![]() |
Leuter Werbung und Link im Internet! Moin Moin, habe seit vier Wochen ein Problem mit meinen Internetbrowser! Es werden manche Wörter als Link markiert der mich immer auf eine bestimmte Seite leitet und es werden immer weiter Fenster geöffnet! Hoffe es kann mir jemand Helfen! Vielen Dank im Voraus! |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Seit 4 Wochen hast du das Problem und du kommst erst heute zu uns? ;) So geht es los: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-10-2013 |
Servus, Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
AdwCleaner Logfile: Code: # AdwCleaner v3.011 - Bericht erstellt am 06/11/2013 um 16:56:13 |
Servus, ok, fehlen nur noch JRT und MBAM. :) |
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x86 Ran by Cornelius Brack on 06.11.2013 at 17:18:02,61 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1840268806-3441741845-855969553-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A81687A2-3ED7-4C36-8F7C-11BDB92560B3} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F1B50D84-7D86-4AA3-B49F-FD2D0C3C63F2} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Cornelius Brack\appdata\locallow\datamngr" Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{00D0DA83-C0A8-4A8D-8254-A92DD70BEF07} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{02EAB2C1-FD26-470B-A228-5884BC1D464A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{03232679-A5CB-48F6-A01F-F988081A339F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{033DDEAA-9627-447E-B1E7-FD4E48EEEEA8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{05EC2661-AD15-4896-A6AD-B867BBED8FBE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0659A02D-63E0-46C0-A044-3761B79818AA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{07159707-059E-4E1A-A336-362AA8BA5925} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{076E1FCE-C4CC-4900-AD59-A92FB5B6FF5B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{08F861CC-BD7A-4946-80E6-99ADFFF0EE1A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0946AF99-0154-4BBE-AA53-F9BED2070BAD} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0A9CA477-E112-449E-8E64-EBC988202CCD} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0C7381E9-5224-41D5-AEBE-751C68A11D06} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0C923516-9A45-433F-BFE3-384AE0D9DB21} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{0D1BAD3B-A765-427F-BE9E-4B2EC1542A10} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{10351F92-2F1A-43D6-BE1F-594FA20AE648} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{105B2448-E5CF-44BF-AA5F-8CC15C1B7B3B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{112048C9-FA18-4D89-B0DC-9AE2FCDB782A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{138C3FC7-2DD6-4FAC-9EB7-467C390FC964} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{13E9A0D3-199C-400E-BA4D-D4AB46EB189C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{161D29C3-70B6-48C8-81DF-89133BF8F68A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{165CE795-EF67-40C4-AC83-88A01430E456} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{16FFD4D4-C5E3-4E4F-A37D-525ADFC8B9F8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{171A6B25-488E-444A-84DB-7E829B04823B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{17D0F0FD-82FA-4644-89C5-0B0EB8F47046} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{17FBF03C-C3BA-4C4A-8DE6-5DD83BD8B25B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{189532F2-498E-4489-B669-FC9E879EA862} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{18A0C3EA-D8D5-4E29-AC11-E9C4543A7A60} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1944D08E-E451-4F8D-8EFB-BA281A4F4648} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1A94F014-5679-4D1A-80C4-E781D6C84217} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1C9A2EF3-D492-4F3B-B4E0-7E2CF315377C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1DE7AF91-EA77-48A0-8799-ED2B523C88BA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1EC7DEA9-E2FB-4D2E-A86B-A9897831BE1D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1EFA9C42-504B-4A8A-8655-AE9861B385D7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{1F77B03F-5D5A-43D1-843A-8AD2C7716F6A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{202C4F33-32FD-4E29-8376-D48D5088FD62} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{20E54E6B-6777-4F40-8F14-A2DE1472515A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{20ED81A2-1FD9-450F-88EF-842D2C18E837} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{213F31FA-EE7D-4AE2-BEC0-35449FE55928} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{22162881-2B12-4003-BDA0-94FCDBCFD013} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2243D33D-7B62-4812-BCDF-20320DE591EB} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{236D3A70-3E2A-4FF3-B381-0A0DCA9C9E27} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2724F3B6-9376-4321-A109-B9D21DE62923} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{28A75742-83FC-4906-A4B7-C7531AB67930} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{28CD431C-E99D-49BB-8D39-D58185B854DB} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{294CF411-7C04-43F0-A597-1A29A291033E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2A3F4490-BF88-46AF-8758-95E7AE03949B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2AD5BBC1-71EF-4CE7-85C8-0187DD155FEE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2AE2D1F2-40B8-42DF-A1BB-CC423FCE1901} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2AF081BF-EA39-4CC1-9C0E-C80C9C07875C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2B78C602-623B-4FC5-A6CC-9F0AC14DAD3E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2B978B90-2B88-4C59-B432-E4C4E31FFABF} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2CCB139F-80AA-42BC-B5EE-2727122A7B1D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2F583C48-0056-441C-8CFD-0FB99379B7B5} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2F724981-6A43-4C52-BAD1-9B057E874CFD} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{2FC36D4D-C0DF-4A17-87E1-248B3B052AE8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{34840E5C-FAF9-4551-BD47-B7DA7CBEC800} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3625CA02-7A68-4D39-85AA-B6C649A7494D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{390D1A3E-1145-4DBC-A2B5-49CF2DD2A198} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{397A6CEF-1FAE-47E4-9D02-946EDBDDBD22} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3A1B2C44-745C-456C-8E1A-0DA8EE84CFF4} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3A4DDC13-D706-4946-B96D-9437FFD52180} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3A64D769-7F75-4A7B-BE0C-FB1B69B3BC2A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3ACB9070-0DE8-4CB2-9574-113B97DBD28C