845fsdhv | 03.05.2015 16:09 | Hallo,
hier kommen die Logs. Code:
# AdwCleaner v4.202 - Logfile created 03/05/2015 at 16:46:29
# Updated 23/04/2015 by Xplode
# Database : 2015-04-23.1 [Local]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Sylvia - SYLVIA-JHPW1HHX
# Running from : G:\AdwCleaner_4.203.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Programme\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Anwendungsdaten\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Anwendungsdaten\MyAshampoo
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E2B992B0-804A-45DA-AAD0-8F8075176C9A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C65A354-1D79-4C65-A3FE-0B5553FF81F0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\MyAshampoo
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\MyAshampoo\toolbar
Key Deleted : HKLM\SOFTWARE\MyAshampoo
***** [ Web browsers ] *****
-\\ Internet Explorer v6.0.2900.5512
-\\ Mozilla Firefox v37.0.1 (x86 de)
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.CommunitiesChangesLastUrl", "hxxp://grouping.services.conduit.com/GroupingRequest.ctp?type=ToolbarsInfo&ctids=CT2481020,CT2481024,CT2481025,CT2481029,CT2481031,CT2481032,CT2481033[...]
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.SearchEngine", "Searchhxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2475029");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.ct2481020.SearchEngine", "Suchenhxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2481020&octid=EB_ORIGINAL_CTID&SearchSource=1");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CT2475029.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2431232/CT2431232", "\"88836c072cc81bc5dff4702dfdea491a3\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2481020/CT2475029", "\"1324548149\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825439/821247/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874426/870225/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874430/870228/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874431/870229/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874435/870233/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874437/870235/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874438/870236/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874439/870237/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874440/870238/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874441/870239/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874443/870241/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431232", "\"1367226698\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2481020", "\"1323698787\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de", "oIwsta2spzadhjRgiY1Nhw==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=es-es", "9UWicC1QufG0y8uU3vd0vg==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=es-es&ctid=CT2431232", "n8H4541pVwCdPLeb5omhbg==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de", "WiZSpHJzJ/uTUKvfHHyj/w==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=es-es", "znC1DUVfpP1W2B74ytFJRg==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=es-es&ctid=CT2431232", "O1ZRe2dN7gRzhYzEzZwBjA==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de", "9H/gICSaMqbmx+Gd+8W4Sg==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=es-es", "vU9YcV2GGaMgX3epCY7a+A==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=es-es&ctid=CT2431232", "74yhthvDPI+7cxfwBzmz0g==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de", "eJfMrdrGnhGHiiPiYjgAww==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=es-es", "Z/HZ+gZJLbYGvG+/nrCTxA==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=es-es&ctid=CT2431232", "OHnvZXrujCOjg92py8TzCw==");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"c70353cabc2ce1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"807dc126dd28cc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10.0.1", "\"4ead38b3e6bcd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.0.7", "\"4ead38b3e6bcd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16.0.100", "\"0343677cfb1cd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16.0.3", "\"0343677cfb1cd1:15a3\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"0343677cfb1cd1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.19.0.3", "\"2a1a0d7b586ce1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.20.0.4", "\"dfe74040abc2ce1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.0.12", "\"8028f138140cc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.0.10", "\"80ee9485875dcc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"6a637346d78ccc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.0.8", "\"6a637346d78ccc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.1.0", "\"6a637346d78ccc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.0.3", "\"801a319dd78ccc1:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2431232", "\"07766f5592f76b152ec9246ce6a0b574\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2475029", "\"567c96be3ef640e157660940cadc2edb\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=ct2481020&octid=CT2475029", "\"1321973191\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/ct2481020/CT2475029", "\"1311168835\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equalizer_dead.gif", "\"0678fe477ac91:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimize.gif", "\"046c7ab477ac91:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gif", "\"0484de117c4c91:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gif", "\"0e7a152347ac91:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif", "\"087c778347ac91:0\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"7e871e7510b21f05d3a07d64188add52\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"819b10a48a04e71d01aab6208f744e69\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=es-es", "\"8c81ee512d5fa5ee72ede6d3fb5d62fa\"");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.EngineOwner", "");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "myashampoo");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Dokumente