![]() |
Trojaner lassen sich trotz Malwarebytes nicht löschen, was soll ich tun ? Hallo liebes Team, ich habe seit 3 Tagen folgendes Problem. Ich war in Facebook und habe einen link geschickt bekommen und da ich nicht wirklich drauf geachtet habe was das für ein link war hab ich drauf geklickt und gleich danach hat Avast! mir angezeigt das ich einen Trojaner habe. Ich habe mich etwas im Internet erkundigt und habe mir Malwarebytes installiert. Nach dem Scan (ich habe es Vollständig scannen lassen) gab es so einige Funde und es hieß das ich meinen Laptop neu starten soll, das hat aber nicht viel gebracht denn die Viren sind alle immer noch drauf. Was soll ich tun ? Hier das Logfile: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.20.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Mama :: MAMA-PC [Administrator] Schutz: Aktiviert 21.08.2012 00:06:32 mbam-log-2012-08-21 (00-06-32).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 395034 Laufzeit: 1 Stunde(n), 14 Minute(n), 28 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 15 HKCR\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MyNewsBarLauncher.IE5BarLauncherBHO.1 (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MyNewsBarLauncher.IE5BarLauncherBHO (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MyNewsBarLauncher.IE5BarLauncher.1 (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MyNewsBarLauncher.IE5BarLauncher (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 4 HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Daten: ;áÃzÊ;XA³0öm»Áµ -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Daten: VShareTB -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 14 C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3DL0AVTH\trololololol[1].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\63542LG6\sl[1].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\63542LG6\start[1].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\75C0X8PJ\trololololol[1].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F34Z2THM\trololololol[1].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F34Z2THM\trololololol[2].exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\105373.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\4138247671.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\477070.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\7109904467.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\893997.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mama\AppData\Local\Temp\983048.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Temp\_avast_\unp105114360.tmp (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Schon einmal vielen Dank im voraus für eure Hilfe Grüße Venomous |
:hallo: CustomScan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code: netsvcs
|
OTL Logfile: Code: OTL logfile created on: 8/23/2012 2:10:17 PM - Run 1 |
Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
All processes killed ========== OTL ========== Error: No service named Akamai was found to stop! Service\Driver key Akamai not found. File c:\program files (x86)\common files\akamai/netsession_win_4f7fccd.dll not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{90b49673-5506-483e-b92b-ca0265bd9ca8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-2614301483-2537791305-717444225-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKU\S-1-5-21-2614301483-2537791305-717444225-1001\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found. Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{90b49673-5506-483e-b92b-ca0265bd9ca8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found. HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{57E14EC0-3D8D-4B24-9B75-AB3FDBBBDFE4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57E14EC0-3D8D-4B24-9B75-AB3FDBBBDFE4}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{59CD5ECA-5095-4976-AC87-D31D9A31877A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59CD5ECA-5095-4976-AC87-D31D9A31877A}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{92FC8871-6555-4E24-8757-28E4A328D35E}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92FC8871-6555-4E24-8757-28E4A328D35E}\ not found. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. HKU\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "ICQ Search" removed from browser.search.selectedEngine Prefs.js: "hxxp://start.icq.com/sk27211/" removed from browser.startup.homepage Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=sk27211&tb_ver=1.4.3&q=" removed from keyword.URL Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "ICQ Search" removed from browser.search.defaultenginename 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513\ deleted successfully. Use Chrome's Settings page to change the HomePage. Use Chrome's Settings page to remove the default_search_provider items. Use Chrome's Settings page to remove the default_search_provider items. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA609D72-8482-4076-8991-8CDAE5B93BCB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA609D72-8482-4076-8991-8CDAE5B93BCB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{90b49673-5506-483e-b92b-ca0265bd9ca8} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Aeria Ignite deleted successfully. Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully. C:\Users\Mama\AppData\Local\Akamai\netsession_win.exe moved successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0000036B-C524-4050-81A0-243669A86B9F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000036B-C524-4050-81A0-243669A86B9F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{328ECD19-C167-40eb-A0C7-16FE7634105E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{328ECD19-C167-40eb-A0C7-16FE7634105E}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1000\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1000\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-2614301483-2537791305-717444225-1000\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ deleted successfully. File {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found. File {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ deleted successfully. File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324}\ deleted successfully. File {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll File not found not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87c17cd3-a4d4-11e1-8357-e81132462835}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87c17cd3-a4d4-11e1-8357-e81132462835}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87c17cd3-a4d4-11e1-8357-e81132462835}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87c17cd3-a4d4-11e1-8357-e81132462835}\ not found. File F:\HTC_Sync_Manager_PC.exe not found. C:\Windows\SysWow64\lMMLDeleteUserData42107612FX.tmp deleted successfully. C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2614301483-2537791305-717444225-1001UA.job moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2614301483-2537791305-717444225-1001UA.job moved successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2614301483-2537791305-717444225-1001Core.job moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2614301483-2537791305-717444225-1001Core.job moved successfully. C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\U\00000008.@ moved successfully. C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\L\00000004.@ moved successfully. C:\Users\Mama\AppData\Roaming\TP folder moved successfully. C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\@ moved successfully. C:\Users\Mama\AppData\Local\{0db82727-358d-64d2-f921-45c55595c778}\@ moved successfully. C:\Users\Mama\AppData\Roaming\Babylon folder moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Mama\Desktop\cmd.bat deleted successfully. C:\Users\Mama\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mama ->Temp folder emptied: 3238557674 bytes ->Temporary Internet Files folder emptied: 8658550 bytes ->Java cache emptied: 51001023 bytes ->FireFox cache emptied: 44391821 bytes ->Google Chrome cache emptied: 227437891 bytes ->Flash cache emptied: 804 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 276057985 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 1330868 bytes Total Files Cleaned = 3,669.00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08232012_210756 Files\Folders moved on Reboot... C:\Users\Mama\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Sehr gut! :daumenhoc Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Wow danke :dankeschoen: Ja bis jetzt habe ich keine Meldungen mehr bekommen, also von Avast aus :) und alles läuft wieder viel schneller. Und Malwarebytes hat keine Viren / infizierte Daten gefunden. # AdwCleaner v1.801 - Logfile created 08/24/2012 at 14:35:32 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Mama - MAMA-PC # Boot Mode : Normal # Running from : C:\Users\Mama\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Mama\AppData\Local\Babylon Folder Found : C:\Users\Mama\AppData\Local\Conduit Folder Found : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Folder Found : C:\Users\Mama\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\Mama\AppData\LocalLow\Conduit Folder Found : C:\Users\Mama\AppData\LocalLow\IMVU_Inc Folder Found : C:\Users\Mama\AppData\LocalLow\PriceGong Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\ConduitCommon Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\CT2612669 Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\{90b49673-5506-483e-b92b-ca0265bd9ca8} Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\ffxtlbr@babylon.com Folder Found : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\plugin@yontoo.com Folder Found : C:\ProgramData\Ask Folder Found : C:\ProgramData\Babylon Folder Found : C:\ProgramData\Tarma Installer Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Found : C:\Program Files (x86)\Conduit File Found : C:\user.js ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2612669 Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\DealPly Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKCU\Software\Google\Chrome\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\StartSearch Key Found : HKLM\SOFTWARE\Babylon Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\DealPly Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Found : HKLM\SOFTWARE\IMVU_Inc Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly [x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit [x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong [x64] Key Found : HKCU\Software\AppDataLow\Toolbar [x64] Key Found : HKCU\Software\Conduit [x64] Key Found : HKCU\Software\DealPly [x64] Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje [x64] Key Found : HKCU\Software\Google\Chrome\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKCU\Software\StartSearch [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Found : HKLM\SOFTWARE\Tarma Installer ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Found : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A19F5EBF-E163-4D4F-B7BD-33149BF756CC} Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DAAFEE7-F776-44CA-934E-86BF68F51FDC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE9004AE-D100-498D-8972-7CC67921AB90} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A19F5EBF-E163-4D4F-B7BD-33149BF756CC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{90B49673-5506-483E-B92B-CA0265BD9CA8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{90B49673-5506-483E-B92B-CA0265BD9CA8} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{90B49673-5506-483E-B92B-CA0265BD9CA8} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{90B49673-5506-483E-B92B-CA0265BD9CA8} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=109958&tt=220512_53all&babsrc=NT_ss&mntrId=96364411000000000000b2749f83086c -\\ Mozilla Firefox v [Unable to get version] Profile name : default File : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\prefs.js Found : user_pref("CT2612669..clientLogIsEnabled", false); Found : user_pref("CT2612669..