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3C138F6D-C76A-4CA0-92C1-50F9D39A27DD} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3E299AE8-4054-4C80-833E-CA10F9FB151E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3E4FE714-5B65-4833-BB51-64C2AE1337FC} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{3EC0AAB7-8BE7-4685-8A02-F898A3A3655A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{40EB4867-284D-49D4-8B34-D685A79D2135} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4255AD77-A4D9-49DE-BEEC-3EE18B31C4D6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{42ADA8BD-A9E7-4A36-83A6-DF2725FE8209} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{43597959-C40E-43F6-BEF0-558FC74902FA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{43C34A67-27A8-4083-999C-767E58E76F43} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4501A210-826C-48A1-AD49-C2E07AAB876F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{452A4DC0-FD2B-4C14-9E4F-1C1AFA140BA1} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{45A3DE45-95DD-458D-9494-ED684A931BA2} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{47BA5771-DB45-413E-8649-F066E7B2A2A2} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{47C465C2-6E5C-4F09-B41B-335334A38E9A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{48429A49-10FA-4967-9BB0-6B5FB66C74D3} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{48453267-854F-4253-BF92-6919BDA0FF83} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4B448A25-B71B-4EB2-8FC8-715E1CA8F379} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4D17AB3F-5912-4A51-937B-02951AEE5934} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4E0C7695-6489-476D-A5F3-289DEB300043} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4E96A03E-0485-4FA5-B611-49B4DCE98F28} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{4F1B1519-E3AE-4BB2-81EF-D026B6124345} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{504FEB7C-D13B-4F36-895B-8A807FF79959} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{50D9DDC2-3B92-4190-A420-264ED0940FC6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{512A3252-9452-4F3F-BB56-07686E79BA7E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5257CD13-A9C2-4628-8F1F-FC613CC40792} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{533672DF-01BB-43FF-BF03-5AADB1DAE20C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{53B33895-C53D-45C7-81DC-91A6602278C9} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{53DAF8D1-F71B-4E4A-AC57-7C3459F72197} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{53FC97E9-0E0D-494E-8C2B-B958DC66F6DC} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5501EE3E-D1EB-453B-BAC8-C5DD9E627441} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{55FF682C-78EE-42C5-9A49-5B5883B2802C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{58544336-13DE-4E72-B795-BF0BEA41B88D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{58FF88F3-3ECF-48FA-A1D5-0C61D02D6E6E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5981BEC8-7B9C-4A50-8E4D-918E4EC07682} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5A7F7782-8F42-4EFD-851B-58D541DE9A16} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5A968330-5CE1-4981-BE8B-05C426C628F8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5BF43505-25DB-4B83-BABE-B49B9C7FD43D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5C3B4F97-C72C-48AB-9446-40FB479B6316} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5CAAFC53-FF08-483E-B368-AEF4E5BAE022} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5D6B5F80-F960-4568-84BB-19391B4D7FBA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5E788EC8-9C25-4DD1-B295-891F2E297856} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{5FDCD149-C6AC-4883-AF99-AE3E3410A27A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6295567A-0F90-4D24-89A9-E7D2DDE737F4} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{62FBF64F-C8D4-40E5-A460-5E699DAA146F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{644A7791-E6B9-476D-9F4E-BF1E2AB66D92} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6461C8DC-4024-4534-99AF-A02C40D6B9E7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{646D3C90-662D-40FD-A6BC-546E739917FE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{652DF534-A631-4F9B-9131-D4249C319EB8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{65E86C16-296C-4B8D-81F1-BC109D9F8481} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{66AD8FC0-0398-4174-B9C3-7573733BD546} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{68BABC77-4BEC-4517-98CA-21B2A0F24DB7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6ADB1501-D1B7-4D45-A939-E7E0E6866390} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6BD48D2D-8907-4E5A-82BF-AC5CA5D762A2} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6BDED18E-CFAF-4098-BA46-9BB43D0803DD} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6D24150F-3411-4207-85AE-B1B9DD306414} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{6FC0105D-A93A-4931-AF9B-5B9FB7278CC9} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{71AAF55F-651C-4F68-B20F-5D55B15052FB} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{73AF6664-B734-4288-8947-5360C6627254} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{75719078-69AA-47F6-BC6C-D8DDC65C5EED} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7835D768-783E-4EE0-A7F2-2E4AC1F2E9A3} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{793DFA78-B659-450B-9382-83310AEC88F8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7AC3478C-02B6-4187-B1FE-2975EDEF5637} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7C53A582-2E2A-4CED-BDB3-6EE614C4429F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7CB94ED6-4F52-4660-A8DF-D6CEA5A944C0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7CC6F984-2E0E-4B6F-B29D-ED32F3986BE6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7D0E9558-6B26-471C-A1E9-B5470516D2B7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{7FF2A375-7CEE-4BBB-AABB-FB8C4979A55A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{803B0AD0-46B7-448F-B5B6-F165BB805A15} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{81BF3458-F053-4D2B-8BDE-727E4A4A52D6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{822C8013-82A0-40DD-BD15-14D2BE0CA8E9} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{849A4F5B-7144-4A3C-B3A5-2C65E7FBEF9D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{851B4720-5049-4E2D-B4EE-7E6A166843E0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8530BDC1-E5F4-489F-BFEE-43E50C324025} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{87B0BD68-47E1-45C6-BD8F-681B2E093E8E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8801ABE8-CCDE-4B4C-9A4A-BA086E17F06E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{881D8B68-CCD2-4828-84D5-E6180A542DFE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