und Einstellungen\\Sylvia\\Anwendungsdaten\\Mozilla\\Firefox\\Profiles\\rcdhlrwc.default\\conduitCommon\\modules\\3.20.0.4");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.20.0.4");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://chat.loke.com/", "800x598");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_ext_msg_key_9a90a631", "356x332");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_ext_msg_key_a88b614e", "356x332");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://s3-eu-west-1.amazonaws.com/tbe/974fed26-vistaprint.de.html", "402x342");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://s3-eu-west-1.amazonaws.com/tbev2/974fed26-default.html", "402x342");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://storage.conduit.com/MarketPlace/fd/c4/fde72b92-1bba-46f6-82b7-8b75c1dd9ec4//6a005e8b-1194-4f36-afe1-5afe9c954255.html", "620x731");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2475029");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "myashampoo");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2475029,CT2431232");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2475029,CT2431232");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2431232");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Jun 13 2011 19:07:43 GMT+0200");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sat Jun 25 2011 07:39:50 GMT+0200");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.locale", "en");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri Jun 24 2011 22:05:00 GMT+0200");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.alert.userId", "bd6e6f1f-fd5d-4af3-8a25-20d9f398dec2");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Mar 18 2011 13:22:48 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.globalUserId", "904923c5-c4f7-4601-b47b-b05cb20e4d39");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.killedEngine", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Nov 03 2013 15:46:41 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 07 2013 07:08:19 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 07 2013 07:08:08 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.notifications.userId", "27a3a4d2-4029-4096-9671-a337fe5296ea");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT2475029&SearchSource=13");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.originalSearchEngine", "MyAshampoo Customized Web Search");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Sat May 22 2010 15:32:05 GMT+0200");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_16276078.LastCheckTime", "Thu Nov 11 2010 22:55:22 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_17876054.LastCheckTime", "Thu Nov 11 2010 22:55:22 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_17965092.LastCheckTime", "Thu Nov 11 2010 22:55:22 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_19345231.LastCheckTime", "Thu Nov 11 2010 22:55:22 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_25987868.LastCheckTime", "Wed Oct 20 2010 03:11:18 GMT+0200");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.twitter.user_9330012.LastCheckTime", "Thu Nov 11 2010 22:55:22 GMT+0100");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("CommunityToolbar.undefined", "");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT2475029");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "MyAshampoo Customized Web Search");
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
[rcdhlrwc.default\prefs.js] - Line Deleted : user_pref("smartbar.machineId", "VGUMIPLLKI2DOMCX91PP05ERTTMY09CHR2G6/2AULSWS9QQOYU0TRIREUP2WAJD3ORVUNGZ16M3GMRH/AAIIHW");
*************************
AdwCleaner[R0].txt - [23668 bytes] - [03/05/2015 16:44:52]
AdwCleaner[S0].txt - [25161 bytes] - [03/05/2015 16:46:29]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [25221 bytes] ########## FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by Sylvia (administrator) on SYLVIA-JHPW1HHX on 03-05-2015 16:55:06
Running from G:\
Loaded Profiles: Sylvia (Available profiles: Sylvia)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 6 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [FreePDF Assistant] => C:\Programme\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKU\S-1-5-21-515967899-220523388-839522115-1003\...\Run: [CrystalDiskInfo] => C:\Programme\CrystalDiskInfo\DiskInfo.exe [2382968 2014-03-05] (Crystal Dew World)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Status Monitor.lnk [2015-04-30]
ShortcutTarget: Status Monitor.lnk -> C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-515967899-220523388-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-515967899-220523388-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKU\S-1-5-21-515967899-220523388-839522115-1003 - Microsoft Url Sucheingriff - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2010-04-16] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2010-04-16] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll [2013-05-28] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.4 -> C:\Programme\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin2.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin3.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin4.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin5.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin6.dll [2012-11-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin7.dll [2012-11-08] (Apple Inc.)
FF Extension: Adblock Plus - C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-08]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-06-21]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 ACDaemon; C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-07] (Mozilla Foundation)
