PrisMaster | 29.07.2012 09:25 | So hier die logs Code:
# AdwCleaner v1.703 - Logfile created 07/28/2012 at 15:49:23
# Updated 20/07/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Kev - PETER
# Running from : C:\Users\Kev\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Users\Kev\AppData\Local\SanctionedMedia
Folder Deleted : C:\Users\Kev\AppData\Local\TempDir
Folder Deleted : C:\Users\Kev\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Kev\AppData\LocalLow\DVDVideoSoftTB
Folder Deleted : C:\Users\Kev\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\Kev\AppData\Roaming\instplugin
Folder Deleted : C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\Conduit
Folder Deleted : C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\ConduitCommon
Folder Deleted : C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\ConduitEngine
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\DVDVideoSoftTB
Folder Deleted : C:\Program Files\facemoods.com
File Deleted : C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\searchplugins\Conduit.xml
***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\facemoods.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smad
Key Deleted : HKCU\Software\SanctionedMedia
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DT Soft
Key Deleted : HKLM\SOFTWARE\DVDVideoSoftTB
Key Deleted : HKLM\SOFTWARE\facemoods.com
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-89AF-189327213627}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-89AF-189327213627}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-89AF-189327213627}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-89AF-189327213627}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.19272
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.facemoods.com/?a=dpg --> hxxp://www.google.com
-\\ Mozilla Firefox v11.0 (de)
Profile name : default
File : C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\prefs.js
C:\Users\Kev\AppData\Roaming\Mozilla\Firefox\Profiles\p39cl31u.default\user.js ... Deleted !
Deleted : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2269050.CTID", "CT2269050");
Deleted : user_pref("CT2269050.CurrentServerDate", "27-9-2010");
Deleted : user_pref("CT2269050.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2269050.DownloadReferralCookieData", "");
Deleted : user_pref("CT2269050.EMailNotifierPollDate", "Mon Sep 27 2010 21:30:13 GMT+0200");
Deleted : user_pref("CT2269050.FirstServerDate", "27-9-2010");
Deleted : user_pref("CT2269050.FirstTime", true);
Deleted : user_pref("CT2269050.FirstTimeFF3", true);
Deleted : user_pref("CT2269050.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2269050.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2269050.Initialize", true);
Deleted : user_pref("CT2269050.InitializeCommonPrefs", true);
Deleted : user_pref("CT2269050.InstallationAndCookieDataSentCount", 1);
Deleted : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2269050.InstalledDate", "Mon Sep 27 2010 21:30:13 GMT+0200");
Deleted : user_pref("CT2269050.InvalidateCache", false);
Deleted : user_pref("CT2269050.IsGrouping", false);
Deleted : user_pref("CT2269050.IsMulticommunity", false);
Deleted : user_pref("CT2269050.IsOpenThankYouPage", false);
Deleted : user_pref("CT2269050.IsOpenUninstallPage", false);
Deleted : user_pref("CT2269050.LanguagePackLastCheckTime", "Mon Sep 27 2010 21:30:16 GMT+0200");
Deleted : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2269050.LastLogin_2.7.0.14", "Mon Sep 27 2010 21:30:14 GMT+0200");
Deleted : user_pref("CT2269050.LatestVersion", "2.7.2.0");
Deleted : user_pref("CT2269050.Locale", "en");
Deleted : user_pref("CT2269050.LoginCache", 4);
Deleted : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2269050.RadioIsPodcast", false);
Deleted : user_pref("CT2269050.RadioLastCheckTime", "Mon Sep 27 2010 21:30:15 GMT+0200");
Deleted : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Deleted : user_pref("CT2269050.RadioMediaID", "12473383");
Deleted : user_pref("CT2269050.RadioMediaType", "Media Player");
Deleted : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Deleted : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Deleted : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Deleted : user_pref("CT2269050.SavedHomepage", "google.at");
Deleted : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...]