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Found : user_pref("CT2612669..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Found : user_pref("CT2612669.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Found : user_pref("CT2612669.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2612669.BrowserCompStateIsOpen_129482420034282070", true); Found : user_pref("CT2612669.BrowserCompStateIsOpen_129683190780749804", true); Found : user_pref("CT2612669.CTID", "CT2612669"); Found : user_pref("CT2612669.CurrentServerDate", "25-3-2012"); Found : user_pref("CT2612669.DSInstall", false); Found : user_pref("CT2612669.DialogsAlignMode", "LTR"); Found : user_pref("CT2612669.DialogsGetterLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.DownloadReferralCookieData", ""); Found : user_pref("CT2612669.FeedLastCount129206864782289142", 23); Found : user_pref("CT2612669.FeedPollDate129206864782914144", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.FeedTTL129206864782914144", 40); Found : user_pref("CT2612669.FirstServerDate", "25-2-2012"); Found : user_pref("CT2612669.FirstTime", true); Found : user_pref("CT2612669.FirstTimeFF3", true); Found : user_pref("CT2612669.FixPageNotFoundErrors", true); Found : user_pref("CT2612669.GroupingServerCheckInterval", 1440); Found : user_pref("CT2612669.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2612669.HPInstall", false); Found : user_pref("CT2612669.HasUserGlobalKeys", true); Found : user_pref("CT2612669.HomePageProtectorEnabled", false); Found : user_pref("CT2612669.HomepageBeforeUnload", "hxxp://start.icq.com/sk27211/"); Found : user_pref("CT2612669.Initialize", true); Found : user_pref("CT2612669.InitializeCommonPrefs", true); Found : user_pref("CT2612669.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2612669.InstallationId", "ConduitNSISIntegration"); Found : user_pref("CT2612669.InstallationType", "ConduitXPEIntegration"); Found : user_pref("CT2612669.InstalledDate", "Fri Feb 24 2012 23:23:05 GMT+0100"); Found : user_pref("CT2612669.IsAlertDBUpdated", true); Found : user_pref("CT2612669.IsGrouping", false); Found : user_pref("CT2612669.IsInitSetupIni", true); Found : user_pref("CT2612669.IsMulticommunity", false); Found : user_pref("CT2612669.IsOpenThankYouPage", false); Found : user_pref("CT2612669.IsOpenUninstallPage", true); Found : user_pref("CT2612669.LanguagePackLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2612669.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Found : user_pref("CT2612669.LastLogin_3.10.0.1", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.LastLogin_3.9.0.3", "Thu Mar 08 2012 16:20:35 GMT+0100"); Found : user_pref("CT2612669.LatestVersion", "3.10.0.1"); Found : user_pref("CT2612669.Locale", "en"); Found : user_pref("CT2612669.MCDetectTooltipHeight", "83"); Found : user_pref("CT2612669.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2612669.MCDetectTooltipWidth", "295"); Found : user_pref("CT2612669.MyStuffEnabledAtInstallation", false); Found : user_pref("CT2612669.OriginalFirstVersion", "3.9.0.3"); Found : user_pref("CT2612669.SHRINK_TOOLBAR", 1); Found : user_pref("CT2612669.SearchCaption", "IMVU Inc Customized Web Search"); Found : user_pref("CT2612669.SearchEngineBeforeUnload", "ICQ Search"); Found : user_pref("CT2612669.SearchFromAddressBarIsInit", true); Found : user_pref("CT2612669.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Found : user_pref("CT2612669.SearchInNewTabEnabled", true); Found : user_pref("CT2612669.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2612669.SearchInNewTabLastCheckTime", "Sun Mar 25 2012 20:12:36 GMT+0200"); Found : user_pref("CT2612669.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Found : user_pref("CT2612669.SearchProtectorEnabled", false); Found : user_pref("CT2612669.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2612669.SendProtectorDataViaLogin", true); Found : user_pref("CT2612669.ServiceMapLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.SettingsLastCheckTime", "Sun Mar 25 2012 20:12:36 GMT+0200"); Found : user_pref("CT2612669.SettingsLastUpdate", "1330961344"); Found : user_pref("CT2612669.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2612669&SearchSource=13"); Found : user_pref("CT2612669.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2612669.ThirdPartyComponentsLastCheck", "Tue Mar 20 2012 14:31:55 GMT+0100"); Found : user_pref("CT2612669.ThirdPartyComponentsLastUpdate", "1312887586"); Found : user_pref("CT2612669.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2612669.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2612669"); Found : user_pref("CT2612669.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Found : user_pref("CT2612669.UserID", "UN11380762161109348"); Found : user_pref("CT2612669.ValidationData_Toolbar", 2); Found : user_pref("CT2612669.alertChannelId", "1005466"); Found : user_pref("CT2612669.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] Found : user_pref("CT2612669.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] Found : user_pref("CT2612669.