S2 ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [177704 2007-06-05] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
R3 nvax; C:\WINDOWS\System32\drivers\nvax.sys [36864 2003-08-13] (NVIDIA Corporation)
R3 NVENET; C:\WINDOWS\System32\DRIVERS\NVENET.sys [70656 2003-06-07] (NVIDIA Corporation)
R3 nvnforce; C:\WINDOWS\System32\drivers\nvapu.sys [311552 2003-08-13] (NVIDIA Corporation)
R0 nv_agp; C:\WINDOWS\System32\DRIVERS\nv_agp.sys [18688 2003-03-19] (NVIDIA Corporation)
S3 P1Scanner; C:\WINDOWS\System32\drivers\usbscan.sys [15104 2008-04-14] (Microsoft Corporation)
S3 catchme; \??\C:\DOKUME~1\SYLVIA~1\LOKALE~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-03 16:51 - 2015-05-03 16:51 - 00000000 ____D () C:\RegBackup
2015-05-03 16:44 - 2015-05-03 16:47 - 00000000 ____D () C:\AdwCleaner
2015-05-03 16:31 - 2015-05-03 16:31 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-03 16:30 - 2015-05-03 16:30 - 00000757 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-03 16:30 - 2015-05-03 16:30 - 00000000 ____D () C:\Programme\Malwarebytes Anti-Malware
2015-05-03 16:30 - 2015-05-03 16:30 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware
2015-05-03 16:30 - 2015-05-03 16:30 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2015-05-03 16:30 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-03 16:30 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-03 16:27 - 2008-04-14 00:15 - 00010368 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidusb.sys
2015-05-03 16:27 - 2008-04-14 00:15 - 00010368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2015-05-03 16:27 - 2001-08-18 04:22 - 00012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mouhid.sys
2015-05-03 16:27 - 2001-08-18 04:22 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-05-01 20:14 - 2015-05-01 20:14 - 00015970 _____ () C:\ComboFix.txt
2015-05-01 20:14 - 2015-05-01 20:14 - 00000000 ____D () C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\temp
2015-05-01 20:14 - 2015-05-01 20:14 - 00000000 ____D () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\temp
2015-05-01 20:14 - 2015-05-01 20:14 - 00000000 ____D () C:\Dokumente und Einstellungen\Default User\Lokale Einstellungen\temp
2015-05-01 20:06 - 2015-05-01 20:14 - 00000000 ____D () C:\Qoobox
2015-05-01 20:06 - 2015-05-01 20:06 - 00000000 ___RD () C:\Dokumente und Einstellungen\Sylvia\Startmenü\Programme\Verwaltung
2015-05-01 20:06 - 2011-06-26 08:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2015-05-01 20:06 - 2010-11-07 19:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2015-05-01 20:06 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2015-05-01 20:06 - 2000-08-31 02:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2015-05-01 20:05 - 2015-05-01 20:13 - 00000000 ____D () C:\WINDOWS\erdnt
2015-05-01 20:05 - 2015-05-01 17:48 - 05619691 ____R (Swearware) C:\Dokumente und Einstellungen\Sylvia\Desktop\ComboFix.exe
2015-05-01 19:58 - 2015-05-01 19:58 - 00000897 _____ () C:\Dokumente und Einstellungen\Sylvia\Desktop\Revo Uninstaller.lnk
2015-05-01 19:58 - 2015-05-01 19:58 - 00000000 ____D () C:\Programme\VS Revo Group
2015-04-30 19:47 - 2015-05-03 16:55 - 00000000 ____D () C:\FRST
2015-04-30 19:02 - 2015-05-03 16:27 - 00000135 _____ () C:\WINDOWS\setupact.log
2015-04-30 19:02 - 2015-04-30 19:02 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-04-30 17:18 - 2015-04-30 17:19 - 00000000 ____D () C:\Kaspersky Rescue Disk 10.0
2015-04-30 15:59 - 2015-04-30 15:59 - 00000000 ____D () C:\KVRT_Data
2015-04-30 15:26 - 2015-05-03 16:27 - 00006657 _____ () C:\WINDOWS\setupapi.log
2015-04-30 14:54 - 2015-04-30 14:54 - 14040196 _____ () C:\Dokumente und Einstellungen\Sylvia\Desktop\Bewerbungen 2015.exe
2015-04-30 01:31 - 2015-05-03 16:49 - 00022352 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-30 01:26 - 2015-04-30 14:49 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVAST Software
2015-04-30 01:08 - 2015-04-30 01:08 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CheckPoint
2015-04-30 00:14 - 2015-04-30 00:55 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Anwendungsdaten\QuickPar
2015-04-30 00:12 - 2015-04-30 00:13 - 00000000 ____D () C:\Programme\QuickPar
2015-04-30 00:12 - 2015-04-30 00:12 - 00000662 _____ () C:\Dokumente und Einstellungen\Sylvia\Desktop\QuickPar.lnk
2015-04-30 00:12 - 2015-04-30 00:12 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Startmenü\Programme\QuickPar
2015-04-29 23:58 - 2014-04-28 10:43 - 07268192 _____ (Bitdefender LLC) C:\BootkitRemoval_x86.exe
2015-04-28 17:34 - 2015-04-28 17:34 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Comodo
2015-04-28 15:51 - 2015-04-28 15:53 - 00000000 ____D () C:\WINDOWS\pss
2015-04-06 16:56 - 2015-04-06 16:56 - 00000000 ____D () C:\Programme\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-03 16:55 - 2010-05-22 09:09 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Temp
2015-05-03 16:48 - 2010-05-22 09:43 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-05-03 16:48 - 2010-05-22 09:43 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-05-03 16:48 - 2010-05-22 08:56 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-03 16:47 - 2010-05-22 09:09 - 00000300 ___SH () C:\Dokumente und Einstellungen\Sylvia\ntuser.ini
2015-05-03 16:47 - 2010-05-22 09:05 - 00032158 _____ () C:\WINDOWS\SchedLgU.Txt
2015-05-03 16:46 - 2010-05-22 09:42 - 00000000 ___RD () C:\Programme
2015-05-03 16:30 - 2010-05-22 09:42 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2015-05-03 16:22 - 2001-08-18 15:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-05-01 20:36 - 2010-05-22 09:42 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart
2015-05-01 20:14 - 2010-05-22 09:05 - 00000000 __SHD () C:\Dokumente und Einstellungen\NetworkService
2015-05-01 20:13 - 2001-08-18 15:00 - 00000227 _____ () C:\WINDOWS\system.ini
2015-05-01 20:06 - 2010-05-22 09:09 - 00000000 ___RD () C:\Dokumente und Einstellungen\Sylvia\Startmenü\Programme
2015-04-30 16:05 - 2010-05-22 09:09 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia
