|
Plagegeister aller Art und deren Bekämpfung: Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.12.2011, 19:43 | #31 |
/// Malware-holic | Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 na das können wir auch später machen. du kannst ja für sie nen extra thema eröffnen dann schaue ich mir das an. ja, sichern ist das einfachste, aber leider machts kaum einer
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
03.12.2011, 17:51 | #32 |
| Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 Hi, neues Thema kommt erstmal nicht. Tochter (Geduld ist nicht ihr Freund) begnügt sich vorerst mit der Mogelpackung in Form von Wiederherstellung, wenn das mal gut geht........
__________________ |
03.12.2011, 17:53 | #33 |
/// Malware-holic | Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 jo finde ich auch keine idiale lösung,man weis nie ob nicht noch mehr malware instaliert wurde
__________________
__________________ |
03.12.2011, 18:01 | #34 |
| Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 Nochmal herzlichen Dank für deine Hilfe. |
04.12.2011, 16:16 | #35 |
| Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 Hi, oha, ich hab eben nochmal einen Vollscan mit Malwarebytes gemacht und es wurden 2 infizierte Dateien gefunden. hier der mbam-log Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Datenbank Version: 8307 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 04.12.2011 15:51:39 mbam-log-2011-12-04 (15-51-25).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|) Durchsuchte Objekte: 458152 Laufzeit: 1 Stunde(n), 4 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 2 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\_OTL\movedfiles\12012011_170328\c_programdata\jtsddw9nsshwjx.exe (Trojan.FakeAlert.Gen) -> No action taken. c:\_OTL\movedfiles\12012011_170328\c_programdata\nfwokoyrvdaorqh.exe (Trojan.FakeAlert.Gen) -> No action taken. und hier der otl-log nach entfernen der 2 DateienOTL Logfile: Code:
ATTFilter OTL logfile created on: 04.12.2011 16:07:52 - Run 3 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Angela\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,91 Gb Total Physical Memory | 2,78 Gb Available Physical Memory | 71,00% Memory free 7,82 Gb Paging File | 6,63 Gb Available in Paging File | 84,70% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 657,54 Gb Total Space | 620,18 Gb Free Space | 94,32% Space Free | Partition Type: NTFS Drive D: | 37,99 Gb Total Space | 13,84 Gb Free Space | 36,43% Space Free | Partition Type: NTFS Drive E: | 116,44 Gb Total Space | 41,45 Gb Free Space | 35,60% Space Free | Partition Type: NTFS Drive F: | 104,73 Gb Total Space | 66,17 Gb Free Space | 63,19% Space Free | Partition Type: NTFS Computer Name: LÄPPI | User Name: Angela | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.12.01 15:56:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Angela\Desktop\OTL.exe PRC - [2011.09.05 09:04:54 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.08.31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2011.07.21 11:08:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2011.04.21 06:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2011.02.11 20:40:00 | 000,997,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe PRC - [2011.02.11 20:39:54 | 000,907,600 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe PRC - [2010.10.22 13:03:56 | 000,826,368 | ---- | M] (A Note) -- C:\Program Files (x86)\A Note\A Note.exe ========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011.05.02 22:27:50 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2011.05.02 22:13:54 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2011.05.02 22:10:26 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2011.04.21 17:34:16 | 001,136,640 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV:64bit: - [2011.04.21 16:42:50 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) SRV:64bit: - [2010.12.17 15:46:34 | 000,198,784 | ---- | M] (Conexant Systems Inc.) [Auto | Running] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg) SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2011.09.05 09:04:54 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2011.07.21 11:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.30 08:32:54 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R) SRV - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011.02.22 21:20:21 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R) SRV - [2011.02.22 21:20:17 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R) SRV - [2011.02.11 20:40:00 | 000,997,712 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV - [2011.02.11 20:39:58 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service) SRV - [2011.02.11 20:39:54 | 000,907,600 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor) SRV - [2010.03.18 21:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2011.08.01 14:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64) DRV:64bit: - [2011.07.21 11:11:10 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2011.07.21 11:11:09 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2011.05.17 17:27:52 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus) DRV:64bit: - [2011.05.17 17:27:50 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible) DRV:64bit: - [2011.05.01 22:33:06 | 008,593,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel(R) DRV:64bit: - [2011.04.26 19:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2011.04.21 17:09:26 | 000,294,912 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP) Intel(R) Centrino(R) DRV:64bit: - [2011.04.21 17:09:26 | 000,294,912 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL) Intel(R) Centrino(R) DRV:64bit: - [2011.04.15 10:08:26 | 012,228,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.04.15 00:16:08 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd) DRV:64bit: - [2011.04.13 17:30:54 | 000,207,872 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2011.04.13 17:30:50 | 000,087,552 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011.03.10 16:01:40 | 001,581,184 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService) DRV:64bit: - [2011.01.24 10:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux) DRV:64bit: - [2011.01.24 10:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex) DRV:64bit: - [2011.01.24 09:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf) DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R) DRV:64bit: - [2010.10.15 00:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) DRV:64bit: - [2010.09.27 10:32:28 | 000,632,704 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw10bda.sys -- (hcw10bda) DRV:64bit: - [2010.09.23 21:03:06 | 000,129,008 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd) DRV:64bit: - [2010.08.24 17:55:44 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2010.05.10 08:29:16 | 000,046,080 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\hcw10cir.sys -- (hcw10cir) DRV:64bit: - [2010.01.22 10:26:50 | 000,305,200 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2009.10.23 16:26:14 | 000,046,592 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2011.09.03 10:43:36 | 000,001,722 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysWow64\NULL -- (Null) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.bwin.com/de/sportsbook.aspx IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "" FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://my.ebay.de/ws/eBayISAPI.dll?MyEbayBeta&&CurrentPage=MyeBayNextSelling&ssPageName=STRK%3AME%3ALNLK%3AMESEX&guest=1" FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 17:11:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.02 07:16:57 | 000,000,000 | ---D | M] [2011.09.02 05:46:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Angela\AppData\Roaming\mozilla\Extensions [2011.12.01 17:48:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Angela\AppData\Roaming\mozilla\Firefox\Profiles\xhtjj79a.default\extensions [2011.11.03 11:27:59 | 000,000,933 | ---- | M] () -- C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\xhtjj79a.default\searchplugins\11-suche.xml [2011.11.03 11:27:59 | 000,002,419 | ---- | M] () -- C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\xhtjj79a.default\searchplugins\englische-ergebnisse.xml [2011.09.02 18:07:03 | 000,010,525 | ---- | M] () -- C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\xhtjj79a.default\searchplugins\gmx-suche.xml [2011.11.03 11:27:59 | 000,002,457 | ---- | M] () -- C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\xhtjj79a.default\searchplugins\lastminute.xml [2011.11.03 11:27:59 | 000,005,508 | ---- | M] () -- C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\xhtjj79a.default\searchplugins\webde-suche.xml [2011.12.01 21:49:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2011.12.01 21:49:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} () (No name found) -- C:\USERS\ANGELA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XHTJJ79A.