![]() |
Ständig Weiterleitung auf unerwünschte Werbeseiten Hallo zusammen, ich habe folgendes Problem: Seit ein paar Tagen werde ich beim Internet Explorer auf Werbeseiten weitergeleitet. Dieses passiert meistens, wenn ich etwas lese und auf die nächste Seite klicken möchte oder einen Artikel lesen möchte. Es erscheint oben vor der weiterleitung die Internetadresse z.B "benathome", leider bin ich nicht schnell genung, mir die Adressen aufzuschreiben. Danach lande ich auf Otto.de oder bei Ebay. Avira und Adaware habe ich schon zig mal durchlaufen lassen, aber es wird keine Virus oder ähnliches angezeigt. Ich hoffe ihr könnt mir helfen Gruss bettina |
Hi, OTL Lade Dir OTL von Oldtimer herunter (http://filepony.de/download-otl/) und speichere es auf Deinem Desktop
Malwarebytes Antimalware (MAM) Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen: http://filepony.de/download-chameleon/ Danach bitte update der Signaturdateien (Reiter "Aktualisierungen" -> Suche nach Aktualisierungen") Fullscan und alles bereinigen lassen! Log posten. AdwareCleaner (AdwCleaner) Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen! Poste die Logfiles in Code-Tags Download über AdwCleaner by Xplode zum Desktop. http://www.imgdumper.nl/uploads5/4fd...Cleaner_00.jpg Starte AdwCleaner und klicke Search Nach einiger zeit öffnet ein Logfile (C:\AdwCleaner[xx].txt) poste dessen Inhalt hier ins Forum. chris |
Hallo, vielen Dank, ich hoffe so ist es richtig gepostet: # AdwCleaner v1.702 - Logfile created 07/16/2012 at 19:18:59 # Updated 13/07/2012 by Xplode # Operating system : Windows 7 Home Premium (64 bits) # User : betti - BETTI-PC # Running from : C:\Users\betti\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\betti\AppData\Local\Conduit Folder Found : C:\Users\betti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Folder Found : C:\Users\betti\AppData\Local\Temp\boost_interprocess Folder Found : C:\Users\betti\AppData\LocalLow\Conduit Folder Found : C:\Users\betti\AppData\LocalLow\pdfforge Folder Found : C:\Users\betti\AppData\LocalLow\PriceGong Folder Found : C:\Users\betti\AppData\LocalLow\Search Settings Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\Conduit Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\ConduitEngine Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\engine@conduit.com Folder Found : C:\Program Files (x86)\Application Updater Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\pdfforge Toolbar Folder Found : C:\Program Files (x86)\Common Files\spigot ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2269050[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\Search Settings Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Application Updater Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\pdfforge Key Found : HKLM\SOFTWARE\Search Settings [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong [x64] Key Found : HKCU\Software\AppDataLow\Software\Search Settings [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v3.6.6 (de) Profile name : default File : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\prefs.js Found : user_pref("CT2431245..clientLogIsEnabled", true); Found : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2431245.CTID", "CT2431245"); Found : user_pref("CT2431245.CurrentServerDate", "20-5-2011"); Found : user_pref("CT2431245.DialogsAlignMode", "LTR"); Found : user_pref("CT2431245.DownloadReferralCookieData", ""); Found : user_pref("CT2431245.EMailNotifierPollDate", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("CT2431245.FeedLastCount129009402595187825", 488); Found : user_pref("CT2431245.FeedPollDate7470634014180506963", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014269327586", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014329599698", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014537505092", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014970726540", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015410831318", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015483395460", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015636754705", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015768347545", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015855543602", "Fri May 20 2011 07:50:27 GMT+0200"); der zweite log :OTL Logfile: Code: OTL logfile created on: 16.07.2012 07:56:55 - Run 1 der dritte dauert noch einen moment, vielleicht hilft das ja shcon ein wenig weiter. DANKE und hier das letzte: Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: v2012.07.16.08 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 betti :: BETTI-PC [Administrator] Schutz: Aktiviert 16.07.2012 19:14:37 mbam-log-2012-07-16 (22-29-10).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 469756 Laufzeit: 2 Stunde(n), 42 Minute(n), 43 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\betti\Pictures\Downloads\SoftonicDownloader_fuer_gimp.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\betti\Pictures\Downloads\SoftonicDownloader_fuer_magix-video-deluxe-mx.exe (PUP.ToolbarDownloader) -> Keine Aktion durchgeführt. (Ende) ich hoffe es ist noch was zu retten... Danke lg Betti und hier das letzte: Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: v2012.07.16.08 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 betti :: BETTI-PC [Administrator] Schutz: Aktiviert 16.07.2012 19:14:37 mbam-log-2012-07-16 (22-29-10).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 469756 Laufzeit: 2 Stunde(n), 42 Minute(n), 43 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\betti\Pictures\Downloads\SoftonicDownloader_fuer_gimp.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. C:\Users\betti\Pictures\Downloads\SoftonicDownloader_fuer_magix-video-deluxe-mx.exe (PUP.ToolbarDownloader) -> Keine Aktion durchgeführt. (Ende) ich hoffe es ist noch was zu retten... Danke lg Betti |
