.05.2012 14:49:39 AVSMTP.DLL : 12.3.0.32 63480 Bytes 08.08.2012 14:37:20 NETNT.DLL : 12.3.0.15 17104 Bytes 09.05.2012 14:49:39 RCIMAGE.DLL : 12.3.0.31 4444408 Bytes 08.08.2012 14:33:08 RCTEXT.DLL : 12.3.0.31 100088 Bytes 08.08.2012 14:33:08 Konfiguration für den aktuellen Suchlauf: Job Name..............................: AVGuardAsyncScan Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_50250be1\guard_slideup.avp Protokollierung.......................: standard Primäre Aktion........................: reparieren Sekundäre Aktion......................: quarantäne Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: aus Durchsuche aktive Programme...........: ein Durchsuche Registrierung..............: aus Suche nach Rootkits...................: aus Integritätsprüfung von Systemdateien..: aus Datei Suchmodus.......................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: vollständig Beginn des Suchlaufs: Freitag, 10. August 2012 15:55 Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'mbam.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'FlashPlayerPlugin_11_3_300_270.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'FlashPlayerPlugin_11_3_300_270.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'plugin-container.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SvcGuiHlpr.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'winampa.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'UIExec.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'MCPLaunch.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'rundll32.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SSScheduler.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TeaTimer.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TpScrex.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'rfx-tray.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'phonostarTimer.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TPONSCR.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Skype.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'IAAnotif.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'tpfnf6r.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TPOSDSVC.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'tpnumlkd.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'tvt_reg_monitor_svc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SUService.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SeaPort.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'mbamservice.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'iviRegMgr.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'GoogleUpdate.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'BcmSqlStartupSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AVWEBGRD.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AcSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'IAANTMon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AssistantServices.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'rfx-server.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'MICMUTE.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'java.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wrapper.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AcPrfMgrSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'tpnumlk.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TPHKSVC.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000000.@' C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000000.@ [FUND] Ist das Trojanische Pferd TR/ATRAPS.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '55b4bb9c.qua' verschoben! Ende des Suchlaufs: Freitag, 10. August 2012 15:55 Benötigte Zeit: 00:23 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 0 Verzeichnisse wurden überprüft 45 Dateien wurden geprüft 1 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 1 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 44 Dateien ohne Befall 0 Archive wurden durchsucht 0 Warnungen 1 Hinweise Das ging aber schnell mit dem Adware. Hier die Datei # AdwCleaner v1.800 - Logfile created 08/10/2012 at 17:38:19 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Stephan - STEPHAN-THINK # Running from : C:\Users\Stephan\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Stephan\AppData\Local\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Stephan\AppData\LocalLow\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Stephan\AppData\LocalLow\softonic-de3 Folder Found : C:\Users\Stephan\AppData\Roaming\OpenCandy Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\Conduit Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\ConduitEngine Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\extensions\engine@conduit.com Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\ConduitEngine Folder Found : C:\Program Files (x86)\softonic-de3 Folder Found : C:\Program Files (x86)\Common Files\Software Update Utility Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\searchplugins\aol-web-search.xml File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\Ask.com.tmp Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\dnUpdate Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic-de3 Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Found : HKLM\SOFTWARE\softonic-de3 [x64] Key Found : HKCU\Software\APN [x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Das ging aber schnell mit dem Adware. Hier die Datei # AdwCleaner v1.800 - Logfile created 08/10/2012 at 17:38:19 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Stephan - STEPHAN-THINK # Running from : C:\Users\Stephan\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Stephan\AppData\Local\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Stephan\AppData\LocalLow\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Stephan\AppData\LocalLow\softonic-de3 Folder Found : C:\Users\Stephan\AppData\Roaming\OpenCandy Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\Conduit Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\ConduitEngine Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\extensions\engine@conduit.com Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\ConduitEngine Folder Found : C:\Program Files (x86)\softonic-de3 Folder Found : C:\Program Files (x86)\Common Files\Software Update Utility Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\searchplugins\aol-web-search.xml File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\Ask.com.tmp Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\dnUpdate Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic-de3 Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Found : HKLM\SOFTWARE\softonic-de3 [x64] Key Found : HKCU\Software\APN [x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\conduitEngine sry war nicht vollständig. Hier das gesamte logfile # AdwCleaner v1.800 - Logfile created 08/10/2012 at 17:38:19 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Stephan - STEPHAN-THINK # Running from : C:\Users\Stephan\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Stephan\AppData\Local\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Stephan\AppData\LocalLow\Conduit Folder Found : C:\Users\Stephan\AppData\LocalLow\ConduitEngine Folder Found : C:\Users\Stephan\AppData\LocalLow\softonic-de3 Folder Found : C:\Users\Stephan\AppData\Roaming\OpenCandy Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\Conduit Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\ConduitEngine Folder Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\extensions\engine@conduit.com Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\ConduitEngine Folder Found : C:\Program Files (x86)\softonic-de3 Folder Found : C:\Program Files (x86)\Common Files\Software Update Utility Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Found : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\searchplugins\aol-web-search.xml File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\conduitEngine Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\Ask.com.tmp Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\dnUpdate Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic-de3 Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Found : HKLM\SOFTWARE\softonic-de3 [x64] Key Found : HKCU\Software\APN [x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\conduitEngine [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\Ask.com [x64] Key Found : HKCU\Software\Ask.com.tmp [x64] Key Found : HKCU\Software\Conduit [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine [x64] Key Found : HKLM\SOFTWARE\Classes\dnUpdate [x64] Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser [x64] Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 [x64] Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController [x64] Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 [x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd [x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 [x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF [x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D2AD6F1A-2464-484B-A323-0ABAED1187FB} Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAE444C-01D5-49BD-ABBA-DE92372FA515} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60E7F651-E84C-4B1E-A55E-073BCAEC475F} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CC21B6B5-E56B-4987-B36D-1B29886FFC23} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D2AD6F1A-2464-484B-A323-0ABAED1187FB} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT2431245 -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\prefs.js Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2431245",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Found : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine"); Found : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com"); Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine"); Found : user_pref("CommunityToolbar.IsEngineShown", true); Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Stephan\\AppData\\Roaming\\Mozilla\[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.12.2.3"); Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] Found : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine"); Found : user_pref("CommunityToolbar.ToolbarsList2", ""); Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Jun 13 2011 17:36:41 GMT+02[...] Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Aug 01 2011 17:34:06 GMT+0200"); Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.alert.locale", "en"); Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Aug 03 2011 13:01:07 GMT+0200"); Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.alert.userId", "b5cdeb45-31ec-4808-ba64-9f1be422cf61"); Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Sep 16 2010 13:44:12 GMT+0200"); Found : user_pref("CommunityToolbar.globalUserId", "333e4a9e-cd7c-4f92-86e7-60d7a904a2e5"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu May 10 2012 15:47:4[...] Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon May 14 2012 16:03:26 GMT+020[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon May 14 2012 16:03:18 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "da6e3e3c-7caf-43db-b437-52090a20325e"); Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Mon Jul 11 2011 19:12:17 GMT+0200"); Found : user_pref("ConduitEngine.CTID", "ConduitEngine"); Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Aug 03 2011 13:01:14 GMT+0200"); Found : user_pref("ConduitEngine.FirstServerDate", "06/13/2011 18"); Found : user_pref("ConduitEngine.FirstTime", true); Found : user_pref("ConduitEngine.FirstTimeFF3", true); Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Found : user_pref("ConduitEngine.Initialize", true); Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Found : user_pref("ConduitEngine.InstalledDate", "Mon Jun 13 2011 17:36:45 GMT+0200"); Found : user_pref("ConduitEngine.IsMulticommunity", false); Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Found : user_pref("ConduitEngine.IsOpenUninstallPage", true); Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Aug 03 2011 13:01:15 GMT+0200"); Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Aug 03 2011 13:01:18 GMT+0200"); Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Aug 03 2011 13:01:14 GMT+0200"); Found : user_pref("ConduitEngine.UserID", "UN38053047963541310"); Found : user_pref("ConduitEngine.componentAlertEnabled", false); Found : user_pref("ConduitEngine.engineLocale", "de"); Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Aug 03 2011 13:01:16 GMT+0200"); Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Aug 03 2011 13:01:16 GMT+0200"); Found : user_pref("ConduitEngine.initDone", true); Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Found : user_pref("ConduitEngine.usagesFlag", 2); Found : user_pref("aol_toolbar.surf.date", "5"); Found : user_pref("aol_toolbar.surf.lastDate", "15"); Found : user_pref("aol_toolbar.surf.lastMonth", "4"); Found : user_pref("aol_toolbar.surf.lastYear", "2012"); Found : user_pref("aol_toolbar.surf.month", "5"); Found : user_pref("aol_toolbar.surf.prevMonth", "2254"); Found : user_pref("aol_toolbar.surf.total", "4667"); Found : user_pref("aol_toolbar.surf.week", "5"); Found : user_pref("aol_toolbar.surf.year", "3504"); Found : user_pref("extensions.asktb.AviraIDW-TS", "1320246902691"); Found : user_pref("extensions.asktb.AviraIDW-XML", "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<button xm[...] Found : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\"); Found : user_pref("extensions.asktb.cbid", "LL"); Found : user_pref("extensions.asktb.config-updated", true); Found : user_pref("extensions.asktb.crumb", "2011.10.04+05.42.30-toolbar003iad-DE-RHVzc2VsZG9yZixHZXJtYW55")[...] Found : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...] Found : user_pref("extensions.asktb.dtid", "YYYYYYYYDE"); Found : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); Found : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0028"); Found : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); Found : user_pref("extensions.asktb.first-restart-after-config-update", true); Found : user_pref("extensions.asktb.fresh-install", false); Found : user_pref("extensions.asktb.guid", "041004d6-4271-4793-a81c-6970428170f3"); Found : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...] Found : user_pref("extensions.asktb.if", "first"); Found : user_pref("extensions.asktb.l", "dis"); Found : user_pref("extensions.asktb.last-config-req", "1337071579667"); Found : user_pref("extensions.asktb.last-search-timestamp", "1331462031684"); Found : user_pref("extensions.asktb.last-v", "3.14.0.100010"); Found : user_pref("extensions.asktb.locale", "de_DE"); Found : user_pref("extensions.asktb.location", "Dusseldorf,Germany"); Found : user_pref("extensions.asktb.notification-shown", true); Found : user_pref("extensions.asktb.o", "APN10023"); Found : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Found : user_pref("extensions.asktb.qsrc", "2871"); Found : user_pref("extensions.asktb.r", "3"); Found : user_pref("extensions.asktb.sa", "NO"); Found : user_pref("extensions.asktb.search-history-queries", "leistungserschleichung bahn||br-online||konto"[...] Found : user_pref("extensions.asktb.search-suggestions-enabled", true); Found : user_pref("extensions.asktb.silent-upgrade", true); Found : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Found : user_pref("extensions.asktb.themeid", ""); Found : user_pref("extensions.asktb.to", ""); Found : user_pref("extensions.asktb.v", "3.14.0.100012"); ************************* AdwCleaner[R1].txt - [20622 octets] - [10/08/2012 17:38:01] AdwCleaner[R2].txt - [20630 octets] - [10/08/2012 17:38:19] ########## EOF - C:\AdwCleaner[R2].txt - [20759 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
# AdwCleaner v1.800 - Logfile created 08/11/2012 at 10:45:22 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Stephan - STEPHAN-THINK # Running from : C:\Users\Stephan\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Stephan\AppData\Local\Conduit Folder Deleted : C:\Users\Stephan\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Stephan\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Stephan\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Stephan\AppData\LocalLow\softonic-de3 Folder Deleted : C:\Users\Stephan\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\Conduit Folder Deleted : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\ConduitEngine Folder Deleted : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\extensions\engine@conduit.com Folder Deleted : C:\Program Files (x86)\Ask.com Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\ConduitEngine Folder Deleted : C:\Program Files (x86)\softonic-de3 Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} File Deleted : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\searchplugins\aol-web-search.xml File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\Ask.com.tmp Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\APN Key Deleted : HKLM\SOFTWARE\AskToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic-de3 Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\softonic-de3 [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2AD6F1A-2464-484B-A323-0ABAED1187FB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAE444C-01D5-49BD-ABBA-DE92372FA515} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60E7F651-E84C-4B1E-A55E-073BCAEC475F} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CC21B6B5-E56B-4987-B36D-1B29886FFC23} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D2AD6F1A-2464-484B-A323-0ABAED1187FB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT2431245 --> hxxp://www.google.com -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\prefs.js C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\9ein93uj.default\user.js ... Deleted ! Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2431245",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine"); Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com"); Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine"); Deleted : user_pref("CommunityToolbar.IsEngineShown", true); Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Stephan\\AppData\\Roaming\\Mozilla\[...] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.12.2.3"); Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine"); Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", ""); Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Jun 13 2011 17:36:41 GMT+02[...] Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Aug 01 2011 17:34:06 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.locale", "en"); Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Aug 03 2011 13:01:07 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.alert.userId", "b5cdeb45-31ec-4808-ba64-9f1be422cf61"); Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Sep 16 2010 13:44:12 GMT+0200"); Deleted : user_pref("CommunityToolbar.globalUserId", "333e4a9e-cd7c-4f92-86e7-60d7a904a2e5"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu May 10 2012 15:47:4[...] Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon May 14 2012 16:03:26 GMT+020[...] Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon May 14 2012 16:03:18 GMT+0200"); Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "da6e3e3c-7caf-43db-b437-52090a20325e"); Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Mon Jul 11 2011 19:12:17 GMT+0200"); Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine"); Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Aug 03 2011 13:01:14 GMT+0200"); Deleted : user_pref("ConduitEngine.FirstServerDate", "06/13/2011 18"); Deleted : user_pref("ConduitEngine.FirstTime", true); Deleted : user_pref("ConduitEngine.FirstTimeFF3", true); Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true); Deleted : user_pref("ConduitEngine.Initialize", true); Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true); Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Jun 13 2011 17:36:45 GMT+0200"); Deleted : user_pref("ConduitEngine.IsMulticommunity", false); Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false); Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true); Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Aug 03 2011 13:01:15 GMT+0200"); Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Aug 03 2011 13:01:18 GMT+0200"); Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Aug 03 2011 13:01:14 GMT+0200"); Deleted : user_pref("ConduitEngine.UserID", "UN38053047963541310"); Deleted : user_pref("ConduitEngine.componentAlertEnabled", false); Deleted : user_pref("ConduitEngine.engineLocale", "de"); Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Aug 03 2011 13:01:16 GMT+0200"); Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Aug 03 2011 13:01:16 GMT+0200"); Deleted : user_pref("ConduitEngine.initDone", true); Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Deleted : user_pref("ConduitEngine.usagesFlag", 2); Deleted : user_pref("aol_toolbar.surf.date", "5"); Deleted : user_pref("aol_toolbar.surf.lastDate", "15"); Deleted : user_pref("aol_toolbar.surf.lastMonth", "4"); Deleted : user_pref("aol_toolbar.surf.lastYear", "2012"); Deleted : user_pref("aol_toolbar.surf.month", "5"); Deleted : user_pref("aol_toolbar.surf.prevMonth", "2254"); Deleted : user_pref("aol_toolbar.surf.total", "4667"); Deleted : user_pref("aol_toolbar.surf.week", "5"); Deleted : user_pref("aol_toolbar.surf.year", "3504"); Deleted : user_pref("extensions.asktb.AviraIDW-TS", "1320246902691"); Deleted : user_pref("extensions.asktb.AviraIDW-XML", "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<button xm[...] Deleted : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\"); Deleted : user_pref("extensions.asktb.cbid", "LL"); Deleted : user_pref("extensions.asktb.config-updated", true); Deleted : user_pref("extensions.asktb.crumb", "2011.10.04+05.42.30-toolbar003iad-DE-RHVzc2VsZG9yZixHZXJtYW55")[...] Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...] Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYDE"); Deleted : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); Deleted : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0028"); Deleted : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); Deleted : user_pref("extensions.asktb.first-restart-after-config-update", true); Deleted : user_pref("extensions.asktb.fresh-install", false); Deleted : user_pref("extensions.asktb.guid", "041004d6-4271-4793-a81c-6970428170f3"); Deleted : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...] Deleted : user_pref("extensions.asktb.if", "first"); Deleted : user_pref("extensions.asktb.l", "dis"); Deleted : user_pref("extensions.asktb.last-config-req", "1337071579667"); Deleted : user_pref("extensions.asktb.last-search-timestamp", "1331462031684"); Deleted : user_pref("extensions.asktb.last-v", "3.14.0.100010"); Deleted : user_pref("extensions.asktb.locale", "de_DE"); Deleted : user_pref("extensions.asktb.location", "Dusseldorf,Germany"); Deleted : user_pref("extensions.asktb.notification-shown", true); Deleted : user_pref("extensions.asktb.o", "APN10023"); Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Deleted : user_pref("extensions.asktb.qsrc", "2871"); Deleted : user_pref("extensions.asktb.r", "3"); Deleted : user_pref("extensions.asktb.sa", "NO"); Deleted : user_pref("extensions.asktb.search-history-queries", "leistungserschleichung bahn||br-online||konto"[...] Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true); Deleted : user_pref("extensions.asktb.silent-upgrade", true); Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Deleted : user_pref("extensions.asktb.themeid", ""); Deleted : user_pref("extensions.asktb.to", ""); Deleted : user_pref("extensions.asktb.v", "3.14.0.100012"); ************************* AdwCleaner[R1].txt - [20622 octets] - [10/08/2012 17:38:01] AdwCleaner[R2].txt - [20683 octets] - [10/08/2012 17:38:19] AdwCleaner[R3].txt - [20744 octets] - [11/08/2012 10:45:05] AdwCleaner[S1].txt - [18614 octets] - [11/08/2012 10:45:22] ########## EOF - C:\AdwCleaner[S1].txt - [18743 octets] ########## Emsisoft Anti-Malware - Version 6.6 Letztes Update: 11.08.2012 11:54:53 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, Q:\ Archiv Scan: An ADS Scan: An Scan Beginn: 11.08.2012 11:55:15 Key: hkey_current_user\software\toolbar gefunden: Trace.Registry.websearchtoolbar!E1 Key: hkey_local_machine\software\toolbar gefunden: Trace.Registry.websearchtoolbar!E1 C:\_OTL\MovedFiles\08092012_150415\C_Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\80000000.@ gefunden: Backdoor.Win64.AMN!E1 C:\_OTL\MovedFiles\08092012_150415\C_Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000004.@ gefunden: Trojan.Win64!E2 C:\Windows\Installer\{0fad7129-7c25-c438-408e-33d7642b857e}\U\00000004.@ gefunden: Trojan.Win64!E2 C:\Windows\assembly\GAC_64\Desktop.ini gefunden: Trojan.Win64!E2 C:\Windows\assembly\GAC_32\Desktop.ini gefunden: Trojan.Win32.Sirefef!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 10.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\7\66\551C4d01 gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 10.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\7\66\551C4d01 -> unnamed gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 10.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\7\F6\FB6BAd01 -> unnamed gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 10.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\7\F6\FB6BAd01 gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 2.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\0\CB\1232Cd01 -> unnamed gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 2.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\0\CB\1232Cd01 gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 9.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\6\7A\A9926d01 gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 8.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\6\1E\3705Ad01 -> unnamed gefunden: AdWare.JS.Pornpop!E2 Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 8.zip -> C\Users\Stephan\AppData\Local\Mozilla\Firefox\Profiles\9ein93uj.default\Cache\6\1E\3705Ad01 gefunden: AdWare.JS.Pornpop!E2 Gescannt 618615 Gefunden 16 Scan Ende: 11.08.2012 13:27:31 Scan Zeit: 1:32:16 |
Bite ein Scan mit: http://www.trojaner-board.de/114276-...s-remover.html |