8832D1A5-A5F3-4A43-91FD-B8273921FD18} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8884B0C0-6D1A-4AD0-BE2A-8716A3243C2D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{88F42BE1-A590-4FCD-ACF9-644D3919C082} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{89E495A3-46DB-4BED-88B1-FB93A5F858D7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{89FFFBBA-C7D6-4375-83D0-B6A1D98A7B2D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8AD4142B-BE28-49F2-9115-FC12DD1EEB31} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8DD6846E-C962-4FA7-BEC0-54A8301D714E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8EB13128-A233-40F9-9ED5-0891130CFCE7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8F3FDE70-4A90-4998-904E-64EE5550E0BA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8FDFA6CA-0FC6-4547-B7D2-529E275C9B68} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{8FE73627-C71B-4AFC-85AD-CCC5100DF4C3} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{93181B34-4EA9-4A14-9712-69438AF7371B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{95AB60F1-BF6F-415C-A080-244B608BA243} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9670E9A4-AC09-48A7-BD49-868CE25BDA18} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{969AD394-6B68-4820-8046-0A1C751DFF53} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{972BF8FE-5F82-4CA5-A543-A015A39B66DC} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{99DB7294-86DC-4A69-A848-FB5D80DEAD0C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9C21E614-10AC-4E06-8A1F-CA45110939A2} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9D43B103-7884-4064-9680-B05F4070509D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9EFC6564-3098-4A5A-9A56-7FF7221D6B4D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9F8BFE3E-E7F7-47F2-97C2-640F56B52DF8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{9FB88E4D-B4A6-42D9-8F30-C6DC8A198372} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A2E09A5B-BFBC-4C05-A0B0-016216BD2675} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A59EEFDA-8BAC-4A01-A1F9-42DE064AD008} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A65F413B-5461-4A01-870A-C8D198C1A1DF} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A66CC784-7D0D-4A95-B14C-98F7EAA29685} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A6B39AC0-1B5C-4957-93A7-33670542A26D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A8F58AD1-9926-472E-B441-65BE509ED6E5} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A9884592-0293-41D3-8553-AEAC63DFD500} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{A9C182CE-8E4A-45F0-AF2A-20752F10AC62} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AAFDAC55-AF68-4D5A-AC19-78CB79183496} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AD07A9C9-F1B3-4D02-87D8-A2B7C4D3468F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AD5FFE88-97F0-4E67-9D1D-4516A1F6436F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{ADC80FF8-B14B-45D9-9A15-A8C0FD833ED7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AE5224D8-F50D-4D41-89B3-D2C9FD2DAEF4} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AE5E77EC-62AC-445E-8695-9DBAA5213B5A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AF541C12-7CB8-4A57-8027-3CA96FE6E0C1} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{AFFC9E4B-D88D-4BC2-8E36-055109399122} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B001AD02-B6E8-4743-929F-FB42C0CAFA0A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B1263B55-6C72-48B7-B24B-00573909687D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B29E81E1-1B90-41FF-9778-5AEA93F66214} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B2DE226A-AC8A-47A4-8482-2F70F814E8BC} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B3165926-AAEC-4835-9AAB-24D67A2F2165} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B495356D-07BB-49C9-A0C6-799742266746} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B5C5A383-FE65-4162-8B71-65B1B4DCD0B1} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B6E2B000-C6C5-41AF-AADE-B346BAF0D43C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B74A971F-B4A3-4341-85A7-A928ECE2F5E2} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B794C75E-0245-43B7-A714-9426977991AF} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B83B9107-D7E2-4B1A-B779-F7E34950EF9B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{B877BD05-AC79-4202-A5C0-9EC5F7BABD59} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BA76546C-4198-40FA-AF37-2B45CCFE9302} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BB043798-D970-4CED-B6F3-04B7666EC38B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BB23ACD3-D359-4151-BE83-F891896D1F8E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BB53596A-A574-49DD-BF4E-287AA98DFA69} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BC313EB7-621E-4FD1-B2F7-F8D8F5D3246F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BE62AA3D-57BF-4D7E-8A14-94A19E7F9A67} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BF350EB8-99FB-4B52-927A-725FD70584F5} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BF73A4A1-E8B9-4F5D-AEBB-3EA3481A1019} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{BFD9A015-BEB2-4C30-B0B1-E9C439061571} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C1571248-1C94-49D0-A37A-88617045A53B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C2776D65-72BE-40A3-AF6B-C1B9C6FEF16B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C2D4CD01-933F-48F8-B747-BBA03DCD12B6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C3867C03-10D6-4963-85E9-18C602578127} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C3DAD344-6D31-4B83-B066-4883668759E5} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C3FBF054-31D4-4514-8591-3A0F5BF6EEA0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C50E8567-2BD3-409A-B282-36C431387816} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C5D24F33-DAFF-4192-9CEE-856536655A79} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C94140B2-D3DC-440B-9307-1FFF137B3B0C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{C95A97F1-BA1B-4EFB-A122-9F48D815AB92} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CBD4BB49-48E3-48F4-A467-10398F503805} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CC108A69-9491-49F2-B1D9-69D7FE20E356} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CC3A17C3-5E7C-4D4C-AD7A-62DA33FD7A2A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CCBAE61E-A872-4663-96DB-6DF84E962216} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CD7E4176-A65F-4B76-AA86-653228DFFE1E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CEAE69D8-08F6-4703-9EAA-3D430F16EB7B} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CFC9C808-CBEC-416A-9C9E-58E6E3D10D5F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{CFD852EB-8D28-4AED-8C34