Hi, here we go... Bitte folgende Files prüfen: Dateien Online überprüfen lassen:
Code: C:\Windows\Wiainst.exe
Fix für OTL:
Code:
Falls Adware gefunden wurde: AdwareCleaner Schliesse alle offenstehende Fenster und starte AdwCleaner (Win7/Vista: Als Administrator ausführen)
Dein Rechner wird neu gestartet und es öffnet sich ein Logfile (C:\AdwCleaner[xx].txt), poste dessen Inhalt hier ins Forum. Poste dann noch ein neues OTL-Log... chris |
All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoControlPanel deleted successfully. ADS C:\ProgramData\Temp:AB689DEA deleted successfully. ADS C:\ProgramData\Temp:93DE1838 deleted successfully. ADS C:\ProgramData\Temp:E3C56885 deleted successfully. ADS C:\ProgramData\Temp:0B9176C0 deleted successfully. C:\Windows\Wiainst.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: AppData User: betti ->Temp folder emptied: 65368046 bytes ->Temporary Internet Files folder emptied: 593030390 bytes ->Java cache emptied: 16590860 bytes ->FireFox cache emptied: 92254326 bytes ->Google Chrome cache emptied: 6337660 bytes ->Flash cache emptied: 57067 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 14113 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 349183952 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36052464 bytes RecycleBin emptied: 8476818892 bytes Total Files Cleaned = 9.189,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07172012_081000 Files\Folders moved on Reboot... C:\Users\betti\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y18OJTH9\schlauch-pflege-wie-oft-putzt-ihr-240223-4[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MRQEMQ0U\54791-anleitung-uploadchannel-trojaner-board[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[2].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[3].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[4].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\data_sync[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L9CWR0NH\data_sync[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K6QJKX1D\ads[4].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K6QJKX1D\ads[5].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GMNR4YTW\afr[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FM1TBPQT\ads[3].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BD682KN8\ads[3].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A4LGLFST\analysis[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0N2A8VS0\119605-staendig-weiterleitung-unerwuenschte-werbeseiten[1].htm moved successfully. File\Folder C:\Windows\temp\mcafee_bmANqlY31Mc7FGl not found! File\Folder C:\Windows\temp\mcmsc_231dXWyoXIvCESb not found! File\Folder C:\Windows\temp\mcmsc_96WpFpvq0YGa4xx not found! File\Folder C:\Windows\temp\mcmsc_oWOLoU5Yr3qvrwM not found! File\Folder C:\Windows\temp\mcmsc_ZDpaZ48GpsTO3Kw not found! File\Folder C:\Windows\temp\sqlite_HjjE4hgtiq0qvvF not found! File\Folder C:\Windows\temp\sqlite_ki97wjr6ovwLdxq not found! File\Folder C:\Windows\temp\sqlite_mNXhR42kPek5NNM not found! File\Folder C:\Windows\temp\sqlite_UYMiBUKgbRWyNT9 not found! PendingFileRenameOperations files... File C:\Users\betti\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y18OJTH9\schlauch-pflege-wie-oft-putzt-ihr-240223-4[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MRQEMQ0U\54791-anleitung-uploadchannel-trojaner-board[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[2].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[3].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\afr[4].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH1LL87B\data_sync[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L9CWR0NH\data_sync[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K6QJKX1D\ads[4].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K6QJKX1D\ads[5].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GMNR4YTW\afr[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FM1TBPQT\ads[3].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BD682KN8\ads[3].