2015-04-30 15:38 - 2010-05-22 10:41 - 00000211 __RSH () C:\boot.ini
2015-04-30 15:38 - 2001-08-18 15:00 - 00000583 _____ () C:\WINDOWS\win.ini
2015-04-30 01:27 - 2010-05-22 09:42 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Dokumente
2015-04-30 00:54 - 2011-11-25 11:34 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-29 01:32 - 2015-03-14 22:33 - 00000189 _____ () C:\siw_debug.txt
2015-04-28 17:27 - 2015-03-14 21:12 - 00448470 _____ () C:\WINDOWS\system32\prfh0407.dat
2015-04-28 17:27 - 2015-03-14 21:12 - 00065536 _____ () C:\WINDOWS\system32\config\COMODO I.evt
2015-04-28 17:26 - 2015-03-14 21:12 - 00079910 _____ () C:\WINDOWS\system32\prfc0407.dat
2015-04-22 16:17 - 2010-05-22 10:04 - 00002501 _____ () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Word.lnk
2015-04-19 14:42 - 2014-10-23 19:54 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Desktop\forum noch
2015-04-17 11:18 - 2015-03-30 13:19 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Desktop\schnitte und kurse 2015
2015-04-15 16:07 - 2015-01-05 11:57 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Desktop\Bewerbungen 2015
2015-04-15 14:13 - 2015-02-16 19:07 - 00000000 ____D () C:\Dokumente und Einstellungen\Sylvia\Desktop\nixfrei noch
2015-04-08 13:53 - 2012-05-03 12:53 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2012-11-08 17:54 - 2012-11-08 17:54 - 0000268 ___RH () C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Clean Electric Guitar
2012-11-08 17:54 - 2012-11-08 17:54 - 0000268 ___RH () C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Clips
2012-11-08 17:54 - 2012-11-08 17:54 - 0000268 ___RH () C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Cocoa
2011-04-03 09:00 - 2014-08-28 14:13 - 0011264 _____ () C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Temp\Quarantine.exe
C:\Dokumente und Einstellungen\Sylvia\Lokale Einstellungen\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.7 (04.30.2015:1)
OS: Microsoft Windows XP x86
Ran by Sylvia on 03.05.2015 at 16:51:10,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\mozilla\firefox\profiles\rcdhlrwc.default\conduitcommon
Successfully deleted: [Folder] C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\mozilla\firefox\profiles\rcdhlrwc.default\smartbar
Successfully deleted the following from C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\mozilla\firefox\profiles\rcdhlrwc.default\prefs.js
user_pref(CT2431232_Firefox.csv, [{\from\:\Abs Layer\,\action\:\loading toolbar\,\time\:1395423206126,\isWithState\:\\,\timeFromStart\:0,\timeFromPrev\:0}
user_pref(CT2475029..clientLogIsEnabled, false);
user_pref(CT2475029.ALLOW_SHOWING_HIDDEN_TOOLBAR, false);
user_pref(CT2475029.BrowserCompStateIsOpen_129469746101488132, true);
user_pref(CT2475029.BrowserCompStateIsOpen_129633221356525288, true);
user_pref(CT2475029.BrowserCompStateIsOpen_129681723868939970, true);
user_pref(CT2475029.CT2481020.CommunityChanged, true);
user_pref(CT2475029.CT2481020.alertChannelId, 874426);
user_pref(CT2475029.CT2481024.CommunityChanged, true);
user_pref(CT2475029.CT2481024.alertChannelId, 874430);
user_pref(CT2475029.CT2481025.CommunityChanged, true);
user_pref(CT2475029.CT2481025.alertChannelId, 874431);
user_pref(CT2475029.CT2481029.CommunityChanged, true);
user_pref(CT2475029.CT2481029.alertChannelId, 874435);
user_pref(CT2475029.CT2481031.CommunityChanged, true);
user_pref(CT2475029.CT2481031.alertChannelId, 874437);
user_pref(CT2475029.CT2481032.CommunityChanged, true);
user_pref(CT2475029.CT2481032.alertChannelId, 874438);
user_pref(CT2475029.CT2481033.CommunityChanged, true);
user_pref(CT2475029.CT2481033.alertChannelId, 874439);
user_pref(CT2475029.CT2481034.CommunityChanged, true);
user_pref(CT2475029.CT2481034.alertChannelId, 874440);
user_pref(CT2475029.CT2481035.CommunityChanged, true);
user_pref(CT2475029.CT2481035.alertChannelId, 874441);
user_pref(CT2475029.CT2481037.CommunityChanged, true);
user_pref(CT2475029.CT2481037.alertChannelId, 874443);
user_pref(CT2475029.CTID, ct2481020);
user_pref(CT2475029.CommunitiesChangesLastCheckTime, Tue Jan 10 2012 12:23:47 GMT+0100);
user_pref(CT2475029.CommunityChanged, true);
user_pref(CT2475029.CurrentServerDate, 10-1-2012);
user_pref(CT2475029.DialogsAlignMode, LTR);
user_pref(CT2475029.DialogsGetterLastCheckTime, Mon Jan 09 2012 13:38:00 GMT+0100);
user_pref(CT2475029.DownloadDomainsCheckInterval, 168);
user_pref(CT2475029.DownloadDomainsListLastCheckTime, Thu Jan 05 2012 09:49:35 GMT+0100);
user_pref(CT2475029.DownloadDomainsListLastServerUpdateTime, 1201069983);
user_pref(CT2475029.DownloadReferralCookieData, );
user_pref(CT2475029.EMailNotifierPollDate, Sun Jun 12 2011 12:12:07 GMT+0200);
user_pref(CT2475029.ExternalComponentPollDate129077842555155326, Tue Dec 14 2010 12:56:13 GMT+0100);
user_pref(CT2475029.ExternalComponentPollDate129078508355624514, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedLastCount129133095456874337, 100);
user_pref(CT2475029.FeedLastCount6244576562585401993, 92);
user_pref(CT2475029.FeedPollDate129076849370150342, Tue Jan 10 2012 12:23:50 GMT+0100);
user_pref(CT2475029.FeedPollDate129076850042182211, Tue Jan 10 2012 12:23:50 GMT+0100);
user_pref(CT2475029.FeedPollDate129076850596400916, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076850791868756, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076852434375419, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076853083906444, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076854010937606, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076855068438037, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076855340312884, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076855597344292, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076855883906472, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076856408281730, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076856723281882, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076856982969262, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.FeedPollDate129076857229219583, Tue Jan 10 2012 12:23:52 GMT+0100);