-4D1AEAE22965} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D13802D0-0D81-48F3-AB64-78E9422C4BD8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D590F060-F7E3-40B6-9C02-9D265AD11F4E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D5AD74E3-F320-47B5-B6AF-D886471D48CA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D5B7CF9E-7BED-43E6-8AC4-CF007A045B3A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D617253A-0CEA-4ED2-900E-22A351B2A817} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D862F6F0-41C7-4D78-A856-71EB9D788265} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D8ABA50E-16E5-4C57-894C-A95FEA0DD41F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D8BAF279-D5D8-4236-BC09-4C01D0C37916} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D97079FC-7452-4388-9AFA-517302BBA4D7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{D9EA6A04-D2C2-4F87-8482-543FE0B81A99} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{DC33E3D2-9539-4861-A96A-54670ABA2B12} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{DC750BA3-C7A6-48E9-923A-7D818F56F2A4} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{DCC7BF53-A54C-4261-9321-F047C14C05BB} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{DDCD1811-2D47-46B8-A56A-A57FAF20F386} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{DECC1120-36C6-4947-8C90-B18308A9873F} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E0B4013F-0706-44E9-A341-C802580F141D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E11F5E29-12AF-4C25-ADC4-3EEAA77DE5E5} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E1707F8F-F5C3-4250-9796-672B1B40F5FF} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E1DC4545-1C73-4A2C-A817-B4C355152913} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E1F9CB6A-2869-47A6-BD37-2C4D8C07A74C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E2BAA2D0-02B3-43F4-94E0-6CAAE406C58D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E2FAD2C6-A0F9-449D-91C5-F5080495D3F7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E31A47C9-43ED-4F4A-AC88-C792E9914391} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E3C6D71F-9A3C-4056-91E6-755307E81EFE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E3C8420B-DBF9-49FC-ADFE-18DEEBE70F83} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E4C75AE9-3809-4EC8-BCED-D5A891FD7198} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E5E35CE3-AFB2-46AA-846F-317AB229BC30} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E8815380-3382-4856-A775-1F4023D71A6E} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{E92705A5-23A6-4127-B203-3C93C5DCB4F8} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EA8C7229-C154-401E-926F-63C30CE935C1} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EAE360FB-3C10-42A1-831E-3917D17DECE9} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EAE4F5A5-9BF2-435E-B18F-5FE1A7BAF060} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EBED6FCD-6E28-4D87-9E46-8F473293DC83} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EE273068-6E52-4F90-999F-955A8FE7BDD0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EEC11D50-70C5-4064-9EA6-6F94B2832EAC} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EF0B68F0-E5E2-4CC6-A6CC-A54F39F809FE} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EF41AE6A-4A6E-4D77-8526-F691C08FB6DA} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{EFDF62C1-2946-412F-9AD0-E4493F873BB7} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F1026FDB-A55C-41F0-BFAB-3F10652049A6} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F36EB27B-625A-4C6D-96FA-E24D65039729} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F3B77B9B-FA77-49E8-AD08-BBB65776265C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F3DEEAE7-440C-483D-930A-7F21D6818ED0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F421CAE4-6696-4839-8FCC-7D417702788C} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F4C25E04-F465-4EA3-8F1E-60E83EB08A68} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F57EADBA-5318-4CA1-BFD5-9CACB36B0F2D} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F5EFCB93-97CB-48CA-A7B0-73E3C51FC58A} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F644FE63-DF7A-49D9-8C84-215A00AC69F0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F895D933-300D-4574-A0D6-03912F055809} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{F996052D-80B6-4CCB-8D60-FD1277764783} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FABF7F8D-8A37-4D2C-A515-70CF1C3608E9} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FB59CF27-D68C-4DD0-905A-23B9E113E228} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FDBFC2D8-64BC-4A40-B898-AFECDC49F3B0} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FFD19ADE-4B44-481B-8BA3-193EE5F7E152} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FFF491AB-BCC1-40C5-B7EA-72F8F3E46119} Successfully deleted: [Empty Folder] C:\Users\Cornelius Brack\appdata\local\{FFF94155-7BEA-4194-BF3C-32872ECA875B} ~~~ FireFox Successfully deleted: [File] C:\Users\Cornelius Brack\AppData\Roaming\mozilla\firefox\profiles\r4i8zxdo.default\extensions\trtv3@trtv.com.xpi Successfully deleted: [Folder] C:\Users\Cornelius Brack\AppData\Roaming\mozilla\firefox\profiles\r4i8zxdo.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com Successfully deleted the following from C:\Users\Cornelius Brack\AppData\Roaming\mozilla\firefox\profiles\r4i8zxdo.default\prefs.js user_pref("CT2269050./9b+7e3x305.from_oldbar.enc", "JH4vQT87NjM/R0Y/fUk+QS52MH4iJCE1LDdHS1lXS0pIWFhOXjdiVzpTXkkySzo9PztQR1JibGJddXhtdmp8UXxxdGFKY1JVV1JoX2p6LSYsLCR+LzIuaTUqLXl user_pref("CT2269050./9b+7ebx305.from_oldbar.enc", "JH4+OTFBMD0zRUA2Mn5KP0IvdzF7fSM1LDdWWUlITk9RUlxOTFVTW1RgWlo+aV5hTjdQOz1BVEtWdXVlbXNneW1tfFUhdXhlTmdSVFdrYm0tIiUuIGczKGokL3l user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.value", "%22var%20adsDe user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/833447eaff04548ccb80787286a7cad9_DE.value", "%22var%20ca