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A4LGLFST\analysis[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0N2A8VS0\119605-staendig-weiterleitung-unerwuenschte-werbeseiten[1].htm not found! File C:\Windows\temp\mcafee_bmANqlY31Mc7FGl not found! File C:\Windows\temp\mcmsc_231dXWyoXIvCESb not found! File C:\Windows\temp\mcmsc_96WpFpvq0YGa4xx not found! File C:\Windows\temp\mcmsc_oWOLoU5Yr3qvrwM not found! File C:\Windows\temp\mcmsc_ZDpaZ48GpsTO3Kw not found! File C:\Windows\temp\sqlite_HjjE4hgtiq0qvvF not found! File C:\Windows\temp\sqlite_ki97wjr6ovwLdxq not found! File C:\Windows\temp\sqlite_mNXhR42kPek5NNM not found! File C:\Windows\temp\sqlite_UYMiBUKgbRWyNT9 not found! Registry entries deleted on Reboot... leider hat mich der akku im stich gelassen und von virustotal ist die datei nicht mehr auffindbar. kann ich da noch was machen? Ich hoffe so ist es richtig mit dem log. bettina hier der log vom adware cleaner. # AdwCleaner v1.702 - Logfile created 07/17/2012 at 19:41:30 # Updated 13/07/2012 by Xplode # Operating system : Windows 7 Home Premium (64 bits) # User : betti - BETTI-PC # Running from : C:\Users\betti\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\betti\AppData\Local\Conduit Folder Found : C:\Users\betti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Folder Found : C:\Users\betti\AppData\Local\Temp\boost_interprocess Folder Found : C:\Users\betti\AppData\LocalLow\Conduit Folder Found : C:\Users\betti\AppData\LocalLow\pdfforge Folder Found : C:\Users\betti\AppData\LocalLow\PriceGong Folder Found : C:\Users\betti\AppData\LocalLow\Search Settings Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\Conduit Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\ConduitEngine Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Folder Found : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\engine@conduit.com Folder Found : C:\Program Files (x86)\Application Updater Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\pdfforge Toolbar Folder Found : C:\Program Files (x86)\Common Files\spigot ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2269050[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\Search Settings Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Application Updater Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\pdfforge Key Found : HKLM\SOFTWARE\Search Settings [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong [x64] Key Found : HKCU\Software\AppDataLow\Software\Search Settings [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] [x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] [x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v3.6.6 (de) Profile name : default File : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\prefs.js Found : user_pref("CT2431245..clientLogIsEnabled", true); Found : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2431245.CTID", "CT2431245"); Found : user_pref("CT2431245.CurrentServerDate", "20-5-2011"); Found : user_pref("CT2431245.DialogsAlignMode", "LTR"); Found : user_pref("CT2431245.DownloadReferralCookieData", ""); Found : user_pref("CT2431245.EMailNotifierPollDate", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("CT2431245.FeedLastCount129009402595187825", 488); Found : user_pref("CT2431245.FeedPollDate7470634014180506963", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014269327586", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014329599698", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014537505092", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634014970726540", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015410831318", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015483395460", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015636754705", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015768347545", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634015855543602", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016030710453", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016114705611", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016129205152", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016143724791", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016271239162", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016568520719", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634016726993788", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017109031809", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017132743740", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017299547668", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017302327846", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017344111490", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017478360748", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017732797593", "Fri May 20 2011 07:50:27 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634017821686064", "Fri May 20 2011 07:50:29 GMT+0200"); Found : user_pref("CT2431245.FeedPollDate7470634018090228721", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.FeedTTL7470634014269327586", 5); Found : user_pref("CT2431245.FeedTTL7470634014537505092", 5); Found : user_pref("CT2431245.FeedTTL7470634014970726540", 2); Found : user_pref("CT2431245.FeedTTL7470634016568520719", 30); Found : user_pref("CT2431245.FeedTTL7470634017109031809", 30); Found : user_pref("CT2431245.FeedTTL7470634017299547668", 2); Found : user_pref("CT2431245.FirstServerDate", "20-5-2011"); Found : user_pref("CT2431245.FirstTime", true); Found : user_pref("CT2431245.FirstTimeFF3", true); Found : user_pref("CT2431245.FixPageNotFoundErrors", true); Found : user_pref("CT2431245.GroupingServerCheckInterval", 1440); Found : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2431245.HasUserGlobalKeys", true); Found : user_pref("CT2431245.Initialize", true); Found : user_pref("CT2431245.InitializeCommonPrefs", true); Found : user_pref("CT2431245.InstallationAndCookieDataSentCount", 