user_pref(CT2475029.FeedPollDate129076857478587121, Tue Jan 10 2012 12:23:52 GMT+0100);
user_pref(CT2475029.FeedPollDate129076858014837073, Tue Jan 10 2012 12:23:52 GMT+0100);
user_pref(CT2475029.FeedPollDate129132307482029379, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129132307482029381, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129132307482029382, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate129133095459686870, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129133095459686871, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129137419319063373, Thu Nov 11 2010 22:30:33 GMT+0100);
user_pref(CT2475029.FeedPollDate129137419319063374, Thu Nov 11 2010 22:30:33 GMT+0100);
user_pref(CT2475029.FeedPollDate129137435445312162, Thu Nov 11 2010 22:30:33 GMT+0100);
user_pref(CT2475029.FeedPollDate129137435445312163, Thu Nov 11 2010 22:30:33 GMT+0100);
user_pref(CT2475029.FeedPollDate129137435445312164, Thu Nov 11 2010 22:30:33 GMT+0100);
user_pref(CT2475029.FeedPollDate129137435445312165, Wed Oct 20 2010 03:11:10 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687146, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687147, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687148, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576560869056615, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561015434053, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561386746076, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561414772911, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561420903218, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561602550763, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561619886036, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561754984581, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561797886832, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561811548356, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561872249134, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561930219330, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576561981855850, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562037116008, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562041692017, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562207067564, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562230147241, Sat May 22 2010 15:32:10 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562294787742, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562356557644, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562442400632, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562443695659, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562504191975, Sat May 22 2010 15:32:10 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562833836505, Sat May 22 2010 15:32:10 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562864286456, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562875617752, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576562959235652, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563001642200, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563032567449, Sat May 22 2010 15:32:10 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563042939011, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563120943592, Sat May 22 2010 15:32:10 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563149812339, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563275725470, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563336850582, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563398664519, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563491628460, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563508458497, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563736132084, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563919782085, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563926653077, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576563995598288, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564023582060, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564025306008, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564149391022, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564240601882, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564283815262, Sat May 22 2010 15:32:06 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564295923619, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564370576533, Sat May 22 2010 15:32:05 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564539739037, Sat May 22 2010 15:32:07 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564541982906, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564713374620, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564879189886, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedPollDate6244576564901169500, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.FeedTTL129076850596400916, 5);
user_pref(CT2475029.FeedTTL129076850791868756, 5);
user_pref(CT2475029.FeedTTL129076855068438037, 2);
user_pref(CT2475029.FeedTTL129076856408281730, 2);
user_pref(CT2475029.FeedTTL129076856723281882, 5);
user_pref(CT2475029.FeedTTL129076857229219583, 30);
user_pref(CT2475029.FeedTTL129076858014837073, 2);
user_pref(CT2475029.FeedTTL129132307482029379, 40);
user_pref(CT2475029.FeedTTL129132307482029381, 40);
user_pref(CT2475029.FeedTTL129132307482029382, 40);
user_pref(CT2475029.FeedTTL129133095459686870, 40);
user_pref(CT2475029.FeedTTL129133095459686871, 40);
user_pref(CT2475029.FeedTTL129137419319063373, 40);
user_pref(CT2475029.FeedTTL129137419319063374, 40);
user_pref(CT2475029.FeedTTL129137435445312162, 40);
user_pref(CT2475029.FeedTTL129137435445312163, 40);
user_pref(CT2475029.FeedTTL129137435445312164, 40);
user_pref(CT2475029.FeedTTL129137435445312165, 40);