Deleted : user_pref("CT2269050.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Mon Sep 27 2010 21:30:15 GMT+0200");
Deleted : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2269050.SettingsLastCheckTime", "Mon Sep 27 2010 21:30:11 GMT+0200");
Deleted : user_pref("CT2269050.SettingsLastUpdate", "1285583098");
Deleted : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Mon Sep 27 2010 21:30:11 GMT+0200");
Deleted : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2269050.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2269050.UserID", "UN13250458163620826");
Deleted : user_pref("CT2269050.WeatherNetwork", "");
Deleted : user_pref("CT2269050.WeatherPollDate", "Mon Sep 27 2010 21:30:14 GMT+0200");
Deleted : user_pref("CT2269050.WeatherUnit", "C");
Deleted : user_pref("CT2269050.alertChannelId", "666138");
Deleted : user_pref("CT2269050.clientLogIsEnabled", false);
Deleted : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2269050.myStuffEnabled", true);
Deleted : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT484075.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT484075.DSInstall", false);
Deleted : user_pref("CT484075.DialogsAlignMode", "LTR");
Deleted : user_pref("CT484075.DialogsGetterLastCheckTime", "Tue Jan 31 2012 08:29:27 GMT+0100");
Deleted : user_pref("CT484075.FirstTimeFF3", true);
Deleted : user_pref("CT484075.HPInstall", false);
Deleted : user_pref("CT484075.HasUserGlobalKeys", true);
Deleted : user_pref("CT484075.Initialize", true);
Deleted : user_pref("CT484075.InitializeCommonPrefs", true);
Deleted : user_pref("CT484075.InstalledDate", "Tue Jan 31 2012 08:29:28 GMT+0100");
Deleted : user_pref("CT484075.IsGrouping", false);
Deleted : user_pref("CT484075.IsInitSetupIni", true);
Deleted : user_pref("CT484075.IsMulticommunity", false);
Deleted : user_pref("CT484075.IsOpenThankYouPage", true);
Deleted : user_pref("CT484075.IsOpenUninstallPage", true);
Deleted : user_pref("CT484075.LanguagePackLastCheckTime", "Tue Jan 31 2012 08:29:28 GMT+0100");
Deleted : user_pref("CT484075.Locale", "de");
Deleted : user_pref("CT484075.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT484075.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT484075.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT484075.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT484075.SearchCaption", "Bofanz Customized Web Search");
Deleted : user_pref("CT484075.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT484075.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT484075.ServiceMapLastCheckTime", "Tue Jan 31 2012 08:29:26 GMT+0100");
Deleted : user_pref("CT484075.SettingsLastCheckTime", "Tue Jan 31 2012 08:29:26 GMT+0100");
Deleted : user_pref("CT484075.SettingsLastUpdate", "1323179912");
Deleted : user_pref("CT484075.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT484075&SearchSource=13");
Deleted : user_pref("CT484075.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT484075.ThirdPartyComponentsLastCheck", "Tue Jan 31 2012 08:29:26 GMT+0100");
Deleted : user_pref("CT484075.ThirdPartyComponentsLastUpdate", "1255344657");
Deleted : user_pref("CT484075.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT484075.Uninstall", true);
Deleted : user_pref("CT484075.alertChannelId", "70019");
Deleted : user_pref("CT484075.globalFirstTimeInfoLastCheckTime", "Tue Jan 31 2012 08:29:27 GMT+0100");
Deleted : user_pref("CT484075.initDone", true);
Deleted : user_pref("CT484075.isAppTrackingManagerOn", true);
Deleted : user_pref("CT484075.revertSettingsEnabled", true);
Deleted : user_pref("CT484075.testingCtid", "");
Deleted : user_pref("CT484075.toolbarAppMetaDataLastCheckTime", "Tue Jan 31 2012 08:29:26 GMT+0100");
Deleted : user_pref("CT484075.toolbarContextMenuLastCheckTime", "Tue Jan 31 2012 08:29:28 GMT+0100");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT484075/CT484075",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=70019&fid=69447", "\"0\"");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/70019/69447/AT", "\"0\"");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/AT", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT484075", "[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT484075", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT484075&octid=C[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT484075/CT484075",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"420[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "CT484075");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{6aefa029-2d13-465f-ae31-203fc5b98897}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bofanz");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Kev\\AppData\\Roaming\\Mozilla\\Fir[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.1.0");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT484075");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{6aefa029-2d13-465f-ae31-203fc5b98897}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bofanz");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,ConduitEngine,CT484075");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT484075");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun May 29 2011 08:23:55 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sat Jun 25 2011 18:36:11 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat Jun 25 2011 16:51:00 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "{8a3ae335-f78f-4113-af77-0cd488290871}");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Sep 27 2010 21:30:15 GMT+0200");
Deleted : user_pref("CommunityToolbar.globalUserId", "8a0612b8-f295-46ab-8b9e-1a22283283cc");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2269050");
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jan 31 2012 08:29:2[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Jan 29 2012 18:29:22 GMT+010[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jan 31 2012 08:29:28 GMT+0100");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "4762ac89-ed2a-4ac2-88d1-6c14045a6fce");
Deleted : user_pref("CommunityToolbar.originalHomepage", "google.at");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "foxsearch");
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed Jun 22 2011 16:13:49 GMT+0200");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Thu Jun 23 2011 19:16:24 GMT+0200");
Deleted : user_pref("ConduitEngine.FirstServerDate", "05/07/2011 01");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Sat May 07 2011 00:46:12 GMT+0200");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sat Jun 25 2011 18:35:49 GMT+0200");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sat Jun 25 2011 16:35:45 GMT+0200");
Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Sat Jun 25 2011 16:35:45 GMT+0200");
Deleted : user_pref("ConduitEngine.UserID", "UN22624984165108946");
Deleted : user_pref("ConduitEngine.engineLocale", "de");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sat Jun 25 2011 18:35:49 GMT+0200");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sat Jun 25 2011 18:35:45 GMT+0200");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&Sea[...]