C:\Windows\system32\ntoskrnl.exe OK C:\Windows\system32\hal.dll OK C:\Windows\system32\kdcom.dll OK C:\Windows\system32\mcupdate_GenuineIntel.dll OK C:\Windows\system32\PSHED.dll OK C:\Windows\system32\CLFS.SYS OK C:\Windows\system32\CI.dll OK C:\Windows\system32\drivers\Wdf01000.sys OK C:\Windows\system32\drivers\WDFLDR.SYS OK C:\Windows\system32\drivers\ACPI.sys OK C:\Windows\system32\drivers\WMILIB.SYS OK C:\Windows\system32\drivers\msisadrv.sys OK C:\Windows\system32\drivers\pci.sys OK C:\Windows\system32\drivers\vdrvroot.sys OK C:\Windows\System32\drivers\partmgr.sys OK C:\Windows\system32\DRIVERS\compbatt.sys OK C:\Windows\system32\DRIVERS\BATTC.SYS OK C:\Windows\system32\drivers\volmgr.sys OK C:\Windows\System32\drivers\volmgrx.sys OK C:\Windows\System32\drivers\mountmgr.sys OK C:\Windows\system32\DRIVERS\iaStor.sys OK C:\Windows\system32\drivers\atapi.sys OK C:\Windows\system32\drivers\ataport.SYS OK C:\Windows\system32\drivers\msahci.sys OK C:\Windows\system32\drivers\PCIIDEX.SYS OK C:\Windows\system32\drivers\amdxata.sys OK C:\Windows\system32\drivers\fltmgr.sys OK C:\Windows\system32\drivers\fileinfo.sys OK C:\Windows\System32\Drivers\PxHlpa64.sys OK C:\Windows\System32\Drivers\Ntfs.sys OK C:\Windows\System32\Drivers\msrpc.sys OK C:\Windows\System32\Drivers\ksecdd.sys OK C:\Windows\System32\Drivers\cng.sys OK C:\Windows\System32\drivers\pcw.sys OK C:\Windows\System32\Drivers\Fs_Rec.sys OK C:\Windows\system32\drivers\ndis.sys OK C:\Windows\system32\drivers\NETIO.SYS OK C:\Windows\System32\Drivers\ksecpkg.sys OK C:\Windows\System32\drivers\tcpip.sys OK C:\Windows\System32\drivers\fwpkclnt.sys OK C:\Windows\system32\drivers\volsnap.sys OK C:\Windows\System32\DRIVERS\ApsHM64.sys OK C:\Windows\System32\Drivers\spldr.sys OK C:\Windows\System32\drivers\rdyboost.sys OK C:\Windows\System32\DRIVERS\Apsx64.sys OK C:\Windows\System32\Drivers\mup.sys OK C:\Windows\System32\drivers\hwpolicy.sys OK C:\Windows\System32\DRIVERS\fvevol.sys OK C:\Windows\system32\DRIVERS\disk.sys OK C:\Windows\system32\DRIVERS\CLASSPNP.SYS OK C:\Windows\system32\drivers\cdrom.sys OK C:\Windows\System32\Drivers\Null.SYS OK C:\Windows\System32\Drivers\Beep.SYS OK C:\Windows\System32\drivers\vga.sys OK C:\Windows\System32\drivers\VIDEOPRT.SYS OK C:\Windows\System32\drivers\watchdog.sys OK C:\Windows\System32\DRIVERS\RDPCDD.sys OK C:\Windows\system32\drivers\rdpencdd.sys OK C:\Windows\system32\drivers\rdprefmp.sys OK C:\Windows\System32\Drivers\Msfs.SYS OK C:\Windows\System32\Drivers\Npfs.SYS OK C:\Windows\system32\DRIVERS\tdx.sys OK C:\Windows\system32\DRIVERS\TDI.SYS OK C:\Windows\system32\drivers\afd.sys OK C:\Windows\System32\DRIVERS\netbt.sys OK C:\Windows\system32\drivers\ws2ifsl.sys OK C:\Windows\system32\DRIVERS\wfplwf.sys OK C:\Windows\system32\DRIVERS\pacer.sys OK C:\Windows\system32\DRIVERS\vwififlt.sys OK C:\Windows\system32\DRIVERS\netbios.sys OK C:\Windows\system32\DRIVERS\wanarp.sys OK C:\Windows\System32\drivers\Tppwr64v.sys OK C:\Windows\system32\drivers\termdd.sys OK C:\Windows\system32\DRIVERS\rdbss.sys OK C:\Windows\system32\drivers\nsiproxy.sys OK C:\Windows\system32\drivers\mssmbios.sys OK C:\Windows\system32\DRIVERS\smiifx64.sys OK C:\Windows\System32\drivers\discache.sys OK C:\Windows\System32\Drivers\dfsc.sys OK C:\Windows\system32\DRIVERS\blbdrive.sys OK C:\Windows\system32\DRIVERS\avkmgr.sys OK C:\Windows\system32\DRIVERS\avipbb.sys OK C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys OK C:\Windows\system32\DRIVERS\tunnel.sys OK C:\Windows\system32\DRIVERS\igdkmd64.sys OK C:\Windows\System32\drivers\dxgkrnl.sys OK C:\Windows\System32\drivers\dxgmms1.sys OK C:\Windows\system32\DRIVERS\usbuhci.sys OK C:\Windows\system32\DRIVERS\USBPORT.SYS OK C:\Windows\system32\DRIVERS\usbehci.sys OK C:\Windows\system32\drivers\HDAudBus.sys OK C:\Windows\system32\DRIVERS\jmcr.sys OK C:\Windows\system32\DRIVERS\SCSIPORT.SYS OK C:\Windows\system32\DRIVERS\NETw5s64.sys OK C:\Windows\system32\DRIVERS\vwifibus.sys OK C:\Windows\system32\DRIVERS\Rt64win7.sys OK C:\Windows\system32\drivers\i8042prt.sys OK C:\Windows\system32\drivers\kbdclass.sys OK C:\Windows\system32\DRIVERS\SynTP.sys OK C:\Windows\system32\DRIVERS\USBD.SYS OK C:\Windows\system32\DRIVERS\mouclass.sys OK C:\Windows\system32\DRIVERS\ibmpmdrv.sys OK C:\Windows\system32\DRIVERS\intelppm.sys OK C:\Windows\system32\DRIVERS\CmBatt.sys OK C:\Windows\system32\drivers\wmiacpi.sys OK C:\Windows\system32\drivers\CompositeBus.sys OK C:\Windows\system32\DRIVERS\AgileVpn.sys OK C:\Windows\system32\DRIVERS\rasl2tp.sys OK C:\Windows\system32\DRIVERS\ndistapi.sys OK C:\Windows\system32\DRIVERS\ndiswan.sys OK C:\Windows\system32\DRIVERS\raspppoe.sys OK C:\Windows\system32\DRIVERS\raspptp.sys OK C:\Windows\system32\DRIVERS\rassstp.sys OK C:\Windows\system32\DRIVERS\psadd.sys OK C:\Windows\system32\drivers\swenum.sys OK C:\Windows\system32\drivers\ks.sys OK C:\Windows\system32\drivers\umbus.sys OK C:\Windows\system32\DRIVERS\usbhub.sys OK C:\Windows\System32\Drivers\NDProxy.SYS OK C:\Windows\system32\drivers\RTKVHD64.sys OK C:\Windows\system32\drivers\portcls.sys OK C:\Windows\system32\drivers\drmk.sys