user_pref("extensions.iminent.admin", false); user_pref("extensions.iminent.aflt", "orgnl"); user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}"); user_pref("extensions.iminent.autoRvrt", "false"); user_pref("extensions.iminent.dfltLng", ""); user_pref("extensions.iminent.excTlbr", false); user_pref("extensions.iminent.ffxUnstlRst", false); user_pref("extensions.iminent.id", "78f85ae5000000000000001d7e050599"); user_pref("extensions.iminent.instlDay", "15961"); user_pref("extensions.iminent.instlRef", ""); user_pref("extensions.iminent.newTab", false); user_pref("extensions.iminent.prdct", "iminent"); user_pref("extensions.iminent.prtnrId", "iminent"); user_pref("extensions.iminent.rvrt", "false"); user_pref("extensions.iminent.smplGrp", "none"); user_pref("extensions.iminent.tlbrId", "base"); user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q="); user_pref("extensions.iminent.vrsn", "1.8.25.0"); user_pref("extensions.iminent.vrsnTs", "1.8.25.014:49:41"); user_pref("extensions.iminent.vrsni", "1.8.25.0"); user_pref("iminent.LayoutId", "1"); user_pref("iminent.ShowThankyouPixel", "0"); user_pref("iminent.enabledAds", "false"); user_pref("iminent.registerToolbarEvent100", "1379152161835"); user_pref("iminent.registerToolbarEvent101", "1379149570375"); user_pref("iminent.registerToolbarEvent102", "1379346461612"); user_pref("iminent.registerToolbarEvent109", "1379346507120"); user_pref("iminent.registerToolbarEvent111", "1379346507127"); user_pref("iminent.registerToolbarEvent112", "1379346529527"); user_pref("iminent.registerToolbarEvent122", "1379346507135"); user_pref("iminent.version", "7.36.1.1"); user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.36.1.1\",\"InstallEventCTime\":1379076718440,\"InstallEvent\":\"True\"}"); Emptied folder: C:\Users\Cornelius Brack\AppData\Roaming\mozilla\firefox\profiles\r4i8zxdo.default\minidumps [205 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06.11.2013 at 17:22:07,41 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
Servus, fehlt nur noch die Logdatei von MBAM, dann kann es weitergehen. ;) |
Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.06.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16721 Cornelius Brack :: CORNELIUSBRACK [Administrator] 06.11.2013 17:27:22 mbam-log-2013-11-06 (17-27-22).txt Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|G:\|I:\|J:\|K:\|L:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 525298 Laufzeit: 2 Stunde(n), 44 Minute(n), 39 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 1 C:\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 6 C:\$Recycle.Bin\S-1-5-21-1840268806-3441741845-855969553-1001\$R9M1ESC.exe (PUP.Optional.OneClickDownloader.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-1840268806-3441741845-855969553-1001\$RAKFD5T.exe (PUP.Optional.OneClickDownloader.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-1840268806-3441741845-855969553-1001\$RPG775Z.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\ffxtlbr@babylon.com\components\FFHst.dll.vir (PUP.Optional.BabylonToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\OpenCandy\OpenCandy_480173DC476845F193740351D397D6D2\DLMgr3WrapperUniBlue.exe.vir (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Config.Msi\3908ec.rbf (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Endlich geschaft |
Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 --- --- --- Nach dem Scan gab es nur diesen einen bei FRST! |
Servus, Zitat:
|
SystemLook 30.07.11 by jpshortstuff Log created at 17:08 on 07/11/2013 by Cornelius Brack Administrator - Elevation successful ========== filefind ========== Searching for "*Iminent*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\iminent.xml.vir --a---- 1368 bytes [12:49 13/09/2013] [12:49 13/09/2013] 3FF67AC466058B3BE657AE19C55AB49E Searching for "*crossrider*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.57_0\crossriderManifest.json.vir --a---- 737 bytes [12:50 13/09/2013] [12:50 13/09/2013] C186E13766026B5B830BE81856461D25 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.57_0\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 5955 bytes [12:50 13/09/2013] [12:50 13/09/2013] A15314F10FA928B5C242EDDC4B91F503 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.57_0\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [12:50 13/09/2013] [12:50 13/09/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.57_0\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2220 bytes [12:50 13/09/2013] [12:50 13/09/2013] EC3226E86137F361EEEF8F1244A0225A C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.57_0\js\lib\crossriderAPI.js.vir --a---- 11366 bytes [12:50 13/09/2013] [12:50 13/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\extensionData\plugins\13_CrossriderAppUtils.js --a---- 7056 bytes [16:57 06/11/2013] [19:48 05/11/2013] 5C624086605726A12BFEC9C83F5E0CF2 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\extensionData\plugins\14_CrossriderUtils.js --a---- 12369 bytes [16:57 06/11/2013] [19:48 05/11/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\extensionData\plugins\78_CrossriderInfo.js --a---- 2234 bytes [16:57 06/11/2013] [19:48 05/11/2013] AFC19F46F2798D47DCE5568D444A571A C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\crossrider_statusbar.png --a---- 1361 bytes [16:57 06/11/2013] [19:48 05/11/2013] 8B1EB9CB80417EC0022D278A44AB1DC7 Searching for "*Babylon*" C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox\searchplugins\Babylon.xml.vir --a---- 2288 bytes [13:28 01/10/2013] [12:49 02/10/2011] F04CF51B7C79720A0E3502156AE3CCC4 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Babylon\Setup\Babylon.dat.vir --a---- 11198 bytes [12:49 02/10/2011] [21:27 08/08/2011] 0EA4B325AEDED4466C4CF6F8DAE88ECF C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\ffxtlbr@babylon.com\content\babylon.css.vir --a---- 2740 bytes [09:02 22/03/2011] [09:02 22/03/2011] 8473A23281D302880A9E6508321201BE C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\ffxtlbr@babylon.com\content\babylon.xul.vir --a---- 10941 bytes [10:37 11/07/2011] [10:37 11/07/2011] 97BF7CBF63DFFEEC117A1A7F788D71DA C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\ffxtlbr@babylon.com\defaults\preferences\babylon.js.vir --a---- 603 bytes [12:49 02/10/2011] [12:49 02/10/2011] AAD1CBE901A1BEE5689FBD50121F7D8C C:\Program Files\Microsoft Games\Age of Empires\campaign\Stimmen aus Babylon.cpn -r----- 913682 bytes [15:41 26/06/2013] [15:41 26/06/2013] 16E685EF1B62F4559D8C7DEBECE25F5F C:\Program Files\Microsoft Games\Age of Empires\data\Auf Leben und Tod Babylon.ai ------- 3686 bytes [15:41 26/06/2013] [15:41 26/06/2013] 70330ABC18E7EE52EFFD23D275020A8F C:\Program Files\Microsoft Games\Age of Empires\data\Babylon Schwertkämpfer.ai ------- 3467 bytes [15:41 26/06/2013] [15:41 26/06/2013] AD9B93F6EBC90543998B0B15DF62738F C:\Program Files\Microsoft Games\Age of Empires\data\Babylon Späher.ai ------- 3784 bytes [15:41 26/06/2013] [15:41 26/06/2013] 3AF7F90F21C6A984BF521090AE0E8304 C:\Program Files\Microsoft Games\Age of Empires\data2\Auf Leben und Tod Babylon Wasser.ai ------- 3923 bytes [15:44 26/06/2013] [15:44 26/06/2013] FCA0381BA745DBBE7E5334A88AE5C188 C:\Program Files\Microsoft Games\Age of Empires\data2\Auf Leben und Tod Babylon.ai ------- 3884 bytes [15:44 26/06/2013] [15:44 26/06/2013] 694C7031F3FB4C2B8F48D1759E013234 C:\Program Files\Microsoft Games\Age of Empires\data2\Babylon Schwertkämpfer.ai ------- 3959 bytes [15:44 26/06/2013] [15:44 26/06/2013] 8C2D6BA1A5A177E3F55533129B8EF144 C:\Program Files\Microsoft Games\Age of Empires\data2\Babylon Späher.ai ------- 4184 bytes [15:44 26/06/2013] [15:44 26/06/2013] 502C138C587D0CF5CD91162133C3A7BD C:\Program Files\Microsoft Games\Age