Deleted : user_pref("extensions.facemoods.aflt", "_#dpg");
Deleted : user_pref("extensions.facemoods.firstRun", false);
Deleted : user_pref("extensions.facemoods.lastActv", "28");
-\\ Google Chrome v20.0.1132.57
File : C:\Users\Kev\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted : "css": [ "style/facemoods_chrome_1.0.1.css" ],
Deleted : "name": "Facemoods",
Deleted : "permissions": [ "tabs", "hxxp://igor.facemoods.com/", "hxxp://reports.facemoods.com/[...]
Deleted : "update_url": "hxxp://facemoods.com/public/download/chrome/update.xml",
*************************
AdwCleaner[R1].txt - [24621 octets] - [28/07/2012 10:04:12]
AdwCleaner[S1].txt - [25286 octets] - [28/07/2012 15:49:23]
########## EOF - C:\AdwCleaner[S1].txt - [25415 octets] ##########
und Emisoft: Code:
Emsisoft Anti-Malware - Version 6.6
Letztes Update: 28.07.2012 19:14:56
Scan Einstellungen:
Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\
Archiv Scan: An
ADS Scan: An
Scan Beginn: 28.07.2012 19:15:13
c:\users\kev\appdata\roaming\microst\ gefunden: Trace.File.carberp!E1
Value: hkey_current_user\software\nirsoft\pspv --> columns gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showoutlook gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showpasswordprotected gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showsubitems gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> winpos gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showautocompletenopass gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showmsnexplorer gefunden: Trace.Registry.protected storage pass view!E1
Value: hkey_current_user\software\nirsoft\pspv --> showautocomplete gefunden: Trace.Registry.protected storage pass view!E1
C:\Users\Kev\Downloads\pass\BulletsPassView.exe gefunden: Riskware.PSWTool.Win32.NetPass!E1
C:\Users\Kev\Downloads\pass\VNCPassView.exe gefunden: Riskware.PSWTool.Win32.VNCPwdump!E1
C:\Users\Kev\Documents\te.comp\training2007\Simulation\Uebungen\CopyTasks.exe gefunden: Trojan.Win32.Buzus!E2
C:\Users\Kev\Documents\te.comp\training2007\Access\autorun.inf gefunden: Worm.Win32.AutoRun!E2
C:\Users\Kev\Documents\te.comp\training2007\Simulation\Uebungen\MouseFencer.exe gefunden: Trojan.Win32.Buzus!E2
C:\Users\Kev\Documents\te.comp\training2007\Simulation\Uebungen\ShortCutDialog.exe gefunden: Trojan.Win32.Buzus!E2
C:\Users\Kev\Documents\te.comp\training2007\Simulation\Uebungen\WindowTasks.exe gefunden: Trojan.Win32.Buzus!E2
C:\Users\Kev\AppData\Local\Temp\training2007\EC930E6405923C5B7FC34C35B49EC9F4.zip -> Simulation\Uebungen\WindowTasks.exe gefunden: Trojan.Win32.Buzus!E2
C:\Users\Kev\AppData\Local\Temp\NERO14766\Toolbar.exe gefunden: Adware.Win32.AskTBar!E1
C:\HP\BIN\EndProcess.exe gefunden: Riskware.Win32.KillApp!E1
Gescannt 818807
Gefunden 19
Scan Ende: 29.07.2012 02:50:32
Scan Zeit: 7:35:19 Hatte während Emisoft lief nen Bluescreen, btw :)
lg |