OK C:\Windows\system32\drivers\ksthunk.sys OK C:\Windows\system32\drivers\IntcHdmi.sys OK C:\Windows\System32\win32k.sys OK C:\Windows\System32\drivers\Dxapi.sys OK C:\Windows\system32\DRIVERS\hidusb.sys OK C:\Windows\system32\DRIVERS\HIDCLASS.SYS OK C:\Windows\system32\DRIVERS\HIDPARSE.SYS OK C:\Windows\system32\DRIVERS\mouhid.sys OK C:\Windows\system32\DRIVERS\usbccgp.sys OK C:\Windows\System32\Drivers\usbvideo.sys OK C:\Windows\system32\DRIVERS\monitor.sys OK C:\Windows\System32\TSDDD.dll OK C:\Windows\System32\cdd.dll OK C:\Windows\system32\DRIVERS\cdfs.sys OK C:\Windows\System32\Drivers\crashdmp.sys OK C:\Windows\System32\Drivers\dump_iaStor.sys Not Found C:\Windows\System32\Drivers\dump_dumpfve.sys Not Found C:\Windows\system32\drivers\luafv.sys OK C:\Windows\system32\DRIVERS\avgntflt.sys OK C:\Windows\system32\drivers\WudfPf.sys OK C:\Windows\system32\DRIVERS\lltdio.sys OK C:\Windows\system32\DRIVERS\nwifi.sys OK C:\Windows\system32\DRIVERS\ndisuio.sys OK C:\Windows\system32\DRIVERS\rspndr.sys OK C:\Windows\system32\drivers\HTTP.sys OK C:\Windows\System32\DRIVERS\srvnet.sys OK C:\Windows\system32\DRIVERS\bowser.sys OK C:\Windows\system32\DRIVERS\mrxsmb.sys OK C:\Windows\system32\DRIVERS\mrxsmb10.sys OK C:\Windows\system32\DRIVERS\mrxsmb20.sys OK C:\Windows\System32\DRIVERS\srv2.sys OK C:\Windows\System32\DRIVERS\srv.sys OK C:\Windows\system32\DRIVERS\vwifimp.sys OK C:\Windows\system32\drivers\peauth.sys OK C:\Windows\System32\Drivers\secdrv.SYS OK C:\Windows\System32\drivers\tcpipreg.sys OK C:\Windows\system32\drivers\mbam.sys OK C:\Windows\system32\DRIVERS\USBSTOR.SYS OK C:\Windows\System32\Drivers\fastfat.SYS OK C:\Windows\system32\DRIVERS\WUDFRd.sys OK C:\Windows\system32\drivers\rm.sys Not Found C:\Windows\System32\ntdll.dll OK C:\Windows\System32\smss.exe OK C:\Windows\System32\apisetschema.dll OK C:\Windows\System32\autochk.exe OK C:\Windows\System32\msvcrt.dll OK C:\Windows\System32\comdlg32.dll OK C:\Windows\System32\setupapi.dll OK C:\Windows\System32\ws2_32.dll OK C:\Windows\System32\psapi.dll OK C:\Windows\System32\user32.dll OK C:\Windows\System32\wininet.dll OK C:\Windows\System32\urlmon.dll OK C:\Windows\System32\shlwapi.dll OK C:\Windows\System32\oleaut32.dll OK C:\Windows\System32\gdi32.dll OK C:\Windows\System32\clbcatq.dll OK C:\Windows\System32\msctf.dll OK C:\Windows\System32\normaliz.dll OK C:\Windows\System32\sechost.dll OK C:\Windows\System32\nsi.dll OK C:\Windows\System32\advapi32.dll OK C:\Windows\System32\lpk.dll OK C:\Windows\System32\imm32.dll OK C:\Windows\System32\iertutil.dll OK C:\Windows\System32\difxapi.dll OK C:\Windows\System32\rpcrt4.dll OK C:\Windows\System32\shell32.dll OK C:\Windows\System32\Wldap32.dll OK C:\Windows\System32\usp10.dll OK C:\Windows\System32\kernel32.dll OK C:\Windows\System32\ole32.dll OK C:\Windows\System32\imagehlp.dll OK C:\Windows\System32\wintrust.dll OK C:\Windows\System32\comctl32.dll OK C:\Windows\System32\crypt32.dll OK C:\Windows\System32\devobj.dll OK C:\Windows\System32\KernelBase.dll OK C:\Windows\System32\cfgmgr32.dll OK C:\Windows\System32\msasn1.dll OK C:\Windows\system32\basesrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\sxssrv.dll OK C:\Windows\system32\basesrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\sxssrv.dll OK {9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\InprocServer32 OK {CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 OK C:\Windows\system32\services.exe OK Removing C:\Windows\assembly\temp ... Work complete. -- EOF -- |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=12901d53317840498975222079be58fb # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-13 04:18:17 # local_time=2012-08-13 06:18:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=768 16777215 100 0 61001700 61001700 0 0 # compatibility_mode=1792 16777215 100 0 27134348 27134348 0 0 # compatibility_mode=5893 16776574 66 94 4049340 96496360 0 0 # compatibility_mode=8192 67108863 100 0 4065181 4065181 0 0 # scanned=181559 # found=3 # cleaned=2 # scan_time=8187 C:\Users\Stephan\Downloads\SoftonicDownloader35819.exe a variant of Win32/SoftonicDownloader.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Q:\STEPHAN-THINK\Backup Set 2012-04-10 154448\Backup Files 2012-04-10 154448\Backup files 20.zip multiple threats (deleted - quarantined) 00000000000000000000000000000000 C ${Memory} a variant of Win32/Sirefef.EZ trojan 00000000000000000000000000000000 I |
Alle Zeitangaben in WEZ +1. Es ist jetzt 18:08 Uhr. |
Copyright ©2000-2025, Trojaner-Board