of Empires\data2\Babylon Wasser.ai ------- 4445 bytes [15:44 26/06/2013] [15:44 26/06/2013] 1F44DD1124C3006C7B40ACB5A5D5151E C:\Users\Cornelius Brack\Music\Boney M\The Best of 10 Years\18 Rivers of Babylon (2).wma --a---- 1721094 bytes [16:32 10/02/2012] [07:33 08/02/2012] 6590485EE186A7A3A2C98D6E959D8891 C:\Users\Cornelius Brack\Music\Boney M\The Collection\01 Rivers of Babylon (2).wma --a---- 3884212 bytes [16:32 10/02/2012] [07:29 08/02/2012] DFCB3D589A81C24BEEBB2EF3220B2440 C:\Users\Cornelius Brack\Music\Various Artists\Bravo Hits Lato 2010 Disc 2\10 Babylon.wma --a---- 3710700 bytes [12:47 10/05/2012] [16:53 09/05/2012] 0248C2486A995B2C39A7EEA05E4A7582 Searching for "*ICQToolbar*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\content\icqtoolbar.js.vir --a---- 39929 bytes [13:34 25/11/2012] [12:48 24/07/2012] 64A8C19256690BE7190F083785445B44 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\content\icqtoolbar.xul.vir --a---- 17076 bytes [13:34 25/11/2012] [12:48 24/07/2012] 24B0816F4BB4AAC1C33C746962C93D1D C:\Programme\ICQ6Toolbar\ICQToolBar.dll --a---- 962808 bytes [18:19 08/12/2009] [13:01 16/08/2009] 772C626D0D9F340AA003F0E096B944E1 Searching for "*DriverScanner*" No files found. Searching for "*myfree codec*" No files found. Searching for "*Conduit*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon\cachedIcons\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_eq ualizer_dead.gif.vir --a---- 119 bytes [10:26 03/10/2011] [10:26 03/10/2011] A5220F9E01F826B14FB6E2C3F4ECE421 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon\cachedIcons\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_mi nimize.gif.vir --a---- 590 bytes [10:26 03/10/2011] [10:26 03/10/2011] EFFF305AD2F5AA1DB77F7786B490DC61 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon\cachedIcons\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_pl ay.gif.vir --a---- 676 bytes [10:26 03/10/2011] [10:26 03/10/2011] 40A8862A7994FA5600025CFDF7A8B81E C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon\cachedIcons\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_st op.gif.vir --a---- 703 bytes [10:26 03/10/2011] [10:26 03/10/2011] 253E89E7D1686D67C40FFB20FF78FEEF C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon\cachedIcons\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_vo l.gif.vir --a---- 712 bytes [10:26 03/10/2011] [10:26 03/10/2011] 5AB7200023489A910B502A6EEE23674D C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\CT2269050\conduit.xml.vir --a---- 921 bytes [18:11 05/11/2013] [15:26 06/11/2013] 148BF47826807CE510BB23312000797E C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\CT2269050\radio\Skins\http___storage_conduit_com_BankImages_RadioSkins_Bluenote_displa y_xml.xml.vir --a---- 5803 bytes [10:25 03/10/2011] [10:25 03/10/2011] 6BF50FDA3BC02B1E91036766306A9AB6 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayer.js.vir --a---- 36250 bytes [16:57 05/11/2013] [16:57 05/11/2013] B6892B634B7D453DBEACFC7988445110 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayerBack.js.vir --a---- 36250 bytes [16:57 05/11/2013] [16:57 05/11/2013] B6892B634B7D453DBEACFC7988445110 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayerFront.js.vir --a---- 36250 bytes [16:57 05/11/2013] [16:57 05/11/2013] B6892B634B7D453DBEACFC7988445110 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\aboutBox\images\conduit-logo-OLD.png.vir --a---- 1305 bytes [16:57 05/11/2013] [16:57 05/11/2013] 5F8EF9A0B050532B90B2645E9627E3F9 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\aboutBox\images\conduit-logo.png.vir --a---- 3926 bytes [16:57 05/11/2013] [16:57 05/11/2013] 04EC2FEFD3A417F86E983508778A00DD C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\options\images\conduit-logo.png.vir --a---- 3926 bytes [16:57 05/11/2013] [16:57 05/11/2013] 04EC2FEFD3A417F86E983508778A00DD C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\lib\log4conduit.jsm.vir --a---- 760 bytes [16:57 05/11/2013] [16:57 05/11/2013] 93898FE6A232C5FCD838D8168F65D802 C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Plugins\npConduitFirefoxPlugin.dll.vir --a---- 206624 bytes [16:57 05/11/2013] [16:57 05/11/2013] 9A14DD14D035B32824AF9DBAA4337991 C:\Program Files\Common Files\Apple\Mobile Device Support\iSyncConduit.dll --a---- 1206160 bytes [21:32 09/08/2012] [21:32 09/08/2012] 309B2B1B22EE841E49F62C7A6FB55E46 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayer.js --a---- 36250 bytes [16:57 06/11/2013] [16:57 06/11/2013] B6892B634B7D453DBEACFC7988445110 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayerBack.js --a---- 36250 bytes [16:57 06/11/2013] [16:57 06/11/2013] B6892B634B7D453DBEACFC7988445110 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\ConduitAbstractionLayerFront.js --a---- 36250 bytes [16:57 06/11/2013] [16:57 06/11/2013] B6892B634B7D453DBEACFC7988445110 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\aboutBox\images\conduit-logo-OLD.png --a---- 1305 bytes [16:57 06/11/2013] [16:57 06/11/2013] 5F8EF9A0B050532B90B2645E9627E3F9 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\aboutBox\images\conduit-logo.png --a---- 3926 bytes [16:57 06/11/2013] [16:57 06/11/2013] 04EC2FEFD3A417F86E983508778A00DD C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Chrome\CT2269050\content\tb\al\options\images\conduit-logo.png --a---- 3926 bytes [16:57 06/11/2013] [16:57 06/11/2013] 04EC2FEFD3A417F86E983508778A00DD C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\lib\log4conduit.jsm --a---- 760 bytes [16:57 06/11/2013] [16:57 06/11/2013] 93898FE6A232C5FCD838D8168F65D802 C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Plugins\npConduitFirefoxPlugin.dll --a---- 206624 bytes [16:58 06/11/2013] [16:58 06/11/2013] 9A14DD14D035B32824AF9DBAA4337991 Searching for "*OpenCandy*" No files found. Searching for "*searchresultstb*" No files found. Searching for "*SweetIM*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\SweetIm.xml.vir --a---- 3930 bytes [20:44 31/05/2010] [21:07 22/05/2011] A52ADC92FC90AD1E8FB99265426B797C C:\Dokumente und Einstellungen\CoCo\Cookies\coco@sweetim[4].txt --a---- 1187 bytes [22:29 01/03/2010] [22:29 01/03/2010] 36A4ACF54FCF865CE8E1F4220717D7EE C:\Dokumente und Einstellungen\CoCo\Cookies\coco@www.sweetim[1].txt --a---- 82 bytes [21:58 01/03/2010] [21:58 01/03/2010] 22D61054A854AB9AD0FBF1AD68F34A47 C:\Dokumente und Einstellungen\CoCo\Cookies\coco@www.sweetim[2].txt --a---- 74 bytes [21:58 01/03/2010] [21:58 01/03/2010] F36BFD5AF8A0661F72731DE652D3300F Searching for "*iLivid*" No files found. Searching for "*DataMngr*" C:\Users\Cornelius Brack\AppData\Local\Temp\jrt\datamngr_del.reg --a---- 386 bytes [16:04 06/11/2013] [03:41 22/08/2013] 95F42A3D43416D3BB978F174C83F494C ========== folderfind ========== Searching for "*Iminent*" No folders found. Searching for "*crossrider*" No folders