user_pref(CT2475029.FeedTTL129137437659687146, 40);
user_pref(CT2475029.FeedTTL129137437659687147, 40);
user_pref(CT2475029.FeedTTL129137437659687148, 40);
user_pref(CT2475029.FeedTTL6244576560869056615, 30);
user_pref(CT2475029.FeedTTL6244576561420903218, 60);
user_pref(CT2475029.FeedTTL6244576561619886036, 15);
user_pref(CT2475029.FeedTTL6244576561981855850, 5);
user_pref(CT2475029.FeedTTL6244576562037116008, 30);
user_pref(CT2475029.FeedTTL6244576562041692017, 15);
user_pref(CT2475029.FeedTTL6244576562443695659, 15);
user_pref(CT2475029.FeedTTL6244576562875617752, 5);
user_pref(CT2475029.FeedTTL6244576563149812339, 60);
user_pref(CT2475029.FeedTTL6244576563336850582, 10);
user_pref(CT2475029.FeedTTL6244576563398664519, 15);
user_pref(CT2475029.FeedTTL6244576563508458497, 5);
user_pref(CT2475029.FeedTTL6244576563919782085, 5);
user_pref(CT2475029.FeedTTL6244576564539739037, 15);
user_pref(CT2475029.FeedTTL6244576564901169500, 15);
user_pref(CT2475029.FirstServerDate, 22-5-2010);
user_pref(CT2475029.FirstTime, true);
user_pref(CT2475029.FirstTimeFF3, true);
user_pref(CT2475029.FixPageNotFoundErrors, true);
user_pref(CT2475029.GroupingLastCheckTime, Tue Jan 10 2012 12:23:47 GMT+0100);
user_pref(CT2475029.GroupingLastErrorCode, );
user_pref(CT2475029.GroupingLastResponse, true);
user_pref(CT2475029.GroupingLastServerUpdateTime, 129690325480000000);
user_pref(CT2475029.GroupingServerCheckInterval, 1440);
user_pref(CT2475029.HasUserGlobalKeys, true);
user_pref(CT2475029.Initialize, true);
user_pref(CT2475029.InitializeCommonPrefs, true);
user_pref(CT2475029.InstallationAndCookieDataSentCount, 3);
user_pref(CT2475029.InstalledDate, Sat May 22 2010 15:32:04 GMT+0200);
user_pref(CT2475029.InvalidateCache, false);
user_pref(CT2475029.IsAlertDBUpdated, true);
user_pref(CT2475029.IsGrouping, true);
user_pref(CT2475029.IsMulticommunity, true);
user_pref(CT2475029.IsOpenThankYouPage, false);
user_pref(CT2475029.IsOpenUninstallPage, true);
user_pref(CT2475029.LanguagePackLastCheckTime, Sat May 22 2010 15:32:38 GMT+0200);
user_pref(CT2475029.LanguagePackReloadIntervalMM, 1440);
user_pref(CT2475029.LastLogin_2.5.6.0, Mon Sep 06 2010 19:30:09 GMT+0200);
user_pref(CT2475029.LastLogin_2.7.2.0, Sun Jun 12 2011 11:38:21 GMT+0200);
user_pref(CT2475029.LastLogin_3.3.3.2, Sat Jun 25 2011 17:36:27 GMT+0200);
user_pref(CT2475029.LastLogin_3.5.0.12, Tue Aug 16 2011 06:34:09 GMT+0200);
user_pref(CT2475029.LastLogin_3.6.0.10, Thu Sep 29 2011 07:05:36 GMT+0200);
user_pref(CT2475029.LastLogin_3.7.0.6, Mon Nov 07 2011 20:01:50 GMT+0100);
user_pref(CT2475029.LastLogin_3.8.0.8, Tue Dec 06 2011 19:47:30 GMT+0100);
user_pref(CT2475029.LastLogin_3.8.1.0, Tue Jan 10 2012 12:23:52 GMT+0100);
user_pref(CT2475029.LatestVersion, 3.9.0.3);
user_pref(CT2475029.Locale, en);
user_pref(CT2475029.LoginCache, 4);
user_pref(CT2475029.MCDetectTooltipHeight, 83);
user_pref(CT2475029.MCDetectTooltipShow, true);
user_pref(CT2475029.MCDetectTooltipUrl, hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1);
user_pref(CT2475029.MCDetectTooltipWidth, 295);
user_pref(CT2475029.MyStuffEnabledAtInstallation, true);
user_pref(CT2475029.RadioIsPodcast, false);
user_pref(CT2475029.RadioLastCheckTime, Sat May 22 2010 15:32:09 GMT+0200);
user_pref(CT2475029.RadioLastUpdateIPServer, 0);
user_pref(CT2475029.RadioMediaID, 13098944);
user_pref(CT2475029.RadioMediaType, Media Player);
user_pref(CT2475029.RadioMenuSelectedID, EBRadioMenu_CT247502913098944);
user_pref(CT2475029.RadioShrinkedFromSetup, false);
user_pref(CT2475029.RadioStationName, Mellesleg%20-%20Rapp);
user_pref(CT2475029.RadioStationURL, hxxp://195.228.254.168:8060/);
user_pref(CT2475029.SHRINK_TOOLBAR, 1);
user_pref(CT2475029.SavedHomepage, resource:/browserconfig.properties);
user_pref(CT2475029.SearchBoxWidth, 150);
user_pref(CT2475029.SearchFromAddressBarIsInit, true);
user_pref(CT2475029.SearchInNewTabEnabled, true);
user_pref(CT2475029.SearchInNewTabIntervalMM, 1440);
user_pref(CT2475029.SearchInNewTabLastCheckTime, Sat May 22 2010 15:32:08 GMT+0200);
user_pref(CT2475029.ServiceMapLastCheckTime, Tue Jan 10 2012 12:23:46 GMT+0100);
user_pref(CT2475029.SettingsCheckIntervalMin, 120);
user_pref(CT2475029.SettingsLastCheckTime, Sat May 22 2010 15:32:01 GMT+0200);
user_pref(CT2475029.SettingsLastUpdate, 1273488183);
user_pref(CT2475029.ThirdPartyComponentsInterval, 504);
user_pref(CT2475029.ThirdPartyComponentsLastCheck, Sat May 22 2010 15:32:01 GMT+0200);
user_pref(CT2475029.ThirdPartyComponentsLastUpdate, 1273488183);
user_pref(CT2475029.UserID, UN03589194306444976);
user_pref(CT2475029.ValidationData_Search, 0);
user_pref(CT2475029.ValidationData_Toolbar, 2);
user_pref(CT2475029.WeatherNetwork, );
user_pref(CT2475029.WeatherPollDate, Sun Jun 12 2011 12:09:07 GMT+0200);
user_pref(CT2475029.WeatherUnit, C);
user_pref(CT2475029.alertChannelId, 868510);
user_pref(CT2475029.backendstorage./9b+7e+x305, 247E27413334363379453A3D2A722C797A7E7A3128333B4D474549484C5952594B335E5356432C45333438334A414C546660576364676F6A5E4B766B6E5B
user_pref(CT2475029.backendstorage./9b+7e,x305, 247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426D62455E69543D56444643465B
user_pref(CT2475029.backendstorage./9b+7e-x305, 247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5E6C656E706C7164736D4D786D
user_pref(CT2475029.backendstorage./9b+7e.:2z527, 2423);
user_pref(CT2475029.backendstorage./9b+7e.x305, 247E2A4137374434337A463B3E2B732D7A7D7C213229343F564654524C474A595A4851505E51523964595C49324B393C3B3E5047525D6C6A6B6F786D6850
user_pref(CT2475029.backendstorage./9b+7e/x305, 247E2B413536327844393C29712B787C7B773027323E4C4343534E2D585B3C253E2C302E34433A45515862695E675A416C6164513A5341454348584F5A66
user_pref(CT2475029.backendstorage./9b+7e06cg5el8:, 6E6D6F6C726B71717674);
user_pref(CT2475029.backendstorage./9b+7e06cg5el;8i:k, 247E2D2F226A74737572787177777C7A242F4B49474F42357D5D5C3D);
user_pref(CT2475029.backendstorage./9b+7e0x305, 247E2C403A407743383B28702A777C757D2F26313E41295547484D515A4E5A59325D5255422B443237303749404B585E685E706E6E6674626E696B4D786D