1); Found : user_pref("CT2431245.InstallationId", "Unknown"); Found : user_pref("CT2431245.InstallationType", "ExternalIntegration"); Found : user_pref("CT2431245.InstalledDate", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("CT2431245.InvalidateCache", false); Found : user_pref("CT2431245.IsGrouping", false); Found : user_pref("CT2431245.IsMulticommunity", false); Found : user_pref("CT2431245.IsOpenThankYouPage", false); Found : user_pref("CT2431245.IsOpenUninstallPage", true); Found : user_pref("CT2431245.LanguagePackLastCheckTime", "Fri May 20 2011 07:50:25 GMT+0200"); Found : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2431245.LastLogin_3.2.5.2", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("CT2431245.LatestVersion", "3.2.5.2"); Found : user_pref("CT2431245.Locale", "de-de"); Found : user_pref("CT2431245.MCDetectTooltipHeight", "83"); Found : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2431245.MCDetectTooltipWidth", "295"); Found : user_pref("CT2431245.RadioIsPodcast", false); Found : user_pref("CT2431245.RadioLastCheckTime", "Fri May 20 2011 07:50:28 GMT+0200"); Found : user_pref("CT2431245.RadioLastUpdateIPServer", "3"); Found : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000"); Found : user_pref("CT2431245.RadioMediaID", "20503672"); Found : user_pref("CT2431245.RadioMediaType", "Media Player"); Found : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672"); Found : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland"); Found : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u"); Found : user_pref("CT2431245.SearchFromAddressBarIsInit", true); Found : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...] Found : user_pref("CT2431245.SearchInNewTabEnabled", true); Found : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Fri May 20 2011 07:50:24 GMT+0200"); Found : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Found : user_pref("CT2431245.ServiceMapLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Found : user_pref("CT2431245.SettingsLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Found : user_pref("CT2431245.SettingsLastUpdate", "1305800360"); Found : user_pref("CT2431245.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Fri May 20 2011 07:50:22 GMT+0200"); Found : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1255344657"); Found : user_pref("CT2431245.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Found : user_pref("CT2431245.UserID", "UN19394633091674662"); Found : user_pref("CT2431245.WeatherNetwork", ""); Found : user_pref("CT2431245.WeatherPollDate", "Fri May 20 2011 07:50:25 GMT+0200"); Found : user_pref("CT2431245.WeatherUnit", "C"); Found : user_pref("CT2431245.alertChannelId", "825452"); Found : user_pref("CT2431245.backendstorage.for_aoi", "31333035383730363332"); Found : user_pref("CT2431245.backendstorage.for_ccid", "6E756C6C"); Found : user_pref("CT2431245.backendstorage.for_cdtr5", "31333035383730363332"); Found : user_pref("CT2431245.backendstorage.for_cid", "4445"); Found : user_pref("CT2431245.backendstorage.for_ip", "39322E37322E33332E3233"); Found : user_pref("CT2431245.backendstorage.for_lcut", "31333035383730363333"); Found : user_pref("CT2431245.backendstorage.for_pid", "31303130"); Found : user_pref("CT2431245.backendstorage.for_rid", "3037"); Found : user_pref("CT2431245.backendstorage.for_zoneid", "39353933"); Found : user_pref("CT2431245.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Found : user_pref("CT2431245.myStuffEnabled", true); Found : user_pref("CT2431245.myStuffPublihserMinWidth", 400); Found : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2431245.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2431245.testingCtid", ""); Found : user_pref("CT2431245.toolbarAppMetaDataLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("CT2431245.toolbarContextMenuLastCheckTime", "Fri May 20 2011 07:50:25 GMT+0200"); Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63441308206287[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Found : user_pref("CommunityToolbar.EngineOwner", "CT2431245"); Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "softonic-de3"); Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2431245"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "softonic-de3"); Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.yahoo.com/search?ei=utf-8&[...] Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2431245"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245"); Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 60); Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri May 20 2011 07:50:24 GMT+0200"); Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.alert.locale", "en"); Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri May 20 2011 07:50:21 GMT+0200"); Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.alert.userId", "f6153b5d-335e-46a4-92db-f95bbe45c270"); Found : user_pref("ConduitEngine.FirstServerDate", "05/20/2011 08"); Found : user_pref("ConduitEngine.FirstTime", true); Found : user_pref("ConduitEngine.FirstTimeFF3", true); Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Found : user_pref("ConduitEngine.Initialize", true); Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Found : user_pref("ConduitEngine.InstalledDate", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("ConduitEngine.IsMulticommunity", false); Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Found : user_pref("ConduitEngine.IsOpenUninstallPage", true); Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("ConduitEngine.PublisherContainerWidth", 0); Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Found : user_pref("ConduitEngine.UserID", "UN50644644229747811"); Found : user_pref("ConduitEngine.engineLocale", "de"); Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Found : user_pref("ConduitEngine.initDone", true); -\\ Google Chrome v [Unable to get version] File : C:\Users\betti\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "description": "The fastest way to search the web.", ************************* AdwCleaner[R1].txt - [20354 octets] - [16/07/2012 19:18:59] AdwCleaner[R2].txt - [20415 octets] - [16/07/2012 19:20:06] AdwCleaner[R3].txt - [20375 octets] - [17/07/2012 19:41:30] ########## EOF - C:\AdwCleaner[R3].txt - [20504 octets] ########## |
Hi, MAM alle Funde löschen lassen, nie was von Softonic runterladen, die installieren alles möglich gleich mit... Hast Du alle Funde von Adware wie beschrieben löschen lassen? AdwareCleaner Schliesse alle offenstehende Fenster und starte AdwCleaner (Win7/Vista: Als Administrator ausführen)
Dein Rechner wird neu gestartet und es öffnet sich ein Logfile (C:\AdwCleaner[xx].txt), poste dessen Inhalt hier ins Forum. chris |
Guten Morgen, hier das Logfile. Habe mit MAM alles löschen lassen. Kann ich das Programm weiter nutzen um den Rechner durchsuchen zu lassen? Log: # AdwCleaner v1.702 - Logfile created 07/18/2012 at 07:42:50 # Updated 13/07/2012 by Xplode # Operating system : Windows 7 Home Premium (64 bits) # User : betti - BETTI-PC # Running from : C:\Users\betti\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\betti\AppData\Local\Conduit Folder Deleted : C:\Users\betti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Folder Deleted : C:\Users\betti\AppData\Local\Temp\boost_interprocess Folder Deleted : C:\Users\betti\AppData\LocalLow\Conduit Folder Deleted : C:\Users\betti\AppData\LocalLow\pdfforge Folder Deleted : C:\Users\betti\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\betti\AppData\LocalLow\Search Settings Folder Deleted : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\Conduit Folder Deleted : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\ConduitEngine Folder Deleted : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Folder Deleted : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\extensions\engine@conduit.com Folder Deleted : C:\Program Files (x86)\Application Updater Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\pdfforge Toolbar Folder Deleted : C:\Program Files (x86)\Common Files\spigot ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2431245 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Application Updater Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\pdfforge Key Deleted : HKLM\SOFTWARE\Search Settings ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v3.6.6 (de) Profile name : default File : C:\Users\betti\AppData\Roaming\Mozilla\Firefox\Profiles\eldirn3t.default\prefs.js Deleted : user_pref("CT2431245..clientLogIsEnabled", true); Deleted : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2431245.CTID", "CT2431245"); Deleted : user_pref("CT2431245.CurrentServerDate", "20-5-2011"); Deleted : user_pref("CT2431245.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2431245.DownloadReferralCookieData", ""); Deleted : user_pref("CT2431245.EMailNotifierPollDate", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("CT2431245.FeedLastCount129009402595187825", 488); Deleted : user_pref("CT2431245.FeedPollDate7470634014180506963", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634014269327586", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634014329599698", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634014537505092", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634014970726540", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634015410831318", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634015483395460", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634015636754705", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634015768347545", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634015855543602", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016030710453", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016114705611", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016129205152", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016143724791", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016271239162", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016568520719", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634016726993788", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017109031809", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017132743740", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017299547668", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017302327846", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017344111490", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017478360748", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017732797593", "Fri