found. Searching for "*Babylon*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Local\Babylon d------ [15:56 06/11/2013] C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Babylon d------ [15:56 06/11/2013] C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\ffxtlbr@babylon.com d------ [15:56 06/11/2013] C:\Program Files\ICQ7M\Xtraz\icq\theme\babylon_feed d------ [14:10 07/10/2012] Searching for "*ICQToolbar*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ICQToolbarData d------ [15:56 06/11/2013] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ\ICQToolbar d------ [18:19 08/12/2009] C:\Dokumente und Einstellungen\CoCo\Lokale Einstellungen\Temp\Low\ICQToolbar d------ [18:20 08/12/2009] Searching for "*DriverScanner*" No folders found. Searching for "*myfree codec*" C:\AdwCleaner\Quarantine\C\Program Files\myfree codec d------ [15:56 06/11/2013] C:\AdwCleaner\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec d------ [15:56 06/11/2013] Searching for "*Conduit*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\ConduitCommon d------ [15:56 06/11/2013] Searching for "*OpenCandy*" C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\OpenCandy d------ [15:56 06/11/2013] C:\AdwCleaner\Quarantine\C\Users\Cornelius Brack\AppData\Roaming\OpenCandy\OpenCandy_480173DC476845F193740351D397D6D2 d------ [15:56 06/11/2013] Searching for "*searchresultstb*" No folders found. Searching for "*SweetIM*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*DataMngr*" No folders found. ========== regfind ========== Searching for "iminent" [HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe] [HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe] "Path"="C:\Program Files\Iminent\Iminent.exe" [HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe] [HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe] "Path"="C:\Program Files\Iminent\Iminent.Messengers.exe" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\8d48999d_0] @="{0.0.0.00000000}.{df5527b5-74a9-47c3-b652-e521f6048512}|\Device\HarddiskVolume1\Program Files\Iminent\Iminent.Messengers.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C] "00000000000000000000000000000000"="C:\Program Files\Iminent\StartWeb.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD] "00000000000000000000000000000000"="C:\Program Files\Iminent\USearch.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287] "00000000000000000000000000000000"="C:\Program Files\Iminent\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7] "00000000000000000000000000000000"="C:\Program Files\Iminent\SearchTheWeb.xml" [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe] "Path"="C:\Program Files\Iminent\Iminent.exe" [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe] "Path"="C:\Program Files\Iminent\Iminent.Messengers.exe" [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\8d48999d_0] @="{0.0.0.00000000}.{df5527b5-74a9-47c3-b652-e521f6048512}|\Device\HarddiskVolume1\Program Files\Iminent\Iminent.Messengers.exe%b{00000000-0000-0000-0000-000000000000}" Searching for "crossrider" No data found. Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "ICQToolbar" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1840268806-3441741845-855969553-1001\Software\ICQ\ICQToolBar] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1840268806-3441741845-855969553-1001\Software\ICQ\ICQToolBar] Searching for "DriverScanner" No data found. Searching for "myfree codec" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{FD501041-8EBE-11CE-8183-00AA00577DA2}] "FriendlyName"="MyFree Codec Filter" Searching for "Conduit" [HKEY_CURRENT_USER\Software\Conduit] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="icq.com conduit.com sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966] "3C9969540349183469B424848DB7949F"="C:\Program Files\Common Files\Apple\Mobile Device Support\iSyncConduit.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966\3C9969540349183469B424848DB7949F] "File"="iSyncConduit.dll" [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Conduit] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="icq.com conduit.com sweetim.com" Searching for "OpenCandy" [HKEY_LOCAL_MACHINE\SOFTWARE\Cheat Engine\OpenCandy] [HKEY_LOCAL_MACHINE\SOFTWARE\Uniblue\Registry Booster2] "PurchaseUrl"="hxxp://www.liutilities.com/products/campaigns/rbtrial/adv/opencandy/9/" Searching for "searchresultstb" No data found. Searching for "SweetIM" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="icq.com conduit.com sweetim.com" [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="icq.com conduit.com sweetim.com" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\Cornelius Brack\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\Cornelius Brack\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\Cornelius Brack\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-1840268806-3441741845-855969553-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\Cornelius Brack\AppData\Local\iLivid] Searching for "DataMngr" No data found. Searching for " " [HKEY_LOCAL_MACHINE\SOFTWARE\Canon\WIA\Devices\CNQ2414] "ProductId"="IX-24145H " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{28C5D1F6-BE67-44D1-A345-31918118A52B}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{6948F4DF-FD98-41ea-979A-8364043D7FD6}"/> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{97D9239C-2BA3-4e1d-A710-B626DC4602A6}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </Rating> </Ratings>" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{4B452CE2-3E81-4740-8E26-3FC9BC9F3437}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}"> <Descriptor descriptorID="{9A82F712-5A9D-4409-9539-666BBCDFE12D}"/> <Descriptor descriptorID="{6AB026D3-FAD5-4a18-A53B-2CAFA358AE8F}"/> <Descriptor descriptorID="{1A796A5D-1E25-4862-9443-1550578FF4C4}"/> <Descriptor descriptorID="{E04AAEE8-950C-43c4-B75C-D87736A7FAFD}"/> <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/> </Rating> <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{068D40C4-7809-4c67-8FEA-DA457CF990B4}"/> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{CEC5DB5A-B4C9-4809-96C6-39CE715E4790} [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{8B6C5624-3E4C-4BB8-A4B9-1F32C4D89C8A}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}"> <Descriptor descriptorID="{9A82F712-5A9D-4409-9539-666BBCDFE12D}"/> <Descriptor descriptorID="{6AB026D3-FAD5-4a18-A53B-2CAFA358AE8F}"/> <Descriptor descriptorID="{1A796A5D-1E25-4862-9443-1550578FF4C4}"/> <Descriptor descriptorID="{E04AAEE8-950C-43c4-B75C-D87736A7FAFD}"/> <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/> </Rating> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{CEC5DB5A-B4C9-4809-96C6-39CE715E4790}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </Rating> <Rati [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{9F139328-9B00-448D-B775-17A5833DFD37}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{9236ED52-B5FE-4227-8EB3-353C0BDABECF}"/> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{464299D0-6D57-47e8-AA53-A849CBEA12CB}"/> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{7A53B0BE-B92D-4e8a-A11F-8E6F9F3C575B}"> <Descriptor descriptorID="{56C2626D-3794-473c-B57F-40D31D012C4C}"/> </Rating> <Rating ratingSystemID="{9AAFBACD-EAB9-4946-8BE8-C4D997927C81}" ratingID="{BB63F1DB-83FB-4790-ABE5-920E0AC864BD}"/> <Rating ratingSystemID="{5B39D1B8-ED49-4055-8A47-04B29A579AD6}" ratingID="{FCC61B08-1352-4e5b-9D96-986EAB2FC503}"/> <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" r [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{CB36002A-1329-4450-AA6D-83AEAB4741AF}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}"> <Descriptor descriptorID="{0CFCF432-3544-4f78-9426-07A36843E6BA}"/> <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/> </Rating> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{CEC5DB5A-B4C9-4809-96C6-39CE715E4790}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> <Descriptor descriptorID="{6AB00271-515B-4a4d-8A6E-9E66BF96A437}"/> <Descriptor descriptorID="{9C8680ED-C0A6-4700-ACDF-B24C979511E0}"/> </Rating> <Rating ratingSystemID="{9AAFBACD-EAB9-4946-8BE8-C4D997927C81}" ratingID="{CEC5DB5A-B4C9-4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{FCA7464C-E974-4A5A-9AA2-D26D2119251E}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{CEC5DB5A-B4C9-4809-96C6-39CE715E4790}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </Rating> <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{B3F8E60B-DF77-4104-88AC-F5919C64649A}"/> <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{997B7D18-2AFA-49dc-847B-0E8A69723040}"/> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}"> <Descriptor descriptorID="{9A82F712-5A9D-4409-9539-666BBCDFE12D}"/> <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/> </Rating> <R [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#0810240538A099&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_5.00#301506005BB93301&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SIGMATEL&PROD_MSCN&REV_0100#0002F68C81 304B15&0#] "DeviceDesc"="MSCN " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#0810240538A099&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_5.00#301506005BB93301&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SIGMATEL&PROD_MSCN&REV_0100#0002F68C81 304B15&0#] "DeviceDesc"="MSCN " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#0810240538A099&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_5.00#301506005BB93301&0 #] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SIGMATEL&PROD_MSCN&REV_0100#0002F6 8C81304B15&0#] "DeviceDesc"="MSCN " -= EOF =- FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 --- --- --- --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-10-2013 So jetzt alles geliefert und auch alles richtig gelesen :singsing: |
Servus, wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: start Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 31-10-2013 Ran by Cornelius Brack at 2013-11-08 09:41:04 Run:1 Running from C:\Users\Cornelius Brack\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** start URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-11.xml FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-12.xml FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin.gif FF SearchPlugin: C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin.src FF Extension: Plus-HD-2.2 - C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com FF Extension: DVDVideoSoftTB - C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} S3 dgderdrv; System32\drivers\dgderdrv.sys [x] S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [x] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ\ICQToolbar Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1840268806-3441741845-855969553-1001\Software\ICQ\ICQToolBar" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Conduit" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Cheat Engine\OpenCandy" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Uniblue\Registry Booster2" /f end ***************** HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} => Value deleted successfully. HKCR\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} => Value deleted successfully. HKCR\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} => Key not found. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-11.xml => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-12.xml => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-13.xml => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-14.xml => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin-15.xml => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin.gif => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\searchplugins\icqplugin.src => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com => Moved successfully. C:\Users\Cornelius Brack\AppData\Roaming\Mozilla\Firefox\Profiles\r4i8zxdo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Moved successfully. dgderdrv => Service deleted successfully. pccsmcfd => Service deleted successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ\ICQToolbar => Moved successfully. ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.Messengers.exe" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1840268806-3441741845-855969553-1001\Software\ICQ\ICQToolBar" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}" /f ========= FEHLER: Die L”schvorganganforderung wurde nur teilweise abgeschlossen. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Conduit" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Cheat Engine\OpenCandy" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Uniblue\Registry Booster2" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ==== End of Fixlog ==== Code: HitmanPro 3.7.8.208 all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3a6704590ac5a94c8767c55b6cf0ab3d # engine=15805 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-08 11:52:47 # local_time=2013-11-08 12:52:47 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3591 16777213 100 99 859031 146508152 0 0 # compatibility_mode=5893 16776574 100 94 10163412 135542758 0 0 # scanned=307705 # found=0 # cleaned=0 # scan_time=9979 Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Norton Internet Security Online WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (24.0) Google Chrome 29.0.1547.76 Google Chrome 30.0.1599.101 ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Moin Moin habe alles durchgeführt! ich glaube der PC müsste jetzt sauber sein! Gruß Coco |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:24 Uhr. |
Copyright ©2000-2025, Trojaner-Board