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI [2011.11.09 17:11:30 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.12.01 21:49:15 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010.03.08 11:24:04 | 000,103,168 | ---- | M] (Midasplayer Ltd) -- C:\Program Files (x86)\mozilla firefox\plugins\npmidas.dll [2011.09.10 08:20:16 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.09.10 08:20:16 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011.09.10 08:20:16 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011.09.10 08:20:16 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011.09.10 08:20:16 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011.09.10 08:20:16 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2011.12.01 18:36:01 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found. O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - Startup: C:\Users\Angela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\A Note.lnk = C:\Program Files (x86)\A Note\A Note.exe (A Note) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8068FE7C-7296-400B-9019-82B7F3A7BDB2}: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1AEB345-498B-4D3D-A2B8-DB5469020C02}: DhcpNameServer = 192.168.0.1 O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.12.04 14:09:49 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\16179-Dateien [2011.12.03 12:20:44 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\22612429-Grosses-rechteckiges-Vogelhaus-Typ-9-Dateien [2011.12.02 19:12:33 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\käthe [2011.12.01 21:50:28 | 000,190,752 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe [2011.12.01 21:50:28 | 000,171,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe [2011.12.01 21:50:28 | 000,171,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe [2011.12.01 21:50:18 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2011.12.01 21:49:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2011.12.01 21:49:29 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2011.12.01 21:49:29 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2011.12.01 21:49:29 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2011.12.01 21:49:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2011.12.01 21:41:10 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2011.12.01 21:15:16 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Local\photoOptimizeHistoryDataBase [2011.12.01 21:15:15 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Local\Ashampoo Photo Optimizer Medion [2011.12.01 20:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2011.12.01 20:19:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.12.01 19:03:59 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Roaming\Malwarebytes [2011.12.01 19:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.12.01 19:03:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.12.01 19:03:51 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.12.01 19:03:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011.12.01 18:36:06 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN [2011.12.01 18:29:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2011.12.01 18:29:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2011.12.01 18:29:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2011.12.01 18:28:56 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT [2011.12.01 18:28:53 | 000,000,000 | ---D | C] -- C:\Qoobox [2011.12.01 18:19:46 | 004,323,152 | R--- | C] (Swearware) -- C:\Users\Angela\Desktop\ComboFix.exe [2011.12.01 18:01:48 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Roaming\WinRAR [2011.12.01 18:01:48 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2011.12.01 18:01:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2011.12.01 18:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2011.12.01 17:24:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2011.12.01 17:24:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip [2011.12.01 17:03:28 | 000,000,000 | ---D | C] -- C:\_OTL [2011.12.01 16:30:24 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Angela\Desktop\OTL.exe [2011.12.01 15:37:28 | 000,000,000 | ---D | C] -- C:\Users\Angela\AppData\Roaming\QuickScan [2011.11.19 17:54:26 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\Dichtung-einbauen-Dateien [2011.11.19 10:35:43 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\fensterdichtung-t22388-Dateien [2011.11.17 18:49:12 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\DisplayProductInformation-SearchDetail-Dateien [2011.11.16 14:14:01 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\Schokokekse mit Karamell _ Pi mal Butter-Dateien [2011.11.12 10:32:00 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\111112_wolfsabend-Dateien [2011.11.12 09:27:43 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed [2011.11.10 10:18:42 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\Fotos November [2011.11.10 08:55:45 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\150678567191-Dateien [2011.11.04 19:29:11 | 000,000,000 | ---D | C] -- C:\Users\Angela\Desktop\13234098-Rueschenschal-in-schwarz-Dateien [2011.10.30 10:33:45 | 003,623,592 | ---- | C] (Ask) -- C:\Program Files (x86)\Common Files\ApnToolbarInstaller.exe [2011.10.30 10:33:45 | 000,143,240 | ---- | C] (Ask.com) -- C:\Program Files (x86)\Common Files\ApnStub.exe ========== Files - Modified Within 30 Days ========== [2011.12.04 16:05:50 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat [2011.12.04 16:05:48 | 3151,327,232 | -HS- | M] () -- C:\hiberfil.sys [2011.12.04 14:09:49 | 000,021,441 | ---- | M] () -- C:\Users\Angela\Desktop\16179.htm [2011.12.04 10:10:37 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.04 10:10:37 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.03 18:03:07 | 000,034,008 | ---- | M] () -- C:\Users\Angela\Desktop\monatl. Überweisungen.odt [2011.12.03 13:41:11 | 000,001,230 | ---- | M] () -- C:\Users\Angela\Desktop\Calculator (2).lnk [2011.12.03 12:20:45 | 000,143,418 | ---- | M] () -- C:\Users\Angela\Desktop\22612429-Grosses-rechteckiges-Vogelhaus-Typ-9.htm [2011.12.02 16:43:39 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.12.02 16:43:39 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.12.02 16:43:39 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.12.02 16:43:39 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.12.02 16:43:39 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.12.02 07:39:11 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2011.12.01 21:50:20 | 000,525,544 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll [2011.12.01 21:50:20 | 000,190,752 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe [2011.12.01 21:50:20 | 000,171,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe [2011.12.01 21:50:20 | 000,171,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe [2011.12.01 21:49:14 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2011.12.01 21:49:14 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2011.12.01 21:49:14 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2011.12.01 21:49:14 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2011.12.01 21:23:35 | 000,038,129 | ---- | M] () -- C:\Windows\Irremote.ini [2011.12.01 20:19:41 | 000,000,826 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.12.01 19:03:56 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.12.01 18:36:01 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2011.12.01 18:20:18 | 004,323,152 | R--- | M] (Swearware) -- C:\Users\Angela\Desktop\ComboFix.exe [2011.12.01 17:23:58 | 001,110,476 | ---- | M] () -- C:\Users\Angela\Desktop\7z920.exe [2011.12.01 17:07:03 | 000,001,158 | ---- | M] () -- C:\Users\Angela\Desktop\Mozilla Firefox.lnk [2011.12.01 16:45:26 | 000,684,297 | ---- | M] () -- C:\Users\Angela\Desktop\unhide.exe [2011.12.01 15:56:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Angela\Desktop\OTL.exe [2011.11.25 19:30:03 | 000,020,676 | ---- | M] () -- C:\Users\Angela\Desktop\komplette liste erstellen.odt [2011.11.20 18:39:39 | 000,010,635 | ---- | M] () -- C:\Users\Angela\Desktop\zinn.odt [2011.11.19 17:54:26 | 000,009,275 | ---- | M] () -- C:\Users\Angela\Desktop\Dichtung-einbauen.html [2011.11.19 10:35:43 | 000,072,045 | ---- | M] () -- C:\Users\Angela\Desktop\fensterdichtung-t22388.html [2011.11.17 18:49:12 | 000,260,637 | ---- | M] () -- C:\Users\Angela\Desktop\DisplayProductInformation-SearchDetail.htm [2011.11.16 14:14:02 | 000,071,086 | ---- | M] () -- C:\Users\Angela\Desktop\Schokokekse mit Karamell _ Pi mal Butter.htm [2011.11.12 10:32:01 | 000,039,398 | ---- | M] () -- C:\Users\Angela\Desktop\111112_wolfsabend.html [2011.11.11 18:11:50 | 000,030,040 | ---- | M] () -- C:\Users\Angela\Desktop\November.odt [2011.11.10 08:55:46 | 000,109,425 | ---- | M] () -- C:\Users\Angela\Desktop\150678567191.htm [2011.11.09 07:44:12 | 000,406,312 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011.11.07 16:48:53 | 000,019,031 | ---- | M] () -- C:\Users\Angela\Desktop\Bücherliste.odt [2011.11.07 07:53:26 | 000,849,359 | ---- | M] () -- C:\Users\Angela\Desktop\maxx.jpg [2011.11.06 15:24:38 | 000,026,373 | ---- | M] () -- C:\Users\Angela\Desktop\ordnungsamt.odt [2011.11.04 19:29:11 | 000,128,519 | ---- | M] () -- C:\Users\Angela\Desktop\13234098-Rueschenschal-in-schwarz.htm [2011.11.04 17:42:02 | 000,016,818 | ---- | M] () -- C:\Users\Angela\Desktop\komplette liste erstellen - Rest.odt [2011.11.04 17:17:45 | 280,909,672 | ---- | M] () -- C:\Users\Angela\Desktop\Standard_20111104_171645.zip ========== Files Created - No Company Name ========== [2011.12.04 14:09:49 | 000,021,441 | ---- | C] () -- C:\Users\Angela\Desktop\16179.htm [2011.12.03 13:41:11 | 000,001,230 | ---- | C] () -- C:\Users\Angela\Desktop\Calculator (2).lnk [2011.12.03 12:20:44 | 000,143,418 | ---- | C] () -- C:\Users\Angela\Desktop\22612429-Grosses-rechteckiges-Vogelhaus-Typ-9.htm [2011.12.01 20:19:41 | 000,000,826 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.12.01 19:03:56 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.12.01 18:29:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2011.12.01 18:29:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2011.12.01 