May 20 2011 07:50:27 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634017821686064", "Fri May 20 2011 07:50:29 GMT+0200"); Deleted : user_pref("CT2431245.FeedPollDate7470634018090228721", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.FeedTTL7470634014269327586", 5); Deleted : user_pref("CT2431245.FeedTTL7470634014537505092", 5); Deleted : user_pref("CT2431245.FeedTTL7470634014970726540", 2); Deleted : user_pref("CT2431245.FeedTTL7470634016568520719", 30); Deleted : user_pref("CT2431245.FeedTTL7470634017109031809", 30); Deleted : user_pref("CT2431245.FeedTTL7470634017299547668", 2); Deleted : user_pref("CT2431245.FirstServerDate", "20-5-2011"); Deleted : user_pref("CT2431245.FirstTime", true); Deleted : user_pref("CT2431245.FirstTimeFF3", true); Deleted : user_pref("CT2431245.FixPageNotFoundErrors", true); Deleted : user_pref("CT2431245.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2431245.HasUserGlobalKeys", true); Deleted : user_pref("CT2431245.Initialize", true); Deleted : user_pref("CT2431245.InitializeCommonPrefs", true); Deleted : user_pref("CT2431245.InstallationAndCookieDataSentCount", 1); Deleted : user_pref("CT2431245.InstallationId", "Unknown"); Deleted : user_pref("CT2431245.InstallationType", "ExternalIntegration"); Deleted : user_pref("CT2431245.InstalledDate", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("CT2431245.InvalidateCache", false); Deleted : user_pref("CT2431245.IsGrouping", false); Deleted : user_pref("CT2431245.IsMulticommunity", false); Deleted : user_pref("CT2431245.IsOpenThankYouPage", false); Deleted : user_pref("CT2431245.IsOpenUninstallPage", true); Deleted : user_pref("CT2431245.LanguagePackLastCheckTime", "Fri May 20 2011 07:50:25 GMT+0200"); Deleted : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2431245.LastLogin_3.2.5.2", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("CT2431245.LatestVersion", "3.2.5.2"); Deleted : user_pref("CT2431245.Locale", "de-de"); Deleted : user_pref("CT2431245.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2431245.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2431245.RadioIsPodcast", false); Deleted : user_pref("CT2431245.RadioLastCheckTime", "Fri May 20 2011 07:50:28 GMT+0200"); Deleted : user_pref("CT2431245.RadioLastUpdateIPServer", "3"); Deleted : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000"); Deleted : user_pref("CT2431245.RadioMediaID", "20503672"); Deleted : user_pref("CT2431245.RadioMediaType", "Media Player"); Deleted : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672"); Deleted : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland"); Deleted : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u"); Deleted : user_pref("CT2431245.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...] Deleted : user_pref("CT2431245.SearchInNewTabEnabled", true); Deleted : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Fri May 20 2011 07:50:24 GMT+0200"); Deleted : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...] Deleted : user_pref("CT2431245.ServiceMapLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Deleted : user_pref("CT2431245.SettingsLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Deleted : user_pref("CT2431245.SettingsLastUpdate", "1305800360"); Deleted : user_pref("CT2431245.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Fri May 20 2011 07:50:22 GMT+0200"); Deleted : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1255344657"); Deleted : user_pref("CT2431245.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Deleted : user_pref("CT2431245.UserID", "UN19394633091674662"); Deleted : user_pref("CT2431245.WeatherNetwork", ""); Deleted : user_pref("CT2431245.WeatherPollDate", "Fri May 20 2011 07:50:25 GMT+0200"); Deleted : user_pref("CT2431245.WeatherUnit", "C"); Deleted : user_pref("CT2431245.alertChannelId", "825452"); Deleted : user_pref("CT2431245.backendstorage.for_aoi", "31333035383730363332"); Deleted : user_pref("CT2431245.backendstorage.for_ccid", "6E756C6C"); Deleted : user_pref("CT2431245.backendstorage.for_cdtr5", "31333035383730363332"); Deleted : user_pref("CT2431245.backendstorage.for_cid", "4445"); Deleted : user_pref("CT2431245.backendstorage.for_ip", "39322E37322E33332E3233"); Deleted : user_pref("CT2431245.backendstorage.for_lcut", "31333035383730363333"); Deleted : user_pref("CT2431245.backendstorage.for_pid", "31303130"); Deleted : user_pref("CT2431245.backendstorage.for_rid", "3037"); Deleted : user_pref("CT2431245.backendstorage.for_zoneid", "39353933"); Deleted : user_pref("CT2431245.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Deleted : user_pref("CT2431245.myStuffEnabled", true); Deleted : user_pref("CT2431245.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2431245.