user_pref(CT2475029.backendstorage./9b+7e1x305, 247E2D41313D403279453A3D2A722C7A77797E31283341473E454745482F5A4F523F2841302D2F33463D48566265685C6B675F6D70604873686B58415A49
user_pref(CT2475029.backendstorage./9b+7e2x305, 247E2E3542313D3D393A7B473C3F2C742E79207D3229344356554E472E594E51325E4F412A4335373231483F4A59655F5F626C5B717369756975744D786D
user_pref(CT2475029.backendstorage./9b+7e31;cjc<=fbj#ncf, 247E61393F236B25757677712A212C6E414F444D327A344F4849524E562F5A4F523F364124504C56624730493B4B424D305C5D66523B544356
user_pref(CT2475029.backendstorage./9b+7e31;cjeik4!kk, 247E61393F236B25767177722A212C6E414F444D327A34515557402D57573C333E215E534E5651544E47304928284C434E5E72666A666A553E5D5
user_pref(CT2475029.backendstorage./9b+7e31;cjeik4!lad, 247E61393F236B25767179732A212C6E414F444D327A34515557402D584D503D343F224E4F58442D4635483F4A5A6E62666266513A5954627671
user_pref(CT2475029.backendstorage./9b+7e3x305, 247E2F413F3B36333F47463F7D493E412E76307E222421352C37474B59574B4A4858584E5E3762573A535E49324B3A3D3F3B504752626C625D75786D766A
user_pref(CT2475029.backendstorage./9b+7e4x305, 247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426D6265523B544346494A59505B
user_pref(CT2475029.backendstorage./9b+7e5x305, 247E3136422B7743383B28702A79757A772F2631434B3D49564A50592E594E314A55402942322E332F473E495B5D595A6A5E58707262674974696C59425B
user_pref(CT2475029.backendstorage./9b+7e6x305, 247E322C3E32323238453E7C483D402D752F7E7B2424342B364953545259585A5A50524E36615659462F4838353D3C4D444F626C6D6B72716A77614D786D
user_pref(CT2475029.backendstorage./9b+7e7x305, 247E333D2C3F3E3F79453A3D2A722C7B7A797A312833474745445159575B504B504B4D5E545553533A655A5D4A334C3C3B3A395148536775636367757567
user_pref(CT2475029.backendstorage./9b+7e8x305, 247E343D3F3B35373B3F367C47472C742E7E782332293449565540472E594E513E274030323533453C475C5558636A656E625E6C616B7068734B766B6E5B
user_pref(CT2475029.backendstorage./9b+7e9x305, 247E35332C3F327844393C29712B7B757979302732484C4F4F44504C4754585C5048345F5457442D46373135344B424D636B5D5F5F73696B4A756A6D5A43
user_pref(CT2475029.backendstorage./9b+7e:x305, 247E36333B38327844393C29712B7B76797A30273249485545442C574C4F3C253E2F2A2D2D433A455C67555B5E3F6A5F624F3851423D403F564D586F7A68
user_pref(CT2475029.backendstorage./9b+7e;x305, 247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354D462C574C4F3C253E2F2B2B31433A455D6356575C5C5A416C6164513A5344404045584F5A72
user_pref(CT2475029.backendstorage./9b+7e<x305, 247E38343030442F463644377D493E412E7630217D2426352C37502E4F4747315C5154412A4334313738483F4A635F5A6A645E625A4772676A5740594A47
user_pref(CT2475029.backendstorage./9b+7e=x305, 247E3933363F41413739357C483D402D752F207E2022342B36505459574C554F515B345F5457442D46373637384B424D676B706E606F61666B63664D786D
user_pref(CT2475029.backendstorage./9b+7e>x305, 247E3A41363F323238387B473C3F2C742E7E20217C332A35504F5346482F5A4F523F28413233342F463D48635C5D66626A436E6366533C55464748425A51
user_pref(CT2475029.backendstorage./9b+7e?x305, 247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3652504C5249555256525C35605558452E47383B38364C434E6A706F5F65635D736F67757868
user_pref(CT2475029.backendstorage./9b+7e@x305, 247E3C40422B7743383B28702A7B767E782F26314E52543D2A554A2D46513C253E302B332C433A45626756516259655F5F436E63465F6A553E5749444C44
user_pref(CT2475029.backendstorage./9b+7eax305, 247E3D3D37387743383B28702A7B7A757E2F26314F4F544A52404548564F58315C5154412A4335342F37483F4A68646B645D5E626462616D6971726B6C78
user_pref(CT2475029.backendstorage./9b+7ebe3g=;d9n9=d, 372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57);
user_pref(CT2475029.backendstorage./9b+7ebx305, 247E3E393141303D33454036327E4A3F422F77317B7D23352C37565949484E4F51525C4E4C55535B54605A5A3E695E614E37503B3D41544B567575656D73
user_pref(CT2475029.backendstorage./9b+7ecx305, 247E3F3D303043312E7A463B3E2B732D7B207E3128335351565551575A4F584C5E335E5356432C4534383649404B6B59566C686B46716669563F58474B48
user_pref(CT2475029.backendstorage./9b+7edx305, 247E4035422A363879453A3D2A722C7D202F26315247543C484A2C574C2F48533E27403233433A45665B68505C5E406B6E4F38514343544B56776C79616D
user_pref(CT2475029.backendstorage./9b+7etx305, 247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215642542D584D503D263F2D2E2E2E443B4635645E6669595C6062686F5C7363716F696467764F
user_pref(CT2475029.backendstorage./9b-0?3g>d, 6F703B3E6B716F427A76474776207949204B25207E7C232A2454552A592D5929295D2D32);
user_pref(CT2475029.backendstorage./9b-0?3g@6:5;, );
user_pref(CT2475029.backendstorage./9b-0?3gfa7ef, 2B2E2C3D);
user_pref(CT2475029.backendstorage./9b-3=3eccja=f>, 247E333D2C452F4135276F292A212C393D44307832332A354448584C3A232E333E58604F6456604F6852645858635E604E376B7167617059);
user_pref(CT2475029.backendstorage./9b/>01=9a6k6<im;krie@pdawm, 6A696B7273747576);
user_pref(CT2475029.backendstorage./9b3=>@44i48?, 372C2D326975763342363341484779213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750);
user_pref(CT2475029.backendstorage./9b5ba==9cjag, 6670716E6A7173727A70794848477576767D7C7B4E);
user_pref(CT2475029.backendstorage./9b6b11g4c56b>f;p;anr@p, 6E6D6F6C726B71707372717975);
user_pref(CT2475029.backendstorage./9b9643g3/9e, 6A);
user_pref(CT2475029.backendstorage./9b<:222h64<, 393F352F3E);
user_pref(CT2475029.backendstorage./9b=+03eh8h8j?:, 4443);
user_pref(CT2475029.backendstorage./9b?+e2a52d8, 372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52);
user_pref(CT2475029.backendstorage./9b?b0d:8aj62<h, 6D);
user_pref(CT2475029.backendstorage./9ba@0<0bi6a7gn:6@l?, 6E6B);
user_pref(CT2475029.backendstorage.10008, 31333132393938383238363532);
user_pref(CT2475029.backendstorage.10046, 31333039353231363939363031);
user_pref(CT2475029.backendstorage.10050, 31333037373639363235383834);
user_pref(CT2475029.backendstorage._fb_dailyactivity, 31333032343230303737303135);
user_pref(CT2475029.backendstorage._fb_lifetimesent, 54525545);
user_pref(CT2475029.backendstorage.active, 796573);
user_pref(CT2475029.backendstorage.ctid, 637432343831303230);