18:29:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2011.12.01 18:29:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2011.12.01 18:29:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2011.12.01 17:23:55 | 001,110,476 | ---- | C] () -- C:\Users\Angela\Desktop\7z920.exe [2011.12.01 17:07:03 | 000,001,158 | ---- | C] () -- C:\Users\Angela\Desktop\Mozilla Firefox.lnk [2011.12.01 16:57:47 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk [2011.12.01 16:57:47 | 000,001,010 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2011.12.01 16:57:45 | 000,002,448 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [2011.12.01 16:57:45 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2011.12.01 16:57:45 | 000,002,052 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) WiDi.lnk [2011.12.01 16:57:45 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [2011.12.01 16:57:45 | 000,001,416 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Control Center.lnk [2011.12.01 16:57:45 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk [2011.12.01 16:57:45 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2011.12.01 16:57:45 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk [2011.12.01 16:57:45 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2011.12.01 16:57:45 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk [2011.12.01 16:57:45 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk [2011.12.01 16:57:45 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011.12.01 16:46:27 | 000,684,297 | ---- | C] () -- C:\Users\Angela\Desktop\unhide.exe [2011.11.20 18:39:35 | 000,010,635 | ---- | C] () -- C:\Users\Angela\Desktop\zinn.odt [2011.11.19 17:54:26 | 000,009,275 | ---- | C] () -- C:\Users\Angela\Desktop\Dichtung-einbauen.html [2011.11.19 10:35:43 | 000,072,045 | ---- | C] () -- C:\Users\Angela\Desktop\fensterdichtung-t22388.html [2011.11.17 18:49:11 | 000,260,637 | ---- | C] () -- C:\Users\Angela\Desktop\DisplayProductInformation-SearchDetail.htm [2011.11.16 14:14:01 | 000,071,086 | ---- | C] () -- C:\Users\Angela\Desktop\Schokokekse mit Karamell _ Pi mal Butter.htm [2011.11.12 10:32:00 | 000,039,398 | ---- | C] () -- C:\Users\Angela\Desktop\111112_wolfsabend.html [2011.11.10 08:55:44 | 000,109,425 | ---- | C] () -- C:\Users\Angela\Desktop\150678567191.htm [2011.11.07 07:53:26 | 000,849,359 | ---- | C] () -- C:\Users\Angela\Desktop\maxx.jpg [2011.11.06 11:54:27 | 000,026,373 | ---- | C] () -- C:\Users\Angela\Desktop\ordnungsamt.odt [2011.11.05 09:27:02 | 000,019,031 | ---- | C] () -- C:\Users\Angela\Desktop\Bücherliste.odt [2011.11.04 19:29:10 | 000,128,519 | ---- | C] () -- C:\Users\Angela\Desktop\13234098-Rueschenschal-in-schwarz.htm [2011.11.04 17:17:08 | 280,909,672 | ---- | C] () -- C:\Users\Angela\Desktop\Standard_20111104_171645.zip [2011.10.30 10:33:46 | 000,444,283 | ---- | C] () -- C:\Program Files (x86)\Common Files\WinPcapNmap.exe [2011.09.27 17:43:41 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011.09.27 17:43:41 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2011.09.27 17:43:25 | 000,038,129 | ---- | C] () -- C:\Windows\Irremote.ini [2011.09.27 17:43:14 | 000,142,337 | ---- | C] () -- C:\Windows\SysWow64\Wait.exe [2011.09.27 17:42:34 | 000,005,110 | ---- | C] () -- C:\Windows\HCWPNP.INI [2011.09.02 19:23:54 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011.09.02 19:23:53 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011.09.02 19:23:53 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2011.09.02 19:23:52 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2011.09.02 17:16:39 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe [2011.06.08 20:34:59 | 013,359,616 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2011.06.08 20:34:59 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2011.05.27 02:14:01 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2011.05.27 02:14:00 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2011.05.27 02:14:00 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2009.07.14 06:38:36 | 000,067,584 | ---- | C] () -- C:\Windows\bootstat.dat [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat < End of report > Ist der Mist noch nicht vorbei? |
04.12.2011, 17:03 | #36 |
/// Malware-holic | Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 hi lösche mal auf c: den ordner _OTL das ist nur die quarantäne des programms otl also keine sorge
__________________ --> Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 |
Themen zu Habe auch Probleme mit "Failed to save all the components for the file System32\\00... " Win7 |
corrupted, error, etliche, failed, fenster, file, firefox, hardware, hoffe, ordner, probleme, programme, scripts, system, system32, the file is corrupted, this, thread, win, win7, wirklich, öffnen |