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2431245.testingCtid", ""); Deleted : user_pref("CT2431245.toolbarAppMetaDataLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("CT2431245.toolbarContextMenuLastCheckTime", "Fri May 20 2011 07:50:25 GMT+0200"); Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63441308206287[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2431245"); Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "softonic-de3"); Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2431245"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"); Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "softonic-de3"); Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.yahoo.com/search?ei=utf-8&[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2431245"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245"); Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 60); Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri May 20 2011 07:50:24 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.locale", "en"); Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri May 20 2011 07:50:21 GMT+0200"); Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.alert.userId", "f6153b5d-335e-46a4-92db-f95bbe45c270"); Deleted : user_pref("ConduitEngine.FirstServerDate", "05/20/2011 08"); Deleted : user_pref("ConduitEngine.FirstTime", true); Deleted : user_pref("ConduitEngine.FirstTimeFF3", true); Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true); Deleted : user_pref("ConduitEngine.Initialize", true); Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true); Deleted : user_pref("ConduitEngine.InstalledDate", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("ConduitEngine.IsMulticommunity", false); Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false); Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true); Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0); Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri May 20 2011 07:50:22 GMT+0200"); Deleted : user_pref("ConduitEngine.UserID", "UN50644644229747811"); Deleted : user_pref("ConduitEngine.engineLocale", "de"); Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri May 20 2011 07:50:23 GMT+0200"); Deleted : user_pref("ConduitEngine.initDone", true); -\\ Google Chrome v [Unable to get version] File : C:\Users\betti\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "description": "The fastest way to search the web.", ************************* AdwCleaner[R1].txt - [20354 octets] - [16/07/2012 19:18:59] AdwCleaner[R2].txt - [20415 octets] - [16/07/2012 19:20:06] AdwCleaner[R3].txt - [20476 octets] - [17/07/2012 19:41:30] AdwCleaner[S1].txt - [19436 octets] - [18/07/2012 07:42:50] ########## EOF - C:\AdwCleaner[S1].txt - [19565 octets] ########## Gruss Bettina |
Hi, ja Du kannst MAM weiter nutzen, 1x die Woche updaten und dann Scannen lassen. Erstelle und poste bitte noch ein neues OTL-Logfile... Wie verhält sich der Rechner? chris |
Also es scheint wieder normal zu sein. Ich werde nach der Arbeit nochmal in Ruhe prüfen ob ich wieder weitergeleitet werde. Hier der OTL logOTL Logfile: Code: OTL logfile created on: 18.07.2012 08:07:09 - Run 3 Gruss bettina |
Hi, ganz aufgeräumt ist noch nicht, dann laufen da noch ein Programm bzw. Modul die ich nicht kenne: Bitte folgende Files prüfen: Dateien Online überprüfen lassen:
Code: C:\Users\betti\AppData\Local\Temp\UDT-ABBAMGCHGAOGDHBBFHFH2\udt.exe
Prüfe mal in Ruhe alles und melde Dich dann wieder... chris |
hi, den ersten habe ich noch geschafft, der Rest später SHA256: bf06f847756d9bc6cd270dc437757aae6a95099fd2a663d1ccfbe505fa34d46e File name: udt.exe Detection ratio: 3 / 44 Analysis date: 2011-09-23 00:44:17 UTC ( 9 Monate, 4 Wochen ago ) 0 0 More details Antivirus Result Update AhnLab-V3 - 20110922 AntiVir - 20110922 Antiy-AVL - 20110922 Avast - 20110922 Avast5 - 20110922 AVG - 20110922 BitDefender - 20110923 ByteHero - 20110913 CAT-QuickHeal - 20110922 ClamAV - 20110923 Commtouch - 20110922 Comodo Heur.Suspicious 20110923 DrWeb - 20110922 Emsisoft - 20110923 eSafe - 20110920 eTrust-Vet - 20110922 F-Prot - 20110922 F-Secure - 20110923 Fortinet - 20110923 GData - 20110923 Ikarus - 20110923 Jiangmin - 20110922 K7AntiVirus - 20110922 Kaspersky - 20110922 McAfee - 20110923 McAfee-GW-Edition - 20110922 Microsoft - 20110922 NOD32 - 20110923 Norman - 20110922 nProtect - 20110922 Panda - 20110922 PCTools - 20110923 Prevx - 20110923 Rising - 20110922 Sophos - 20110923 SUPERAntiSpyware - 20110923 Symantec - 20110923 TheHacker - 20110922 TrendMicro PAK_Generic.001 20110922 TrendMicro-HouseCall PAK_Generic.001 20110923 VBA32 - 20110922 VIPRE - 20110922 ViRobot - 20110922 VirusBuster - 20110922 Comments Votes Additional information No comments You have not signed in. Only registered users can leave comments, sign in and have a voice! Sign in Join the community SHA256: bf06f847756d9bc6cd270dc437757aae6a95099fd2a663d1ccfbe505fa34d46e SHA1: 370e0ebb80b2b2e93227077d6491e165d487c5ab MD5: 92190d79bc842037105b3b2aa8df41e0 File size: 129.0 KB ( 132096 bytes ) File name: udt.exe File type: Win32 EXE Tags: upx Detection ratio: 3 / 44 Analysis date: 2011-09-23 00:44:17 UTC ( 9 Monate, 4 Wochen ago |
Hi, Dateien die ausführbar sind und in einem temporären Verzeichnis liegen, sind immer sehr ... äh... verdächtig. Ich würde sie Plattmachen... Schauen wir mal was die zweite Datei bringt... Fix für OTL:
Code:
chris |