user_pref(CT2475029.backendstorage.eule_tb_id, 6564636638623836653664326334373961663734643230303833363562343838);
user_pref(CT2475029.backendstorage.export, 636C6F736564);
user_pref(CT2475029.backendstorage.facebook_ctid_connect_send, 73656E646564);
user_pref(CT2475029.backendstorage.fb_dailyactivity, 31333033373437303937353935);
user_pref(CT2475029.backendstorage.fb_lifetimesent, 54525545);
user_pref(CT2475029.backendstorage.firstinstall, 796573);
user_pref(CT2475029.backendstorage.firsttime, 796573);
user_pref(CT2475029.backendstorage.gsdomain, );
user_pref(CT2475029.backendstorage.lastexport, 323031312D30352D3139);
user_pref(CT2475029.backendstorage.lastrun, 31333236313132363832363635);
user_pref(CT2475029.backendstorage.partner_id, 3937346665643236);
user_pref(CT2475029.backendstorage.runtoolbar, 323031312D30352D3236);
user_pref(CT2475029.backendstorage.shoppingapp.gk.exipres, 53756E204A616E20313520323031322031323A32343A303420474D542B30313030);
user_pref(CT2475029.backendstorage.shoppingapp.gk.geolocation, 6765726D616E79);
user_pref(CT2475029.backendstorage.shopupdate, 323031312D30382D3039);
user_pref(CT2475029.backendstorage.shopversionv2, 3130303039);
user_pref(CT2475029.backendstorage.short, 30);
user_pref(CT2475029.backendstorage.tbready, 74727565);
user_pref(CT2475029.clientLogIsEnabled, false);
user_pref(CT2475029.ct2481020.AppTrackingLastCheckTime, Mon Jan 02 2012 16:43:13 GMT+0100);
user_pref(CT2475029.ct2481020.DialogsAlignMode, LTR);
user_pref(CT2475029.ct2481020.FeedLastCount129076858299680990, 850);
user_pref(CT2475029.ct2481020.FeedLastCount129137419315157090, 250);
user_pref(CT2475029.ct2481020.FirstTimeSettingsDone, true);
user_pref(CT2475029.ct2481020.GroupingInvalidateCache, false);
user_pref(CT2475029.ct2481020.GroupingLastCheckTime, Tue Jan 10 2012 12:23:47 GMT+0100);
user_pref(CT2475029.ct2481020.GroupingLastErrorCode, );
user_pref(CT2475029.ct2481020.GroupingLastResponse, true);
user_pref(CT2475029.ct2481020.GroupingLastServerUpdateTime, 129695500590000000);
user_pref(CT2475029.ct2481020.InvalidateCache, false);
user_pref(CT2475029.ct2481020.LanguagePackLastCheckTime, Tue Jan 10 2012 12:23:54 GMT+0100);
user_pref(CT2475029.ct2481020.Locale, de);
user_pref(CT2475029.ct2481020.RadioLastCheckTime, Tue Jan 10 2012 12:23:50 GMT+0100);
user_pref(CT2475029.ct2481020.RadioLastUpdateIPServer, 3);
user_pref(CT2475029.ct2481020.RadioLastUpdateServer, 129054397178370000);
user_pref(CT2475029.ct2481020.SearchInNewTabLastCheckTime, Tue Jan 10 2012 12:23:51 GMT+0100);
user_pref(CT2475029.ct2481020.SettingsCheckIntervalMin, 120);
user_pref(CT2475029.ct2481020.SettingsLastCheckTime, Tue Jan 10 2012 12:23:49 GMT+0100);
user_pref(CT2475029.ct2481020.SettingsLastUpdate, 1324548148);
user_pref(CT2475029.ct2481020.ThirdPartyComponentsLastCheck, Fri Dec 23 2011 08:28:26 GMT+0100);
user_pref(CT2475029.ct2481020.ThirdPartyComponentsLastUpdate, 1277133335);
user_pref(CT2475029.ct2481020.globalFirstTimeInfoLastCheckTime, Tue Jan 10 2012 12:23:54 GMT+0100);
user_pref(CT2475029.ct2481020.toolbarAppMetaDataLastCheckTime, Tue Jan 10 2012 12:23:54 GMT+0100);
user_pref(CT2475029.ct2481020.toolbarContextMenuLastCheckTime, Wed Dec 28 2011 11:50:55 GMT+0100);
user_pref(CT2475029.homepageProtectorEnableByLogin, true);
user_pref(CT2475029.initDone, true);
user_pref(CT2475029.isAppTrackingManagerOn, true);
user_pref(CT2475029.isFirstRadioInstallation, false);
user_pref(CT2475029.myStuffEnabled, true);
user_pref(CT2475029.myStuffPublihserMinWidth, 400);
user_pref(CT2475029.myStuffServiceIntervalMM, 1440);
user_pref(CT2475029.oldAppsList, 200,129058856464344002,129058856464656507,111,129469746101488132,129391152084062608,129469747048519222,129582129482516486,12939909970058784
user_pref(CT2475029.revertSettingsEnabled, true);
user_pref(CT2475029.searchProtectorDialogDelayInSec, 10);
user_pref(CT2475029.searchProtectorEnableByLogin, true);
user_pref(CT2475029.testingCtid, );
user_pref(CT2475029.usagesFlag, 2);
user_pref(valueApps.storage.mam_gk_userId, 36633963373565362D356463332D346438312D386634382D653131393637666661343166);
Emptied folder: C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\mozilla\firefox\profiles\rcdhlrwc.default\minidumps [6 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.05.2015 at 16:53:18,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.05.2015
Suchlauf-Zeit: 16:31:23
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows XP Service Pack 3
CPU: x86
Dateisystem: NTFS
Benutzer: Sylvia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 316091
Verstrichene Zeit: 9 Min, 43 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 2
PUP.Optional.Conduit.A, HKU\S-1-5-21-515967899-220523388-839522115-1003\SOFTWARE\CONDUIT\FF, In Quarantäne, [83f677cc0a803df9f78952be44c107f9],
PUP.Optional.ValueApps.A, HKU\S-1-5-21-515967899-220523388-839522115-1003\SOFTWARE\CONDUIT\ValueApps, In Quarantäne, [aecbe55ea7e340f69219bb3ada29b64a],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-515967899-220523388-839522115-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029, Gut: (www.google.com), Schlecht: (hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029),Ersetzt,[d8a196ad701a132319e5e8f8d2334ab6]
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 4
PUP.Optional.Conduit.A, C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default\searchplugins\conduit.xml, In Quarantäne, [e0996ed5870375c1219724c6d231817f],
PUP.Optional.Conduit.A, C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=");), Ersetzt,[a2d788bb3258b086a99ed44bce38619f]
PUP.Optional.Conduit.A, C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}");), Ersetzt,[57222d1697f33bfb50089b84d4329868]
PUP.Optional.Conduit.A, C:\Dokumente und Einstellungen\Sylvia\Anwendungsdaten\Mozilla\Firefox\Profiles\rcdhlrwc.default\prefs.js, Gut: (), Schlecht: (user_pref("CT2475029.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=");), Ersetzt,[f28773d03357b6801d3cea351aec7a86]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
Gruß, Ralf |