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] Found : user_pref("CT2612669.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...] Found : user_pref("CT2612669.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] Found : user_pref("CT2612669.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] Found : user_pref("CT2612669.backendstorage./9b+7e06cg5el8:", "6E6D6E70716F75737477"); Found : user_pref("CT2612669.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473747677757B797A7D242F4B4947[...] Found : user_pref("CT2612669.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] Found : user_pref("CT2612669.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] Found : user_pref("CT2612669.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] Found : user_pref("CT2612669.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...] Found : user_pref("CT2612669.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] Found : user_pref("CT2612669.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] Found : user_pref("CT2612669.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] Found : user_pref("CT2612669.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] Found : user_pref("CT2612669.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] Found : user_pref("CT2612669.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] Found : user_pref("CT2612669.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] Found : user_pref("CT2612669.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] Found : user_pref("CT2612669.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] Found : user_pref("CT2612669.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] Found : user_pref("CT2612669.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] Found : user_pref("CT2612669.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] Found : user_pref("CT2612669.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] Found : user_pref("CT2612669.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] Found : user_pref("CT2612669.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] Found : user_pref("CT2612669.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Found : user_pref("CT2612669.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] Found : user_pref("CT2612669.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] Found : user_pref("CT2612669.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] Found : user_pref("CT2612669.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] Found : user_pref("CT2612669.backendstorage./9b-0?3g>d", "3C6A6B403F3E6D747A71467A7A20754A7C4D257E4F537D2A21[...] Found : user_pref("CT2612669.backendstorage./9b-0?3g@6:5;", ""); Found : user_pref("CT2612669.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); Found : user_pref("CT2612669.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Found : user_pref("CT2612669.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); Found : user_pref("CT2612669.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...] Found : user_pref("CT2612669.backendstorage./9b5ba==9cjag", "686B3F40716C74417A42737A48744B7E79207A4D50"); Found : user_pref("CT2612669.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6E70716F75737573797675"); Found : user_pref("CT2612669.backendstorage./9b9643g3/9e", "6A"); Found : user_pref("CT2612669.backendstorage./9b<:222h64<", "393F352F3E"); Found : user_pref("CT2612669.backendstorage./9b=+03eh8h8j?:", "4443"); Found : user_pref("CT2612669.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Found : user_pref("CT2612669.backendstorage./9b?b0d:8aj62<h", "6D"); Found : user_pref("CT2612669.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Found : user_pref("CT2612669.backendstorage.2612669a129684723478947121000000paramsgk3", "7B22757064617465526[...] Found : user_pref("CT2612669.backendstorage.shoppingapp.gk.exipres", "467269204D617220333020323031322032303A[...] Found : user_pref("CT2612669.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79"); Found : user_pref("CT2612669.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Found : user_pref("CT2612669.globalFirstTimeInfoLastCheckTime", "Tue Mar 20 2012 14:31:57 GMT+0100"); Found : user_pref("CT2612669.homepageProtectorEnableByLogin", true); Found : user_pref("CT2612669.initDone", true); Found : user_pref("CT2612669.isAppTrackingManagerOn", true); Found : user_pref("CT2612669.myStuffEnabled", true); Found : user_pref("CT2612669.myStuffPublihserMinWidth", 400); Found : user_pref("CT2612669.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Found : user_pref("CT2612669.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2612669.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Found : user_pref("CT2612669.oldAppsList", "129170380618247103,129170380618247104,111,129174085518698803,129[...] Found : user_pref("CT2612669.revertSettingsEnabled", true); Found : user_pref("CT2612669.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2612669.searchProtectorEnableByLogin", true); Found : user_pref("CT2612669.testingCtid", ""); Found : user_pref("CT2612669.toolbarAppMetaDataLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CT2612669.toolbarContextMenuLastCheckTime", "Mon Mar 12 2012 23:05:51 GMT+0100"); Found : user_pref("CT2612669.usagesFlag", 2); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2612669/CT2612669[...] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1005466/1001181/DE", "\"0\"[...] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2612669", [...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2612669",[...] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"15c[...] Found : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20566976.xml", "\"dcf78fa5b9839849dc2[...] Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Mama\\AppData\\Roaming\\Mozilla\\Fi[...] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1"); Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...] Found : user_pref("CommunityToolbar.ToolbarsList", "CT2612669"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2612669"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2612669"); Found : user_pref("CommunityToolbar.globalUserId", "ccefb025-fdd0-4f8e-a007-a0bffa799a68"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2612669"); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Mar 20 2012 14:31:5[...] Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Mar 20 2012 14:32:05 GMT+010[...] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "5612732b-9d89-4be9-b8c3-f064eb595e89"); Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://start.icq.com/sk27211/"); Found : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search"); Found : user_pref("CommunityToolbar.twitter.user_20566976.LastCheckTime", "Tue Mar 20 2012 14:32:56 GMT+0100[...] Found : user_pref("extensions.BabylonToolbar.admin", false); Found : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar.babExt", ""); Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=110000"); Found : user_pref("extensions.BabylonToolbar.bbDpng", 25); Found : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Found : user_pref("extensions.BabylonToolbar.dfltSrch", false); Found : user_pref("extensions.BabylonToolbar.hmpg", false); Found : user_pref("extensions.BabylonToolbar.id", "96364411000000000000b2749f83086c"); Found : user_pref("extensions.BabylonToolbar.instlDay", "15382"); Found : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar.lastDP", 25); Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.174:47:33"); Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "7.0"); Found : user_pref("extensions.BabylonToolbar.newTab", true); Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb"); Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar.propectorlck", 71259157); Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar.ptch_0717", true); Found : user_pref("extensions.BabylonToolbar.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.174:47:33"); Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110000"); Found : user_pref("extensions.BabylonToolbar_i.hardId", "96364411000000000000b2749f83086c"); Found : user_pref("extensions.BabylonToolbar_i.id", "96364411000000000000b2749f83086c"); Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15382"); Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar_i.newTab", false); Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.174:47:33"); Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Found : user_pref("extensions.enabledAddons", "plugin@yontoo.com:1.20.00,{800b5000-a755-47e1-992b-48a1c1357f[...] -\\ Google Chrome v21.0.1180.83 File : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "homepage": "hxxp://search.babylon.com/?AF=109958&babsrc=HP_ss&mntrId=96364411000000000000b274[...] Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=109958&tt=220512_53all&ba[...] Found : "icon_url": "hxxp://www.babylon.com/favicon.ico", Found : "keyword": "babylon.com", Found : "name": "Search the web (Babylon)", Found : "search_url": "hxxp://search.babylon.com/?q={searchTerms}&AF=110000&babsrc=SP_ss&mntrId=963644[...] Found : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT261266[...] Found : "scriptable_host": [ "hxxp://*/*", "hxxp://cap1.conduit-apps.com/Apps/jdownloader/jdC[...] Found : "matches": [ "hxxp://cap1.conduit-apps.com/Apps/jdownloader/jdController.html*", "[...] Found : "path": "plugins/ConduitChromeApiPlugin.dll", Found : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT317698[...] Found : "homepage": "hxxp://search.babylon.com/?AF=109958&babsrc=HP_ss&mntrId=96364411000000000000b2749f8[...] Found : "search.babylon.com": 0.5227587223052979, Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=109958&tt=220512_53all&babsr[...] ************************* AdwCleaner[R1].txt - [32125 octets] - [24/08/2012 14:35:32] ########## EOF - C:\AdwCleaner[R1].txt - [32254 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Okay also einmal die Logdatei für den AdwCleaner : # AdwCleaner v1.801 - Logfile created 08/24/2012 at 18:42:07 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Mama - MAMA-PC # Boot Mode : Normal # Running from : C:\Users\Mama\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Mama\AppData\Local\Babylon Folder Deleted : C:\Users\Mama\AppData\Local\Conduit Folder Deleted : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Folder Deleted : C:\Users\Mama\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\Mama\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Mama\AppData\LocalLow\IMVU_Inc Folder Deleted : C:\Users\Mama\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\ConduitCommon Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\CT2612669 Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\{90b49673-5506-483e-b92b-ca0265bd9ca8} Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\ffxtlbr@babylon.com Folder Deleted : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\extensions\plugin@yontoo.com Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Deleted : C:\Program Files (x86)\Conduit File Deleted : C:\user.js ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2612669 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DealPly Key Deleted : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKCU\Software\Google\Chrome\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\StartSearch Key Deleted : HKLM\SOFTWARE\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\DealPly Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndkkhdppcfchlghnlhifennhcadbnfld Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\IMVU_Inc Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Deleted : HKLM\SOFTWARE\Tarma Installer ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A19F5EBF-E163-4D4F-B7BD-33149BF756CC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DAAFEE7-F776-44CA-934E-86BF68F51FDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE9004AE-D100-498D-8972-7CC67921AB90} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A19F5EBF-E163-4D4F-B7BD-33149BF756CC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{90B49673-5506-483E-B92B-CA0265BD9CA8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{90B49673-5506-483E-B92B-CA0265BD9CA8} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=109958&tt=220512_53all&babsrc=NT_ss&mntrId=96364411000000000000b2749f83086c --> hxxp://www.google.com -\\ Mozilla Firefox v [Unable to get version] Profile name : default File : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\prefs.js C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\qbeyygmf.default\user.js ... Deleted ! Deleted : user_pref("CT2612669..clientLogIsEnabled", false); Deleted : user_pref("CT2612669..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Deleted : user_pref("CT2612669..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Deleted : user_pref("CT2612669.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT2612669.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT2612669.BrowserCompStateIsOpen_129482420034282070", true); Deleted : user_pref("CT2612669.BrowserCompStateIsOpen_129683190780749804", true); Deleted : user_pref("CT2612669.CTID", "CT2612669"); Deleted : user_pref("CT2612669.CurrentServerDate", "25-3-2012"); Deleted : user_pref("CT2612669.DSInstall", false); Deleted : user_pref("CT2612669.DialogsAlignMode", "LTR"); Deleted : user_pref("CT2612669.DialogsGetterLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.DownloadReferralCookieData", ""); Deleted : user_pref("CT2612669.FeedLastCount129206864782289142", 23); Deleted : user_pref("CT2612669.FeedPollDate129206864782914144", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.FeedTTL129206864782914144", 40); Deleted : user_pref("CT2612669.FirstServerDate", "25-2-2012"); Deleted : user_pref("CT2612669.FirstTime", true); Deleted : user_pref("CT2612669.FirstTimeFF3", true); Deleted : user_pref("CT2612669.FixPageNotFoundErrors", true); Deleted : user_pref("CT2612669.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT2612669.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT2612669.HPInstall", false); Deleted : user_pref("CT2612669.HasUserGlobalKeys", true); Deleted : user_pref("CT2612669.HomePageProtectorEnabled", false); Deleted : user_pref("CT2612669.HomepageBeforeUnload", "hxxp://start.icq.com/sk27211/"); Deleted : user_pref("CT2612669.Initialize", true); Deleted : user_pref("CT2612669.InitializeCommonPrefs", true); Deleted : user_pref("CT2612669.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT2612669.InstallationId", "ConduitNSISIntegration"); Deleted : user_pref("CT2612669.InstallationType", "ConduitXPEIntegration"); Deleted : user_pref("CT2612669.InstalledDate", "Fri Feb 24 2012 23:23:05 GMT+0100"); Deleted : user_pref("CT2612669.IsAlertDBUpdated", true); Deleted : user_pref("CT2612669.IsGrouping", false); Deleted : user_pref("CT2612669.IsInitSetupIni", true); Deleted : user_pref("CT2612669.IsMulticommunity", false); Deleted : user_pref("CT2612669.IsOpenThankYouPage", false); Deleted : user_pref("CT2612669.IsOpenUninstallPage", true); Deleted : user_pref("CT2612669.LanguagePackLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT2612669.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Deleted : user_pref("CT2612669.LastLogin_3.10.0.1", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.LastLogin_3.9.0.3", "Thu Mar 08 2012 16:20:35 GMT+0100"); Deleted : user_pref("CT2612669.LatestVersion", "3.10.0.1"); Deleted : user_pref("CT2612669.Locale", "en"); Deleted : user_pref("CT2612669.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT2612669.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT2612669.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT2612669.MyStuffEnabledAtInstallation", false); Deleted : user_pref("CT2612669.OriginalFirstVersion", "3.9.0.3"); Deleted : user_pref("CT2612669.SHRINK_TOOLBAR", 1); Deleted : user_pref("CT2612669.SearchCaption", "IMVU Inc Customized Web Search"); Deleted : user_pref("CT2612669.SearchEngineBeforeUnload", "ICQ Search"); Deleted : user_pref("CT2612669.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT2612669.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] Deleted : user_pref("CT2612669.SearchInNewTabEnabled", true); Deleted : user_pref("CT2612669.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT2612669.SearchInNewTabLastCheckTime", "Sun Mar 25 2012 20:12:36 GMT+0200"); Deleted : user_pref("CT2612669.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Deleted : user_pref("CT2612669.SearchProtectorEnabled", false); Deleted : user_pref("CT2612669.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT2612669.SendProtectorDataViaLogin", true); Deleted : user_pref("CT2612669.ServiceMapLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.SettingsLastCheckTime", "Sun Mar 25 2012 20:12:36 GMT+0200"); Deleted : user_pref("CT2612669.SettingsLastUpdate", "1330961344"); Deleted : user_pref("CT2612669.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2612669&SearchSource=13"); Deleted : user_pref("CT2612669.