hallo, die weiterleitung ist immer noch da.... oben auf dem Reiter des explorers erscheint kurz " google analytics! " und dann steht da document has moved... hier der erste log von virustotal SHA256: bf06f847756d9bc6cd270dc437757aae6a95099fd2a663d1ccfbe505fa34d46e SHA1: 370e0ebb80b2b2e93227077d6491e165d487c5ab MD5: 92190d79bc842037105b3b2aa8df41e0 File size: 129.0 KB ( 132096 bytes ) File name: udt.exe File type: Win32 EXE Tags: upx Detection ratio: 3 / 44 Analysis date: 2011-09-23 00:44:17 UTC ( 9 Monate, 4 Wochen ago ) 0 0 More details Antivirus Result Update AhnLab-V3 - 20110922 AntiVir - 20110922 Antiy-AVL - 20110922 Avast - 20110922 Avast5 - 20110922 AVG - 20110922 BitDefender - 20110923 ByteHero - 20110913 CAT-QuickHeal - 20110922 ClamAV - 20110923 Commtouch - 20110922 Comodo Heur.Suspicious 20110923 DrWeb - 20110922 Emsisoft - 20110923 eSafe - 20110920 eTrust-Vet - 20110922 F-Prot - 20110922 F-Secure - 20110923 Fortinet - 20110923 GData - 20110923 Ikarus - 20110923 Jiangmin - 20110922 K7AntiVirus - 20110922 Kaspersky - 20110922 McAfee - 20110923 McAfee-GW-Edition - 20110922 Microsoft - 20110922 NOD32 - 20110923 Norman - 20110922 nProtect - 20110922 Panda - 20110922 PCTools - 20110923 Prevx - 20110923 Rising - 20110922 Sophos - 20110923 SUPERAntiSpyware - 20110923 Symantec - 20110923 TheHacker - 20110922 TrendMicro PAK_Generic.001 20110922 TrendMicro-HouseCall PAK_Generic.001 20110923 VBA32 - 20110922 VIPRE - 20110922 ViRobot - 20110922 VirusBuster - 20110922 und Nr. 2 SHA256: 59a5f56d17385221c843089748ae43255885f6fd0bef079025ad1c8acb0bfef0 SHA1: 73da47149639f136d6918e885cb685fe52e8595c MD5: 4629be29c872be99dff638b1dbae2dba File size: 18.0 KB ( 18432 bytes ) File name: 4629BE29C872BE99DFF638B1DBAE2DBA File type: Win32 DLL Tags: armadillo Detection ratio: 2 / 40 Analysis date: 2012-05-16 07:08:05 UTC ( 2 Monate ago ) 0 0 More details Antivirus Result Update AhnLab-V3 - 20120515 AntiVir - 20120516 Antiy-AVL - 20120516 Avast - 20120516 AVG - 20120516 BitDefender - 20120516 ByteHero - 20120515 CAT-QuickHeal - 20120515 ClamAV - 20120516 Commtouch - 20120516 Comodo - 20120516 DrWeb - 20120516 Emsisoft - 20120516 eSafe - 20120515 eTrust-Vet - 20120515 F-Prot - 20120516 F-Secure - 20120516 Fortinet - 20120516 GData - 20120516 Ikarus - 20120516 Jiangmin - 20120516 K7AntiVirus - 20120515 Kaspersky - 20120516 McAfee - 20120516 McAfee-GW-Edition - 20120516 Microsoft - 20120516 NOD32 - 20120516 Norman - 20120516 nProtect - 20120516 PCTools - 20120516 Rising - 20120516 SUPERAntiSpyware - 20120516 Symantec - 20120516 TheHacker - 20120516 TrendMicro PAK_Generic.001 20120516 TrendMicro-HouseCall PAK_Generic.001 20120516 VBA32 - 20120515 VIPRE - 20120516 ViRobot - 20120516 VirusBuster - 20120515 Gruss Bettina All processes killed ========== OTL ========== No active process named udt.exe was found! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: AppData User: betti ->Temp folder emptied: 1420832 bytes ->Temporary Internet Files folder emptied: 19732533 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 671 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 119049715 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 844416 bytes Total Files Cleaned = 135,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07182012_170840 Files\Folders moved on Reboot... C:\Users\betti\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WHT4NHE6\119605-staendig-weiterleitung-unerwuenschte-werbeseiten-2[1].htm moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WHT4NHE6\st[1] moved successfully. C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R1GWF9CM\bv[1].htm moved successfully. File\Folder C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GG3W2OKC\analysis[2].htm not found! File\Folder C:\Windows\temp\mcmsc_RHbk7hcgLudPvui not found! File\Folder C:\Windows\temp\mcmsc_yRopT3FG0UKI8v9 not found! File\Folder C:\Windows\temp\sqlite_DLIhQ06jbwWpIle not found! File\Folder C:\Windows\temp\sqlite_fJ39IMpK3KMyzAy not found! File\Folder C:\Windows\temp\sqlite_OwghS48YNR6uecI not found! File\Folder C:\Windows\temp\sqlite_rKrDf03AKywhbee not found! PendingFileRenameOperations files... File C:\Users\betti\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WHT4NHE6\119605-staendig-weiterleitung-unerwuenschte-werbeseiten-2[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WHT4NHE6\st[1] not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R1GWF9CM\bv[1].htm not found! File C:\Users\betti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GG3W2OKC\analysis[2].htm not found! File C:\Windows\temp\mcmsc_RHbk7hcgLudPvui not found! File C:\Windows\temp\mcmsc_yRopT3FG0UKI8v9 not found! File C:\Windows\temp\sqlite_DLIhQ06jbwWpIle not found! File C:\Windows\temp\sqlite_fJ39IMpK3KMyzAy not found! File C:\Windows\temp\sqlite_OwghS48YNR6uecI not found! File C:\Windows\temp\sqlite_rKrDf03AKywhbee not found! Registry entries deleted on Reboot... aber die Weiterleitung ist immer noch drin. es erscheint "document has moved", oben im Reiter steht kurz google analytics. LG Bettina |
Hi, jetzt musst Du mir mal genau erklären was Du machst. Google-Analytics ist ein Google-Dienst... Du startest Firefox und eine Suchanfrage, dann klickst Du auf einen Fund und dann kommt innerhalb der Page der Hinweis auf die Redirection. Passiert das bei allen Funden oder nur bei bestimmten? Bitte die URL wo das passiert als private PM an mich. Es gibt tatsächlich Sachverhalte, wo der Seiteninhaber seine Pages reorganisiert hat und eine weiterleitung stattfindet, da er die Inhalte verschoben hat... Poste bitte noch ein neues OTL-Log... chris |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:19 Uhr. |
Copyright ©2000-2025, Trojaner-Board