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT2612669.ThirdPartyComponentsLastCheck", "Tue Mar 20 2012 14:31:55 GMT+0100"); Deleted : user_pref("CT2612669.ThirdPartyComponentsLastUpdate", "1312887586"); Deleted : user_pref("CT2612669.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT2612669.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2612669"); Deleted : user_pref("CT2612669.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Deleted : user_pref("CT2612669.UserID", "UN11380762161109348"); Deleted : user_pref("CT2612669.ValidationData_Toolbar", 2); Deleted : user_pref("CT2612669.alertChannelId", "1005466"); Deleted : user_pref("CT2612669.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e06cg5el8:", "6E6D6E70716F75737477"); Deleted : user_pref("CT2612669.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473747677757B797A7D242F4B4947[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] Deleted : user_pref("CT2612669.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] Deleted : user_pref("CT2612669.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] Deleted : user_pref("CT2612669.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] Deleted : user_pref("CT2612669.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] Deleted : user_pref("CT2612669.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] Deleted : user_pref("CT2612669.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] Deleted : user_pref("CT2612669.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] Deleted : user_pref("CT2612669.backendstorage./9b-0?3g>d", "3C6A6B403F3E6D747A71467A7A20754A7C4D257E4F537D2A21[...] Deleted : user_pref("CT2612669.backendstorage./9b-0?3g@6:5;", ""); Deleted : user_pref("CT2612669.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); Deleted : user_pref("CT2612669.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] Deleted : user_pref("CT2612669.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); Deleted : user_pref("CT2612669.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...] Deleted : user_pref("CT2612669.backendstorage./9b5ba==9cjag", "686B3F40716C74417A42737A48744B7E79207A4D50"); Deleted : user_pref("CT2612669.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6E70716F75737573797675"); Deleted : user_pref("CT2612669.backendstorage./9b9643g3/9e", "6A"); Deleted : user_pref("CT2612669.backendstorage./9b<:222h64<", "393F352F3E"); Deleted : user_pref("CT2612669.backendstorage./9b=+03eh8h8j?:", "4443"); Deleted : user_pref("CT2612669.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] Deleted : user_pref("CT2612669.backendstorage./9b?b0d:8aj62<h", "6D"); Deleted : user_pref("CT2612669.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Deleted : user_pref("CT2612669.backendstorage.2612669a129684723478947121000000paramsgk3", "7B22757064617465526[...] Deleted : user_pref("CT2612669.backendstorage.shoppingapp.gk.exipres", "467269204D617220333020323031322032303A[...] Deleted : user_pref("CT2612669.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79"); Deleted : user_pref("CT2612669.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Deleted : user_pref("CT2612669.globalFirstTimeInfoLastCheckTime", "Tue Mar 20 2012 14:31:57 GMT+0100"); Deleted : user_pref("CT2612669.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT2612669.initDone", true); Deleted : user_pref("CT2612669.isAppTrackingManagerOn", true); Deleted : user_pref("CT2612669.myStuffEnabled", true); Deleted : user_pref("CT2612669.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT2612669.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Deleted : user_pref("CT2612669.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT2612669.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Deleted : user_pref("CT2612669.oldAppsList", "129170380618247103,129170380618247104,111,129174085518698803,129[...] Deleted : user_pref("CT2612669.revertSettingsEnabled", true); Deleted : user_pref("CT2612669.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT2612669.searchProtectorEnableByLogin", true); Deleted : user_pref("CT2612669.testingCtid", ""); Deleted : user_pref("CT2612669.toolbarAppMetaDataLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CT2612669.toolbarContextMenuLastCheckTime", "Mon Mar 12 2012 23:05:51 GMT+0100"); Deleted : user_pref("CT2612669.usagesFlag", 2); Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2612669/CT2612669[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1005466/1001181/DE", "\"0\"[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2612669", [...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2612669",[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"15c[...] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20566976.xml", "\"dcf78fa5b9839849dc2[...] Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Mama\\AppData\\Roaming\\Mozilla\\Fi[...] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1"); Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...] Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2612669"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2612669"); Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2612669"); Deleted : user_pref("CommunityToolbar.globalUserId", "ccefb025-fdd0-4f8e-a007-a0bffa799a68"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2612669"); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Mar 20 2012 14:31:5[...] Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Mar 20 2012 14:32:05 GMT+010[...] Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Mar 25 2012 20:12:37 GMT+0200"); Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "5612732b-9d89-4be9-b8c3-f064eb595e89"); Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://start.icq.com/sk27211/"); Deleted : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search"); Deleted : user_pref("CommunityToolbar.twitter.user_20566976.LastCheckTime", "Tue Mar 20 2012 14:32:56 GMT+0100[...] Deleted : user_pref("extensions.BabylonToolbar.admin", false); Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=110000"); Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 25); Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", false); Deleted : user_pref("extensions.BabylonToolbar.hmpg", false); Deleted : user_pref("extensions.BabylonToolbar.id", "96364411000000000000b2749f83086c"); Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15382"); Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar.lastDP", 25); Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.174:47:33"); Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "7.0"); Deleted : user_pref("extensions.BabylonToolbar.newTab", true); Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb"); Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 71259157); Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true); Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17"); Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.174:47:33"); Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17"); Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110000"); Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "96364411000000000000b2749f83086c"); Deleted : user_pref("extensions.BabylonToolbar_i.id", "96364411000000000000b2749f83086c"); Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15382"); Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false); Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.174:47:33"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Deleted : user_pref("extensions.enabledAddons", "plugin@yontoo.com:1.20.00,{800b5000-a755-47e1-992b-48a1c1357f[...] -\\ Google Chrome v21.0.1180.83 File : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "homepage": "hxxp://search.babylon.com/?AF=109958&babsrc=HP_ss&mntrId=96364411000000000000b274[...] Deleted : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=109958&tt=220512_53all&ba[...] Deleted : "icon_url": "hxxp://www.babylon.com/favicon.ico", Deleted : "keyword": "babylon.com", Deleted : "name": "Search the web (Babylon)", Deleted : "search_url": "hxxp://search.babylon.com/?q={searchTerms}&AF=110000&babsrc=SP_ss&mntrId=963644[...] Deleted : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT261266[...] Deleted : "scriptable_host": [ "hxxp://*/*", "hxxp://cap1.conduit-apps.com/Apps/jdownloader/jdC[...] Deleted : "matches": [ "hxxp://cap1.conduit-apps.com/Apps/jdownloader/jdController.html*", "[...] Deleted : "path": "plugins/ConduitChromeApiPlugin.dll", Deleted : "update_url": "hxxp://autoupdate.chromewebtb.conduit-services.com/?productId=CT317698[...] Deleted : "homepage": "hxxp://search.babylon.com/?AF=109958&babsrc=HP_ss&mntrId=96364411000000000000b2749f8[...] Deleted : "search.babylon.com": 0.5227587223052979, Deleted : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=109958&tt=220512_53all&babsr[...] ************************* AdwCleaner[R1].txt - [32172 octets] - [24/08/2012 14:35:32] AdwCleaner[S1].txt - [29608 octets] - [24/08/2012 18:42:07] ########## EOF - C:\AdwCleaner[S1].txt - [29737 octets] ########## Und einmal für Emisoft : Emsisoft Anti-Malware - Version 6.6 Letztes Update: 8/24/2012 7:15:31 PM Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 8/24/2012 7:17:02 PM c:\users\mama\appdata\roaming\windrvconfig.txt gefunden: Trace.File.agent!E1 C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\U\80000064.@ gefunden: Trojan.Win64!E2 C:\Windows\assembly\GAC_32\Desktop.ini gefunden: Trojan.Win32.Sirefef!E2 C:\Windows\assembly\GAC_64\Desktop.ini gefunden: Trojan.Win64!E2 Gescannt 678370 Gefunden 4 Scan Ende: 8/24/2012 8:06:09 PM Scan Zeit: 0:49:07 C:\Windows\Installer\{0db82727-358d-64d2-f921-45c55595c778}\U\80000064.@ Quarantäne Trojan.Win64!E2 c:\users\mama\appdata\roaming\windrvconfig.txt Quarantäne Trace.File.agent!E1 Quarantäne 2 C:\Windows\assembly\GAC_64\Desktop.ini Quarantäne Trojan.Win64!E2 C:\Windows\assembly\GAC_32\Desktop.ini Quarantäne Trojan.Win32.Sirefef!E2 |
Sehr gut! :daumenhoc Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
Ehm von wo soll ich die Funde Löschen ? :wtf: |
Quarantaene reicht auch (Emsi) |
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fa003c9f7197bd429e89ada7bfb52fe6 # end=stopped # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-25 07:18:45 # local_time=2012-08-25 09:18:45 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 66 94 520418 97549125 0 0 # compatibility_mode=8192 67108863 100 0 213 213 0 0 # scanned=48884 # found=0 # cleaned=0 # scan_time=3050 ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fa003c9f7197bd429e89ada7bfb52fe6 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-25 10:26:32 # local_time=2012-08-26 12:26:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 66 94 523545 97552252 0 0 # compatibility_mode=8192 67108863 100 0 3340 3340 0 0 # scanned=179727 # found=1 # cleaned=0 # scan_time=11190 ${Memory} a variant of Win32/Sirefef.EZ trojan 00000000000000000000000000000000 I |
Malware mit Combofix beseitigen Lade Combofix von einem der folgenden Download-Spiegel herunter: BleepingComputer.com - ForoSpyware.com und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig! Beachte die ausführliche Original-Anleitung. Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
Vorbereitung und wichtige Hinweise
Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen! |
Combofix Logfile: Code: ComboFix 12-08-25.04 - Mama 27.08.2012 0:06.3.4 - x64 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:06 Uhr. |
Copyright ©2000-2025, Trojaner-Board